CMMC Compliance Analyst

Lumen

$105K — $155K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • CMMC Registered Practitioner Advanced (RPA) certification required
  • CMMC Certified Professional (CCP) certification to be obtained within the first six months
  • Experience with CMMC Level 2 C3PAO assessments essential
  • Strong grasp of NIST SP 800-171 controls and compliance documentation
  • Well-versed in FAR, DFARS, and requirements for Defense Industrial Base contractors
  • Proven ability to work in a detail-oriented, compliance-driven environment

Responsibilities

  • Execute continuous monitoring to ensure compliance with NIST SP 800-171
  • Maintain and manage audit-ready evidence repositories
  • Conduct control assessments and track remediation efforts
  • Support the management of Plans of Actions and Milestones (POA&Ms)
  • Utilize Governance, Risk, and Compliance (GRC) tools for monitoring and reporting
  • Collaborate with team members to implement and sustain security controls
  • Prepare and assist in external assessments and certification processes

Benefits

  • Comprehensive health and life insurance
  • Voluntary lifestyle benefits
  • Support for physical, mental, emotional, and financial wellbeing
  • Short-term and long-term incentive bonuses available
Full Job Description
The Role

Lumen is looking for an experienced cybersecurity compliance professional to support the ongoing continuous monitoring and compliance operations of a CMMC Level 2 (L2) assessed enclave. These roles are critical to maintaining audit readiness, sustaining compliance with NIST SP 800-171, and supporting successful C3PAO reassessments.

The ideal candidates bring hands-on experience supporting a successful CMMC Level 2 assessment and possess a strong understanding of control implementation, evidence management, and continuous monitoring practices within a regulated DoD environment.

Location

This is a remote opportunity open to candidates located anywhere in the U.S.

The Main Responsibilities

  • Execute continuous monitoring activities across a CMMC L2 enclave, ensuring ongoing compliance with NIST SP 800-171 controls
  • Maintain audit-ready evidence repositories, including policies, procedures, and technical artifacts
  • Perform periodic control assessments, validation, and remediation tracking
  • Support POA&M management, including identification, documentation, and closure of findings
  • Leverage GRC tools to manage controls, track compliance status, and maintain evidence
  • Collaborate with system owners, engineers, and ISSOs to ensure proper control implementation and sustainment
  • Prepare for and support C3PAO assessments, surveillance reviews, and re-certification activities
  • Track and report compliance status, risks, and metrics to leadership
  • Assist in updating SSPs, network diagrams, data flow diagrams, and supporting documentation


What We Look For in a Candidate

Required Qualifications:
  • CMMC Registered Practitioner Advanced (RPA)
  • CMMC Certified Professional (CCP) certification within the first six months
  • Demonstrated experience supporting a successful CMMC Level 2 C3PAO assessment
  • Experience with continuous monitoring, audit preparation, and compliance documentation
  • Strong working knowledge of NIST SP 800-171 controls and assessment objectives
  • Working knowledge of FAR, DFARS, and CMMC-related cybersecurity and contracting requirements for Defense Industrial Base contractors.
  • Familiarity with evolving CMMC requirements
  • Experience integrating GRC platforms into continuous monitoring workflows and reporting
  • Familiarity with POA&M management and remediation processes
  • Ability to work in a structured, compliance-driven environment with strong attention to detail


Preferred Qualifications:
  • CMMC Certified Assessor (CCA) certification
  • Experience supporting FedRAMP Moderate or High ATO environments
  • Hands-on experience using GRC tools such as ServiceNow IRM, Diligent, Archer, or similar platforms
  • Understanding of cloud environments (Azure Gov, AWS GovCloud) in regulated enclaves


Compensation

This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.

Location Based Pay Ranges

$105,786 - $141,047 in these states: AL AR AZ FL GA IA ID IN KS KY LA ME MO MS MT ND NE NM OH OK PA SC SD TN UT VT WI WV WY
$111,074 - $148,099 in these states: CO HI MI MN NC NH NV OR RI
$116,364 - $155,152 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA

Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process.

Learn more about Lumen's:Benefits
Bonus Structure

#LI-Remote

Requisition #: 342277

Similar Jobs

More Jobs at Lumen

More Information Technology Jobs

Find similar CMMC Compliance Analyst jobs: