CMMC Assessment Lead
Paragone Solutions, Inc.
Job Description
Job Description
About SecureITSM
SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary
The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities
Plan and Coordinate Assessments (Primary)
- Maintain the master CMMC customer assessment schedule
- Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams
- Conduct readiness reviews and pre-assessment planning meetings
- Track customer assessment milestones, dependencies, and remediation activities
- Manage customer communications related to assessment preparation and scheduling
- Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
- Monitor assessment status and provide executive-level reporting on customer readiness
- Assist customers in understanding assessment scope, boundary definitions, and enclave considerations
- Update implementation statements as needed
- Gather and organize evidentiary artifacts
- Coordinate customer evidence collection activities
- Review SSPs, policies, procedures, and supporting documentation for assessment readiness
- Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
- Prepare assessor-ready evidence packages and artifact repositories
- Conduct internal quality assurance reviews of documentation and evidence
- Identify documentation gaps and coordinate remediation activities
- Support development and maintenance of Plans of Action & Milestones (POA&Ms)
- Ensure documentation aligns with evolving CMMC and NIST guidance
- Attend and actively support customer assessments
- Actively defend implementations and evidence presented to assessors
- Coordinate assessment interviews and technical demonstrations
- Support mock assessments and readiness exercises for customers
- Assist customers in responding to assessor requests and follow-up questions
- Document assessment observations, findings, and remediation actions
- Coordinate post-assessment remediation activities and evidence resubmissions when required
- Serve as a trusted advisor throughout the certification lifecycle
- Conduct SecureITSM’s annual self-assessment activities
- Maintain internal compliance documentation and evidentiary artifacts
- Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
- Assist with internal policy and procedure updates
- Support ongoing continuous monitoring and compliance validation activities
- Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
- Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance
- Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)
- Standardize implementation language and evidence expectations across customer environments
- Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices
- Validate implementation statements for technical accuracy, completeness, and assessor defensibility
- Support continuous improvement of SecureITSM’s proprietary documentation platform and implementation content library
- Develop and maintain assessment preparation Standard Operating Procedures (SOPs)
- Continuously improve evidence collection and assessment support workflows
- Create standardized templates, checklists, and assessment playbooks
- Document lessons learned and incorporate process improvements
- Maintain internal knowledge base articles and operational documentation
- Assist in refining SecureITSM’s proprietary CMMC documentation platform workflows and processes
- U.S. Citizenship required
- Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies
- 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171
- Experience supporting compliance assessments, audits, or certification activities
- Strong understanding of CMMC assessment methodology and evidence requirements
- Excellent technical writing and communication skills
- Strong project management and organizational abilities
- Exceptional attention to detail
- Ability to manage multiple customer engagements simultaneously
- Experience working directly with external assessors, auditors, or regulatory bodies
- Familiarity with secure project management and compliance collaboration platforms
- PMP certification preferred
- CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred
- CISSP, CISM, or equivalent cybersecurity certification preferred
- Experience supporting DoD contractors or working within the Defense Industrial Base (DIB)
- Familiarity with FedRAMP and DFARS View phone number on ziprecruiter.com
- Experience with SIEM, vulnerability management, and endpoint protection technologies
- Strong leadership and customer engagement skills
- Ability to remain composed and professional during high-pressure assessment activities
- Analytical thinker with strong problem-solving capabilities
- Self-motivated with ability to work independently
- Collaborative team player with strong interpersonal skills
- High level of integrity and professionalism
Powered by JazzHR
0mriC7k8Mc
\nCompany DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Company Description
Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
- ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting... ...compliance platform designed to streamline assessment preparation, evidence management, and... ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination...SuggestedFull timeFor contractorsRemote work
- ...Public Sector Compliance to own our FedRAMP, GovRAMP, and CMMC programs. You will lead authorization activities, drive continuous monitoring,... ...FedRAMP program experience, and provide leadership across assessments, documentation, and remediation while advancing our AI‑enabled...Suggested
- Capital One’s Enterprise Learning & Development team seeks a Principal Associate to lead assessments and team effectiveness initiatives, partnering with learning consultants to analyze and design experiences for leaders and teams. You will manage day-to-day operations,...Suggested
- Capital One is seeking a Principal Associate, Assessments & Team Effectiveness, within Enterprise Learning. The role partners with learning consultants to analyze and design learning experiences for people leaders and teams across the organization. The candidate will manage...Suggested
$90.3k - $189.6k
Job Title: Competitive Assessment LeadJob Category: Business Development and MarketingTime Type: Full timeMinimum Clearance Required to Start... ...Travel: Local* * *The Opportunity:As a Competitive Assessment Lead, you will play a key role in strengthening CACI’s strategic...SuggestedContract workWork experience placementLocal areaFlexible hours- ...Security Assessment Lead OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent risk assessments, vulnerability assessments, and analyses of alternatives conducted under this contract. The candidate will lead assessment...Contract workTemporary workFor contractorsLocal area
- ...& Engineering (OUSW(R&E)) Developmental Test, Evaluation, and Assessment (DTE&A) office. The T&E portfolio leverages MITRE’s broad and... ...disciplines to shape new methodologies and tools for modernizing T&E. Leading a diverse MITRE team of approximately 13.5 staff years and...Work experience placementInternshipWork at officeLocal area
- ...Koniag IT Systems, LLC, a Koniag Government Services company , is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other...Local areaFlexible hours
- ...Analyst (BCBA) to join our growing clinical team in Virginia. You will develop individualized ABA treatment plans, conduct functional assessments, and supervise RBTs while collaborating with families and schools. The role emphasizes ethical, evidence-based care, strong...
