Frazier & Deeter

CMMC Advisory Manager

Frazier & Deeter • $110K — $130K *
Business Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Computer Science, Cybersecurity, or related field.
  • 7-10 years in IT Audit, Cybersecurity, or Compliance, with 2 years in a supervisory role.
  • Certified CMMC Professional (CCP) required; Certified CMMC Assessor (CCA) preferred.
  • Additional certifications like CISA, CISSP, or ISO 27001 Lead Auditor are a plus.
  • U.S. citizenship required for CMMC assessment activities.
  • Deep understanding of CMMC, NIST SP 800-171, and handling of CUI and FCI.
  • Experience managing assessment engagements, including budgeting and quality review.

Responsibilities

  • Manage multiple CMMC Level 1 and Level 2 assessments, overseeing scope, budget, and timelines.
  • Serve as primary contact for client executives, advising on CUI and FCI scoping.
  • Direct evaluation of security practices against NIST SP 800-171 and related objectives.
  • Perform final reviews of assessment deliverables for accuracy and compliance.
  • Resolve complex scoping and evidence-sufficiency questions, escalating risks as needed.
  • Supervise and develop Senior Consultants and Consultants, providing feedback and planning.
  • Support business development through proposals and identifying cross-service opportunities.

Benefits

  • Opportunity to shape and execute go-to-market strategies for the CMMC practice.
  • Engagement in thought leadership through webinars and publications.
  • Participation in CMMC-related conferences and industry events.
  • Support for professional development and credential attainment.
  • Hybrid work environment, promoting work-life balance.
Full Job Description
Job Summary:

We are currently seeking an Advisory Manager who will be responsible for overseeing a diverse portfolio of CMMC readiness and certification assessment engagements. This role encompasses the entire process, from initial scoping to the final reporting stages. Own client relationships, engagement economics, and delivery quality while directing teams performing evaluations against NIST SP 800-171 security requirements. Advise executive stakeholders on CUI scoping decisions, remediation strategy, and certification timelines. Contribute to practice growth through business development, methodology enhancement, and development of the CMMC team.

Duties & Responsibilities:
  • Manage multiple concurrent CMMC Level 1 and Level 2 readiness assessments, gap analyses, and certification engagements, owning scope, budget, staffing, and delivery timelines.
  • Serve as the primary point of contact for client executives and program leadership, advising on CUI and FCI scoping decisions, enclave strategy, and paths to certification.
  • Direct and review the evaluation of security practices against NIST SP 800-171 and the assessment objectives in NIST SP 800-171A, including System Security Plans (SSPs), POA&Ms, policies, configurations, and technical evidence.
  • Perform final review of assessment deliverables, workpapers, and reports to ensure technical accuracy, methodological consistency, and compliance with firm and CMMC Ecosystem quality standards.
  • Resolve complex scoping, interpretation, and evidence-sufficiency questions, and escalate risk or independence matters to practice leadership as appropriate.
  • Supervise, coach, and develop Senior Consultants and Consultants, including performance feedback, credential progression, and workload planning.
  • Support business development through scoping calls, proposals, fee estimates, and identification of cross-serve opportunities across the firm's tax, audit, and advisory practices.
  • Partner with practice and marketing leadership to shape and execute the go-to-market strategy for the CMMC practice, including service offering design, target market definition, pricing, and campaign support.
  • Build a presence as a thought leader in the marketplace through webinars, articles, whitepapers, and client briefings on CMMC and evolving DoD cybersecurity requirements.
  • Represent the firm at CMMC-related conferences, industry associations, and CMMC Ecosystem events, developing relationships with clients, prospects, and referral sources.
  • Contribute to practice development by refining assessment methodology, tooling, and templates, and by monitoring changes to CMMC, DFARS [redacted]/-7019/-7020/-7021, FAR 52.204-21, and related DoD requirements.

Education & Experience:
  • Bachelor's degree in information technology, Computer Science, Cybersecurity, Information Systems, or a related field.
  • 7-10 years of experience in IT Audit, Cybersecurity, Risk Advisory, Compliance, or NIST SP 800-171 / CMMC assessments, including at least 2 years in a supervisory or engagement management capacity.
  • Certified CMMC Professional (CCP) certification required; Certified CMMC Assessor (CCA) certification preferred, with the ability to serve on or lead CMMC Assessment Teams.
  • Additional certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor are preferred.
  • S. citizenship required in order to participate in CMMC assessment activities and access client CUI environments.
  • Deep understanding of the CMMC Program, NIST SP 800-171 and 800-171A, and the identification, handling, and protection of CUI and FCI, with the judgment to resolve complex scoping and interpretation issues.
  • Demonstrated experience managing assessment or audit engagements end to end, including budgeting, staffing, risk management, and quality review.
  • Familiarity with IT General Controls (ITGCs), access management, vulnerability management, network security and segmentation, FIPS-validated encryption, logging/monitoring, and cloud service provider considerations including FedRAMP and External Service Provider requirements.
  • Experience presenting assessment results, remediation strategy, and compliance risk to executive leadership, boards, and government contracting stakeholders.
  • Proven ability to build and maintain client relationships and to support proposals, fee estimates, and practice growth initiatives.
  • Experience recruiting, mentoring, and developing high-performing teams, including supporting credential attainment across the CMMC Ecosystem.

#LI - hybrid

About Frazier & Deeter

Frazier & Deeter is a public accounting firm that provides accounting, tax, audit, and advisory services to clients in various industries. The firm was founded in 1981 and is headquartered in Atlanta, Georgia. Frazier & Deeter has additional offices in Nashville, Tennessee; Tampa, Florida; and London, United Kingdom. The firm has been recognized as one of the top accounting firms in the United States by Accounting Today and Inside Public Accounting.
Learn more about Frazier & Deeter
Size
400 employees
Industry
Net Income
$22 million
Founded
1981
5 Year Trend
+25%
Revenue
$108 million

Similar Jobs

More Jobs at Frazier & Deeter

More Business Services Jobs

Find similar CMMC Advisory Manager jobs: