1

Cmmc Jobs (NOW HIRING)

Track CMMC rulemaking, NIST guidance updates, and DoD policy changes; brief leadership on implications and required organizational responses * Establish and report on compliance program metrics and ...

We seek a highly skilled CMMC Level 2 Certified Assessor (CCA) to join our team on a project basis. This role involves conducting official CMMC Level 2 assessments for organizations seeking ...

CMMC Program Manager

Falls Church, VA · On-site

$123K - $124K/yr

The CMMC Program Manager is responsible for managing, maintaining, and continuously improving the organization's Cybersecurity Maturity Model Certification (CMMC) compliance program for the secure ...

CMMC Compliance Manager

Leesburg, VA · On-site

$150K - $170K/yr

The CMMC Compliance Manger will be responsible for owning and managing the organization's CMMC compliance program for our Controlled Unclassified Information (CUI) enclave. The position serves as the ...

As a CMMC Senior Associate at Schellman, you will play a critical role in delivering high-quality cybersecurity assessments for clients seeking compliance and assessment primarily for CMMC and NIST ...

GRC Engineer (CMMC)

$58.50 - $72/hr

CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST SP 800-171 baselines as they apply to defense contractors and supply chain data. * Sovereign cloud ...

The CMMC Compliance Manager will be responsible for supporting the company's U.S. government cybersecurity compliance program, with primary focus on Cybersecurity Maturity Model Certification (CMMC ...

Overview The Nov 10, 2026 CMMC 2.0 Phase 2 deadline is forcing every DIB contractor to prove they protect CUI - and most are trying to do it by tightening controls on the endpoint. That's the wrong ...

The CMMC Compliance Manager will be responsible for supporting the company's U.S. government cybersecurity compliance program, with primary focus on Cybersecurity Maturity Model Certification (CMMC ...

We seek a highly skilled CMMC Level 2 Certified Assessor (CCA) to join our team on a project basis. This role involves conducting official CMMC Level 2 assessments for organizations seeking ...

Overview The Nov 10, 2026 CMMC 2.0 Phase 2 deadline is forcing every DIB contractor to prove they protect CUI - and most are trying to do it by tightening controls on the endpoint. That's the wrong ...

Showing results 21-40

cmmc information

See salary details

$14

$25

$53

How much do cmmc jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for cmmc in the United States is $25.22, according to ZipRecruiter salary data. Most workers in this role earn between $18.03 and $23.80 per hour, depending on experience, location, and employer.

What is a CMMC?

A CMMC job typically involves ensuring an organization complies with the Cybersecurity Maturity Model Certification (CMMC) framework. Professionals in this role assess cybersecurity practices, prepare for audits, and help implement necessary security controls. They may work as consultants, compliance officers, or cybersecurity specialists, depending on the organization's needs. Their goal is to protect sensitive government and defense-related information by meeting CMMC requirements.

What are the primary responsibilities of a CMMC consultant during a client engagement?

As a CMMC Consultant, your main responsibilities include assessing client organizations’ current cybersecurity practices, identifying gaps relative to CMMC requirements, and developing actionable remediation plans. You will collaborate closely with IT teams, management, and external stakeholders to guide clients through the CMMC certification process. Expect to conduct detailed documentation reviews, perform technical evaluations, and provide training or recommendations to help clients achieve required compliance levels. This role involves balancing technical analysis with regulatory interpretation to support clients throughout their compliance journey.

What are the key skills and qualifications needed to thrive in the CMMC position, and why are they important?

To thrive as a CMMC (Cybersecurity Maturity Model Certification) Consultant, you need expertise in cybersecurity frameworks, risk assessments, and compliance standards, typically supported by a degree in information technology or cybersecurity and relevant certifications such as CMMC-AB certifications or CISSP. Proficiency with security assessment tools, regulatory compliance platforms, and documentation systems is essential in this role. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart in guiding organizations through complex compliance requirements. These skills are vital for ensuring client organizations achieve and maintain compliance with Department of Defense cybersecurity mandates.