$220k - $250k
...Job Description Job Description Lead – Assessment and Impact Analytics The Bezos Earth Fund is committed to rigorous analysis and assessment as it strives for the highest impact nature and decarbonization outcomes. The Earth Fund is looking for a technical lead...Full timeWork experience placementLocal areaImmediate startVisa sponsorshipWork visaFlexible hours- ...excited to join that effort. To learn more about our exciting organization, please visit us at are seeking a Security Assessment & Accreditation Lead to join our team and support our client. The ideal candidate is a detail-oriented security professional with strong expertise...Temporary workFor contractorsWork experience placementWork at officeRemote work2 days per week
- ...this Role: Imagineeer is seeking a Lead Data and Architecture professional to serve... ..., NIST SP 800-53, RMF, FedRAMP, and CMMC requirements # Ensure compliance with HIPAA... ...governance including explainability, bias assessment, and operational validation # Integrate...Local areaWork from homeFlexible hours
- ...Job Description Position: Cybersecurity Lead Clearance: Secret Location: Crystal... ..., and develop risk management plans to assess security design adequacy in acquisition processes... ...(AI) - NIST Standards SP 800-171 (CMMC), SP 800-37 & 800-53 (FISMA RMF), SP 800-3...Full timeTemporary workWork at officeRemote workFlexible hours
- ...Barbaricum is a rapidly growing government contractor providing leading-edge support to federal customers, with a particular focus on... .... Join our team. Barbaricum is seeking an experienced Assessment Lead Subject Matter Expert to lead assessment, analytics, and...Contract workFor contractorsWork at office
$130k - $145k
...Gunnison. Salary: $130,000 - $145,000/year Work location : Hybrid, 2-3 days per week on-site in Bethesda, MD. Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based,...Contract workFlexible hours2 days per week3 days per week- ...candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Security Assessment Lead Location:Washington, DC Clearance: Secret Duties and Responsibilities The Security Assessment Lead will oversee...Full timeFor contractors
$135k - $165k
RMF/Assessment & Authorization Team Lead Bethesda, Maryland, United States SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered...Contract workFor contractorsFor subcontractorWork at office- Capital One’s Enterprise Learning & Development team is seeking a Principal Associate, Assessments & Team Effectiveness to lead the Assessments and Team Effectiveness portfolio for people leaders and teams across Capital One. You will partner with learning consultants...
$135k - $165k
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications... ...on contract win. SkyePoint Decisions is seeking a RMF / Assessment & Authentication (A&A) Team Lead to serve as the senior cybersecurity...Contract work- Barbaricum, a government contractor based in Washington, DC, is looking for an experienced Assessment Lead Subject Matter Expert. In this role, you will lead analytics and performance measurement efforts under the Military Community and Family Policy contract. The ideal...Contract workFor contractors
- STG International is looking for a part-time Lead Psychologist in Rockville, MD, to support our Federal Occupational Health contract. This position requires navigating psychological assessments within federal regulations, offering a hybrid work model for candidates in...Contract workPart time
$200k - $250k
...Description Overview Director, Solution Lead – Critical Infrastructure LOCATION:... ...Mission Evidence Packs, Digital Twins, OT/ICS Assessment & Hardening, Exercise & Readiness... ...3, NIST guidance, CISA guidance, RMF, or CMMC. Experience building or integrating partner...Full timeContract workFor contractors- ...value to clients through tailored solutions based on industry-leading practices. We help forward-thinking clients solve problems and... ...ProSidian Consulting at DescriptionProSidian Seeks a Enterprise Assessment Cyber Security Evaluations Task Leader (Key) (SCA Code: -) in...Full timeTemporary workFor contractorsWork at officeFlexible hours
$112k - $179k
ResponsibilitiesPeraton is a leading provider of Information Operations (IO) and Irregular Warfare (IW) capabilities to the U.S. government... ...bring a multidisciplinary approach to planning, executing, and assessing strategic communications operations, this program integrates...Contract workShift work- ...Technical Division is seeking an experienced, highly motivated Lead Mission Modeling and Simulation Engineer to support defense mission... ..., trade studies, Monte Carlo analyses, and sensitivity assessments to evaluate concepts, architectures, technologies, and capability...Work experience placementLocal area
$106.38k - $125.16k
...Experience LeadJob Description SummaryThe Workplace Experience Lead is the key support resource for the Workplace Experience Manager... ...concerns, troubleshoot issues, and follow up as required.Regularly assess space readiness, ensuring workspaces, conference rooms, and...Minimum wageFull timeWork experience placementWork at officeLocal areaFlexible hours- DescriptionSAIC is seeking a Policy and Proposal Lead to support multiple customers within the Department of Navy (DON), including... ...calendar days depending on the Phase.Conduct counterintelligence assessments on potential SBIR/STTR vendors and proposals to identify...Work at officeRemote work
$125.1k - $225.2k
...:Parsons is looking for an amazingly talented Cyber Acquistion Lead to join our team! In this role the selected candidate will:As a... ...cyber priorities and operational requirements.Provide technical assessments of cyber programs, budget initiatives, and resource proposals,...Full timeContract workWork at officeFlexible hours$222k - $332k
...Organization is looking to hire a Navy/Maritime Division Growth Lead who will work in partnership with D&I operations leadership and... ...capture activities, including building industry teams, assessing win probability, and executing customer call plans to shape acquisitionsBachelor...Full timeTemporary workCasual workLocal areaRelocation packageFlexible hours$112k - $179k
ResponsibilitiesPeraton is a leading provider of Information Operations (IO) and Irregular Warfare (IW) capabilities to the U.S. government... ...bring a multidisciplinary approach to planning, executing, and assessing strategic communications operations, this program integrates...Contract workShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CMMC Assessment Lead. Be the first to apply!


