GRC Engineer (CMMC) [Remote]
jobgether
- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Engineer (CMMC) based in the United States.
This role offers the opportunity to help organizations strengthen cybersecurity and achieve demanding federal and defense compliance standards.
You will support clients across CMMC 2.0, NIST SP 800-171, NIST SP 800-53, and FedRAMP programs.
The position combines hands-on compliance engineering, technical documentation, readiness assessments, and client advisory work.
You will translate complex regulatory requirements into practical security actions and clear compliance roadmaps.
Working across SaaS providers, federal contractors, cloud environments, and independent assessment teams, you will manage multiple initiatives with significant client impact.
The environment is fast-paced and collaborative, with strong expectations for ownership, precision, and high-quality delivery.
This is an excellent opportunity for a GRC professional seeking to deepen expertise in federal and defense cybersecurity frameworks.
Accountabilities:
- Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to assess client architectures against federal security requirements.
- Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 requirements, translating regulatory expectations into practical and actionable security milestones.
- Author, maintain, and evaluate key compliance and authorization artifacts, including System Security Plans (SSPs), control implementation narratives, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).
- Conduct detailed readiness assessments and gap analyses to prepare clients for federal Authority to Operate (ATO), Joint Authorization Board (JAB), and CMMC assessment pathways.
- Define and document technical authorization boundaries, data flows, interconnectivity, and shared-responsibility models across FedRAMP and CMMC environments.
- Execute continuous monitoring activities, including vulnerability management tracking, incident response documentation, structural change workflows, and recurring compliance updates.
- Coordinate external assessment activities between clients, Cloud Service Providers, 3PAOs, C3PAOs, and relevant federal stakeholders.
- Develop structured compliance documentation and assessment-readiness materials for CMMC Level 1 and Level 2 engagements.
- Manage multiple client compliance initiatives simultaneously while maintaining strong documentation quality, deadlines, and delivery standards.
- Serve as a trusted client advisor, communicating complex security and compliance concepts clearly and helping stakeholders navigate evolving requirements.
- Stay current with changes to federal cybersecurity frameworks, regulatory requirements, cloud security practices, and defense compliance standards.
Requirements:
- 2+ years of direct experience in GRC, cybersecurity compliance, or related roles with hands-on exposure to FedRAMP, NIST SP 800-53, NIST SP 800-171, or federal authorization lifecycles.
- Practical experience authoring, evaluating, and maintaining federal compliance artifacts, particularly SSPs and POA&Ms.
- Foundational knowledge of CMMC 2.0 and NIST SP 800-171 requirements as they apply to defense contractors and Controlled Unclassified Information (CUI).
- Familiarity with DFARS requirements and CUI protection practices is strongly valued.
- Experience working with government cloud environments such as AWS GovCloud, Azure Government, or Microsoft GCC High.
- Understanding of cloud shared-responsibility models, technical security boundaries, data flows, and secure configurations.
- Experience supporting B2B SaaS providers, federal contractors, regulated technology organizations, or comparable clients.
- Strong project management and organizational skills, with the ability to manage several fast-moving compliance initiatives while maintaining attention to detail.
- Excellent written and verbal English communication skills, with confidence engaging directly with technical teams, clients, assessors, and other stakeholders.
- Ability to translate complex regulatory and technical requirements into clear, actionable guidance.
- Comfortable operating independently in a fast-growing consulting environment where priorities can evolve quickly and ownership is expected.
- CMMC credentials such as Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) are advantageous.
- Certifications such as CISSP, CISM, or CompTIA Security+ are a plus.
- Direct experience supporting JAB or federal Agency ATO processes is highly valued.
- Previous collaboration with 3PAO or C3PAO assessment teams is beneficial.
- Must be authorized to work in the United States without current or future visa sponsorship.
- Able to work a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time, with occasional flexibility as business needs require.
- Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities.
- Reliable high-speed internet and a professional home-office environment suitable for confidential client work and virtual collaboration.
