Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

CMMC Assessment Lead

Paragone Solutions, Inc.

Job Description

Job Description

About SecureITSM
SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.

We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities.

Location and Travel: This is a remote position with occasional travel required to support customer assessments.

Position Summary
The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership.

This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible.

Key Responsibilities
Plan and Coordinate Assessments (Primary)
  • ​​​​​​​​​​​​​​​​​​​​ Maintain the master CMMC customer assessment schedule
  • Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams
  • Conduct readiness reviews and pre-assessment planning meetings
  • Track customer assessment milestones, dependencies, and remediation activities
  • Manage customer communications related to assessment preparation and scheduling
  • Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
  • Monitor assessment status and provide executive-level reporting on customer readiness
  • Assist customers in understanding assessment scope, boundary definitions, and enclave considerations ​​​​​​​​​​​​​​
Prepare Assessment Packages (Primary)
  • Update implementation statements as needed
  • Gather and organize evidentiary artifacts
  • Coordinate customer evidence collection activities
  • Review SSPs, policies, procedures, and supporting documentation for assessment readiness
  • Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
  • Prepare assessor-ready evidence packages and artifact repositories
  • Conduct internal quality assurance reviews of documentation and evidence
  • Identify documentation gaps and coordinate remediation activities
  • Support development and maintenance of Plans of Action & Milestones (POA&Ms)
  • Ensure documentation aligns with evolving CMMC and NIST guidance
Support Customer Assessments (Primary)
  • Attend and actively support customer assessments
  • Actively defend implementations and evidence presented to assessors
  • Coordinate assessment interviews and technical demonstrations
  • Support mock assessments and readiness exercises for customers
  • Assist customers in responding to assessor requests and follow-up questions
  • Document assessment observations, findings, and remediation actions
  • Coordinate post-assessment remediation activities and evidence resubmissions when required
  • Serve as a trusted advisor throughout the certification lifecycle
Maintain SecureITSM’s Authorization and Compliance (Secondary)
  • Conduct SecureITSM’s annual self-assessment activities
  • Maintain internal compliance documentation and evidentiary artifacts
  • Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
  • Assist with internal policy and procedure updates
  • Support ongoing continuous monitoring and compliance validation activities
  • Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
Implementation Statement Management (Secondary)
  • Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance
  • Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)
  • Standardize implementation language and evidence expectations across customer environments
  • Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices
  • Validate implementation statements for technical accuracy, completeness, and assessor defensibility
  • Support continuous improvement of SecureITSM’s proprietary documentation platform and implementation content library
Maintain and Improve Standard Operating Procedures (Secondary)
  • Develop and maintain assessment preparation Standard Operating Procedures (SOPs)
  • Continuously improve evidence collection and assessment support workflows
  • Create standardized templates, checklists, and assessment playbooks
  • Document lessons learned and incorporate process improvements
  • Maintain internal knowledge base articles and operational documentation
  • Assist in refining SecureITSM’s proprietary CMMC documentation platform workflows and processes
Required Qualifications
  • U.S. Citizenship required
  • Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies
  • 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171
  • Experience supporting compliance assessments, audits, or certification activities
  • Strong understanding of CMMC assessment methodology and evidence requirements
  • Excellent technical writing and communication skills
  • Strong project management and organizational abilities
  • Exceptional attention to detail
  • Ability to manage multiple customer engagements simultaneously
  • Experience working directly with external assessors, auditors, or regulatory bodies
  • Familiarity with secure project management and compliance collaboration platforms
Preferred Qualifications
  • PMP certification preferred
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred
  • CISSP, CISM, or equivalent cybersecurity certification preferred
  • Experience supporting DoD contractors or working within the Defense Industrial Base (DIB)
  • Familiarity with FedRAMP and DFARS View phone number on ziprecruiter.com
  • Experience with SIEM, vulnerability management, and endpoint protection technologies
Key Attributes
  • Strong leadership and customer engagement skills
  • Ability to remain composed and professional during high-pressure assessment activities
  • Analytical thinker with strong problem-solving capabilities
  • Self-motivated with ability to work independently
  • Collaborative team player with strong interpersonal skills
  • High level of integrity and professionalism ​​​​​​​
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law.

