U.S. citizenship required for access to sensitive government information.
5+ years of experience as a compliance analyst in the Defense Industrial Base.
Strong understanding of NIST 800-171 controls and their implementation.
Current CMMC certification required (RP, CCP, or CCA).
Experience in audit, compliance, or consulting roles.
Highly detail-oriented and organized, with a track record of audit-ready documentation.
Experience supporting a Managed Service Provider (MSP).
Responsibilities
Lead NIST 800-171a and CMMC gap assessments, including evidence collection and remediation planning.
Enhance assessment activities utilizing AI-enabled tools for efficiency and accuracy.
Assist clients in developing compliant policies, procedures, and documentation.
Recommend and coordinate remediation strategies to address compliance gaps.
Facilitate communication and collaboration between analysts and client stakeholders.
Act as primary liaison with C3PAO auditors during CMMC assessments.
Benefits
Hybrid work environment for flexibility and collaboration.
Comprehensive benefits package with competitive salary.
Supportive and casual workplace culture.
Opportunities for professional development and advancement.
Full Job Description
Duties/Responsibilities:
Lead and oversee NIST 800-171a and CMMC gap assessment engagements, including evidence collection, control validation, environment reviews, and remediation planning.
Utilize AI-enabled tools to enhance efficiency and accuracy across assessment activities, including evidence gathering, documentation development, and compliance validation.
Assist clients in developing and maintaining compliant policies, procedures, and required documentation such as Network Design Documents, Software Whitelists, POAMs, and SSPs.
Provide recommendations and coordinate remediation efforts to address identified compliance gaps, collaborating closely with Cybersecurity, Engineering, and Support teams to ensure proper implementation and testing.
Facilitate effective communication and collaboration across internal analysts, technical teams, and client stakeholders to ensure alignment and consistent execution throughout the engagement lifecycle.
Serve as a primary liaison with C3PAO auditors during CMMC Level 2 assessments, supporting audit preparation, evidence submission, and clarifications as needed.
Qualifications
Due to the nature of this role, candidates must present proof of U.S. citizenship prior to hire in accordance with federal regulations governing access to sensitive government information.
Minimum of 5 years of experience within the Defense Industrial Base as a compliance analyst or in a closely related cybersecurity or audit function.
Strong technical background with the ability to understand and articulate not only what NIST 800-171 controls require, but how they are implemented and validated in practice.
Current CMMC certification required: RP, CCP, or CCA.
Previous experience in audit, compliance, or consulting role
Highly detail oriented, process-driven, and well-organized with demonstrated ability to produce accurate and audit-ready compliance documentation.
Prior experience working for or directly supporting a Managed Service Provider (MSP).
Comfortable presenting to clients, senior leaders, and internal teams, with strong professional verbal and written communication skills.
Familiarity with the NIST Risk Management Framework (RMF) and the CMMC compliance ecosystem, including assessment methodologies and audit expectations.
Self-starter with a proactive mindset and the ability to independently identify areas for support or process improvement
What We Offer
Salary range of $90,000-$110,000, commensurate with experience.
Hybrid work environment offering flexibility while supporting collaboration.
Competitive salary and comprehensive benefits package.
A casual, friendly, and supportive workplace culture.
Professional development support, including certification growth and advancement opportunities.