Benefits:
- Competitive base salary with regular performance reviews and merit-based appraisal opportunities.
- Bonus opportunities based on performance.
- Remote-first culture with the flexibility to work from anywhere in the United States.
- Mentorship, training, and structured career development opportunities.
- Reimbursement for approved role-related training and professional certification courses.
- Opportunity to deepen expertise across CMMC, NIST, FedRAMP, and federal cybersecurity compliance.
- Growth opportunities within a fast-paced, early-stage environment.
- Collaborative culture with exposure to complex cybersecurity and compliance engagements.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$129.5k - $145k
...Box you will be on the front lines of this massive shift.WHY BOX NEEDS YOU We are looking for an experienced and driven GRC Controls Automation Engineer who is looking to put their demonstrated awareness of regulatory standards to help bridge compliance requirements,...SuggestedLive inWork at officeShift work3 days per week- ...perspectives, develops our people, and fosters a collaborative team environment.Position SummaryThe GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for...SuggestedFull timeLocal area
$105.4k - $207.8k
Position Summary Cyber SAP Security and GRC Access & Process Control Senior Consultant / Senior Engineering Management SpecialistJoin Deloitte’s Enterprise Security team and help clients strengthen SAP security across enterprise transformation, cloud modernization...SuggestedLocal areaVisa sponsorship- ...intimate knowledge of our customers’ business. About the Role As a GRC Consultant at Network Coverage, you will be part of the GRC Team... ...a client facing capacity, under the guidance of the Director of CMMC Compliance and Chief Advisory Officer. Due to the nature of the work...SuggestedRemote jobWork at officeOverseasFlexible hoursShift work
- Industrious Ventures is seeking a Governance, Risk & Compliance (GRC) Lead to oversee compliance programs like CMMC, FedRAMP, and SOC 2. In this senior role, you'll work closely with various teams to ensure the implementation of technical controls and compliance requirements...SuggestedPermanent employment
$153.6k - $192k
A financial technology company based in New York is looking for a Senior GRC Engineer. The role involves automating compliance processes, supporting risk management initiatives, and collaborating with technical teams to ensure compliance in a growing hybrid environment...$130k - $145k
NinjaTrader in Chicago is looking for a mid-level GRC Engineer to enhance its compliance program through automation. In this hands-on role, you'll integrate compliance workflows and run audits across SOC 2, ISO 27001, and SOX. The ideal candidate has 3-5 years of experience...- Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides...For contractorsCasual workH1bLocal areaRemote workHome office
$180k - $200k
...picture and our vision at Postman.The Opportunity The Security GRC team is responsible for the overall security posture of Postman... ...initiatives to further the growth of Postman.We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to...Work at officeFlexible hours3 days per week$152k - $258k
...small, highly motivated, and focused on engineering excellence. This organization is for individuals... ...Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and... ...programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.COMPENSATION AND BENEFITS:$152...Permanent employmentTemporary work$150k - $160k
...cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent... ...benefits and opportunities we offer. Cybersecurity Engineer - GRC / RSA Archer Position Summary Electrosoft is seeking...Full timeFor contractors- As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across our cybersecurity environment. You will serve as a hands-on platform specialist for ServiceNow IRM, helping optimize...Local area
$200k - $250k
...management.What You'll DoWork cross functionally with Security, IT, Engineering, Product and Legal to provide guidance on security controls... ...levels to accomplish program objectives and further Verkada GRC goals.Implement the development and oversight of required corrective...Full timeWork visaFlexible hoursShift work- A cybersecurity consultancy is seeking a CMMC / NIST Consultant / Analyst to support projects involving CMMC readiness and NIST documentation. This role requires 3-5 years of experience in cybersecurity compliance and strong documentation skills. Ideal candidates will...Remote jobFull timeContract workPart time
$130k - $145k
...journey toward becoming the world's top retail-focused trading platform in the world. What you'll do:We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-on,...Work at officeWorldwideMonday to FridayFlexible hours- ...Job Description Job Description Senior Systems Engineer SAP Security & GRC, immediate start. I am working with a Pharmaceutical client with an urgent requirement for a Senior Systems Engineer to own and drive their SAP Security & GRC roadmap across S/4HANA and adjacent...Immediate startRemote work
$245.92k - $286.9k
Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create...Full timeWork experience placementWork at officeFlexible hours- Role Description Workstreet is seeking a Sr. Engineer, GRC Engineering (Government) to serve as a high-touch, executive-level strategic partner for organizations navigating federal compliance frameworks. This role centers on delivering an exceptional client experience,...Full timeVisa sponsorship
- Hotman Group is seeking a CMMC / NIST Consultant / Analyst to support client projects involving CMMC, SSP development, NIST SP 800-171,... ...activities What we’re looking for 3-5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work Hands‑on...Full timeContract workPart timeRemote work
- Northwood Space is seeking a Governance, Risk & Compliance Lead to spearhead their compliance program focusing on CMMC, FedRAMP, and ITAR. You will coordinate with internal teams and act as the primary contact for government clients, ensuring the company meets rigorous...