#ZR

Powered by JazzHR

0mriC7k8Mc

\nCompany Description

Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.

Company Description

Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the CMMC Assessment Lead in McLean, VA vacancy
  • $120k - $160k

    IT State Lead - Security Controls Assessments Sky Solutions is a trusted partner in government contracting, empowering federal agencies with cutting-edge IT solutions. Our expertise spans AI-first enablement, delivering innovative solutions and advanced cybersecurity,... 
    Suggested
    Full time
    Contract work
    Local area
    Remote work

    Sky Solutions LLC

    Mc Lean, VA
    5 days ago
  • Capital One’s Enterprise Learning & Development team seeks a Principal Associate to lead assessments and team effectiveness initiatives, partnering with learning consultants to analyze and design experiences for leaders and teams. You will manage day-to-day operations,... 
    Suggested

    Information Technology Senior Management Forum

    Mc Lean, VA
    2 days ago
  •  ...Security Assessment Lead OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent risk assessments, vulnerability assessments, and analyses of alternatives conducted under this contract. The candidate will lead assessment... 
    Suggested
    Contract work
    Temporary work
    For contractors
    Local area

    OCH Technologies LLC

    Washington DC
    5 days ago
  •  ...awarded, this position may not be filled. Koniag IT Systems, LLC, a Koniag Government Services company , is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The... 
    Suggested
    Contract work
    Local area
    Flexible hours

    Koniag Government Services

    Washington DC
    2 days ago
  •  ...candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Security Assessment Lead Location:Washington, DC Clearance: Secret   Duties and Responsibilities The Security Assessment Lead will oversee... 
    Suggested
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago
  •  ...urgently hiring a hands-on Cyber Security Lead to lead and execute the company’s...  ...compliance with NIST 800-53, NIST 800-171, CMMC, CMMI, ISO 9K, ISO 20K, ISO 27K, RMF, and...  ...with auditors and assessors Conduct risk assessments, vulnerability analysis, and risk mitigation... 
    Full time
    Immediate start

    Atlas Management Services LLC

    Arlington, VA
    7 days ago
  • $220k - $250k

     ...Job Description Job Description Lead – Assessment and Impact Analytics The Bezos Earth Fund is committed to rigorous analysis and assessment as it strives for the highest impact nature and decarbonization outcomes. The Earth Fund is looking for a technical lead... 
    Full time
    Work experience placement
    Local area
    Immediate start
    Visa sponsorship
    Work visa
    Flexible hours

    Bezos Earth Fund

    Washington DC
    17 days ago
  •  ...excited to join that effort. To learn more about our exciting organization, please visit us at are seeking a Security Assessment & Accreditation Lead to join our team and support our client. The ideal candidate is a detail-oriented security professional with strong expertise... 
    Temporary work
    For contractors
    Work experience placement
    Work at office
    Remote work
    2 days per week

    Unissant

    Herndon, VA
    25 days ago
  •  ...Barbaricum is a rapidly growing government contractor providing leading-edge support to federal customers, with a particular focus on...  .... Join our team. Barbaricum is seeking an experienced Assessment Lead Subject Matter Expert to lead assessment, analytics, and... 
    Contract work
    For contractors
    Work at office

    Barbaricum

    Washington DC
    17 days ago
  • $110.18k - $183.63k

     ...want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Assessment and Authorization (A&A) Lead to join our team in Rockville, Maryland (US-MD), United States (US). Job Summary: NTT DATA is seeking an... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA Services

