| Position Summary We are seeking a CMMC Compliance & Cybersecurity Manager to lead our organization’s readiness for certification under the U.S. Department of Defense Cybersecurity Maturity Model Certification (CMMC) framework. This role will be responsible for developing, implementing, and maintaining the policies, controls, and documentation required to achieve and sustain compliance—primarily aligned with NIST SP 800-171. The ideal candidate combines technical cybersecurity knowledge, audit/compliance experience, and strong project management skills to drive cross-functional execution. Key Responsibilities: CMMC Program Leadership - Lead end-to-end CMMC readiness and certification efforts
- Interpret and implement CMMC requirements across the organization
- Serve as the primary internal owner of all CMMC-related activities
Compliance & Documentation - Develop and maintain:
- System Security Plan (SSP)
- Policies, procedures, and control documentation
- Plans of Action & Milestones (POA&M)
- Map organizational controls to NIST SP 800-171 requirements
- Ensure audit-ready documentation and evidence collection
Audit Preparation & Management - Prepare for and support third-party assessments (C3PAO audits)
- Act as the primary liaison during audits
- Coordinate internal responses to audit findings
Risk Management & Remediation - Conduct gap assessments and risk analyses
- Prioritize and track remediation efforts
- Partner with IT and business units to implement required controls
Technical Oversight - Collaborate with IT to ensure proper implementation of:
- Access controls (MFA, least privilege)
- Endpoint and network security
- Logging and monitoring
- Data protection for Controlled Unclassified Information (CUI)
Preferred Education & Certification(s): - Bachelor's Degree, preferably in Cybersecurity, Information Technology or similar field
- Certified CMMC Professional (CCP)
- Certified CMMC Assessor (CCA)
- CISSP (Certified Information Systems Security Professional)
- CISA (Certified Information Systems Auditor)
- CISM (Certified Information Security Manager)
- Other relevant cybersecurity or compliance certifications
|