- ...seeking a Governance, Risk & Compliance Lead to own and drive the company’s compliance program across CMMC, FedRAMP, SOC 2, and ITAR. You will partner with security engineering, network, and product teams to translate regulatory requirements into operational controls. In...
$180k - $200k
...enabling collaboration to create better APIs, faster. The Security GRC team is responsible for the overall security posture of Postman... ...initiatives to grow Postman. What Youind We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to...Work at officeFlexible hours3 days per week$148k - $175k
...third year in a row. In 2022, Ro was listed as a CNBC Disruptor 50. +The Role: The Governance Risk and Compliance Engineer role will be a core member of Ro’s GRC team. This is a remote, Individual Contributor role. The GRC team enables Ro to manage risk by vigorously...Local areaRemote workFlexible hours- ...startup, we specialize in a wide range of GRC (governance, risk, and compliance)... ...frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.... ...Opportunity Workstreet is seeking a Manager, GRC Engineering who leads with a client-first mindset and...H1bRemote workHome office
- A prestigious law firm is seeking a Governance, Risk, and Compliance (GRC) Engineer with Microsoft Purview expertise to lead data governance, security, and compliance initiatives. This remote, full-time role supports the Office of General Counsel, eDiscovery, IT, and Information...Remote jobFull timeWork at office
- SpaceXAI seeks an experienced GRC Engineer focused on fintech regulation to scale compliance across PCI DSS, NYDFS, and FFIEC. You will architect Compliance-as-Code, automate evidence collection, and partner with engineering to embed controls into the platform. The role...
- ...population. The Security Governance, Risk and Compliance team (GRC) is a sub-team of Security. Our job is to make sure that Cloudflare... ...posture to auditors and customers. What you’ll do Automation & Engineering: Develop and implement automated solutions to improve GRC...Local areaRemote work
- Workstreet is seeking a GRC Engineer (NIST 800-53/FedRAMP) to join our government delivery practice. You will support client-facing compliance initiatives, author authorization artifacts, and run gap assessments across the A&A lifecycle. As a key technical contributor,...Remote work
$130k - $170k
...community of collaborators, We speak up, We think big and do small, and We are tenacious. Role Overview ButterflyMX is seeking a GRC Engineer who is equal parts practitioner and builder. You will own the governance, risk, and compliance program. But more importantly,...Temporary workRemote workWorldwideFlexible hours- SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and regulatory compliance to scale our GRC program. You will architect systems that automate trust, balancing rigorous standards with rapid growth, and you will partner...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Engineer (CMMC) [Remote]. Be the first to apply!
- senior devops engineer remote United States
- medical coding remote United States
- remote medical coding supervisor United States
- remote virtual United States
- remote contract attorney United States
- clinical data manager remote United States
- remote servicenow developer United States
- administrative assistant remote United States
- remote animation United States
- remote video editor United States