More about cmmc jobs

What cities are hiring for Cmmc jobs?

Cities with the most Cmmc job openings:

What are the most commonly searched types of Cmmc jobs?

The most popular types of Cmmc jobs are:

What states have the most Cmmc jobs?

States with the most job openings for Cmmc jobs include:

Infographic showing various Cmmc job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 95% Full Time, 2% Part Time, and 2% Contract. Highlights an 79% Physical, 4% Hybrid, and 17% Remote job distribution, with an average salary of $52,465 per year, or $25.2 per hour.

CMMC Compliance Manager

Mason, OH • On-site

Full-time

Re-posted 6 days ago


Job description

Position Summary
The Compliance Manager is the organizational owner of the company’s regulatory compliance program, with primary accountability for achieving and maintaining Cybersecurity Maturity Model Certification (CMMC), ensuring alignment with NIST SP 800-171 and applicable DFARS clauses, and managing the identification and tracking of CUI-related contractual obligations across the business.
This is a leadership role that sits at the intersection of IT, legal, contracts, operations, and executive management. The Compliance Manager does not just track requirements — they drive the organization’s compliance posture, build a culture of security awareness, and ensure the company is audit-ready at all times. They are the primary point of accountability when a C3PAO assessor walks in the door.
Key Responsibilities:
Compliance Program Ownership
  • Own and continuously improve the organization’s end-to-end compliance program encompassing CMMC, NIST SP 800-171, DFARS 252.204-7012/7019/7020/7021, and related federal regulations
  • Develop, maintain, and enforce the organization’s information security policies, standards, and procedures; ensure they are reviewed at least annually and updated in response to regulatory changes
  • Maintain the System Security Plan (SSP), Plan of Action amp; Milestones (POA amp;M), and all supporting compliance artifacts; ensure they are current, accurate, and audit-ready at all times
  • Own the organization’s risk register; conduct periodic risk assessments and drive remediation planning in partnership with IT and operational leadership
  • Track CMMC rulemaking, NIST guidance updates, and DoD policy changes; brief leadership on implications and required organizational responses
  • Establish and report on compliance program metrics and key performance indicators (KPIs) to senior leadership on a regular cadence
CMMC Assessment Readiness
  • Lead all activities related to preparation for and completion of CMMC third-party assessments (C3PAO); serve as the organization’s primary point of contact with assessors
  • Conduct and document internal gap assessments against NIST SP 800-171 and CMMC practice requirements; maintain evidence packages for all 110 practices
  • Coordinate with IT to ensure that technical controls are implemented, documented, and generating the evidence required for a successful assessment
  • Manage the POA amp;M lifecycle: identify gaps, assign remediation owners, set milestone dates, track progress, and verify closure
  • Prepare staff for assessor interviews; conduct mock assessments and tabletop exercises to identify weaknesses before formal assessment
  • Maintain post-assessment continuous compliance, ensuring controls do not degrade between certification cycles
CUI Program Management
  • Define, document, and maintain the organization’s CUI scope: categories of CUI handled, all roles and individuals who access CUI, and all systems and locations where CUI is stored, processed, or transmitted
  • Maintain the assessment boundary documentation and data flow diagrams in coordination with IT
  • Develop and enforce CUI handling procedures, marking standards, and destruction requirements across all departments
  • Conduct periodic CUI audits to verify that staff are handling and marking CUI correctly in both digital and physical form
  • Serve as the internal resource for CUI classification questions from program managers, engineers, procurement, and other staff
Preferred Education amp; Certification(s):
  • Bachelor's Degree, preferably in Cybersecurity, Information Technology or similar field
  • Certified CMMC Professional (CCP)
  • Certified CMMC Assessor (CCA)
  • Project Management Professional (PMP)
  • Certified Authorization Professional (CAP / CGRC)