    Rockville, MD
    3 days ago
  •  ...Job Description Position: Cybersecurity Lead Clearance: Secret Location: Crystal...  ..., and develop risk management plans to assess security design adequacy in acquisition processes...  ...(AI) -       NIST Standards SP 800-171 (CMMC), SP 800-37 & 800-53 (FISMA RMF), SP 800-3... 
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    ADEPT Force Group Incorporated

    Arlington, VA
    25 days ago
  •  ...this Role:   Imagineeer is seeking a Lead Data and Architecture professional to serve...  ..., NIST SP 800-53, RMF, FedRAMP, and CMMC requirements  # Ensure compliance with HIPAA...  ...governance including explainability, bias assessment, and operational validation  # Integrate... 
    Local area
    Work from home
    Flexible hours

    IMAGINEEER LLC

    Arlington, VA
    25 days ago
  • SUMMARY We are seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring activities for federal information systems. The successful candidate will possess strong knowledge of the NIST Risk... 

    Intellect Solutions LLC

    Rockville, MD
    2 days ago
  • $135k - $165k

    RMF/Assessment & Authorization Team Lead Bethesda, Maryland, United States SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered... 
    Contract work
    For contractors
    For subcontractor
    Work at office

    SkyePoint Decisions

    Bethesda, MD
    3 days ago
  • $75k - $100k

     ...Description The Business Development & Capture Lead supports the opportunity lifecycle - from...  ...: capture plan inputs, competitive assessments, and gate review prep Engage customers to...  ...compliance frameworks (RMF, CMMC, ISO 27001) APMP certification or Shipley... 
    Contract work
    For subcontractor
    Second job

    Jimmy Jazz

    Falls Church, VA
    6 days ago
  • $200k

    Cybersecurity & Compliance Lead Position Overview One of our clients is seeking a Cybersecurity & Compliance Lead to oversee CMMC management and security infrastructure operations....  ...manage a supply chain cybersecurity risk assessment framework to identify, evaluate, and... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Second job
    Local area

    10 BTI Solutions, Inc.

    Arlington, VA
    6 days ago
  •  ...and Families' (ACF) Office of Head Start. MSG is seeking CLASS Leads to join a team responsible for gathering, understanding, and reporting...  ...as needed to build skills of reviewers conducting CLASS assessments. Dual code CLASS Reviewer Consultants as needed and debrief with... 
    Contract work
    For contractors
    Work at office
    Remote work
    Long distance

    Manhattan Strategy Group

    Bethesda, MD
    6 days ago
  • Unison is seeking a Security Governance Manager to lead our security governance program, coordinating FedRAMP, IL4, and CMMC authorizations while reporting to the CISO....  ..., control-owner collaboration, and annual assessment support to keep audits moving with discipline... 

    Unison

    Mc Lean, VA
    4 days ago
  • $200k - $250k

     ...Description Overview Director, Solution Lead – Critical Infrastructure LOCATION:...  ...Mission Evidence Packs, Digital Twins, OT/ICS Assessment & Hardening, Exercise & Readiness...  ...3, NIST guidance, CISA guidance, RMF, or CMMC. Experience building or integrating partner... 
    Full time
    Contract work
    For contractors

    Astrion

    Arlington, VA
    25 days ago
  •  ...an individual basis. Provide continuous coaching of the staff so they perform at the highest levels. Meet with direct reports to assess their performance and progress against expectations. Write and communicate performance reviews. Primary point of contact for offshore... 
    For contractors

    MultiPlan

    Mc Lean, VA
    4 days ago
  •  ...seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role...  ...operations across federal and IC environments. Conduct full‑scope assessments, exploit development, and hands‑on attack simulations.... 
    Full time

    Apogee Global Rms

    Arlington, VA
    1 day ago
  • $180k - $190k

     ...source, single-source, fragile-source, foreign-source, and long-lead dependencies.Segment suppliers based on:Effect on program deliveries...  ...qualification, first-article, quality, and delivery milestones.Assess alternate-source, second-source, or redesign options when the... 
    Contract work
    Temporary work
    For contractors
    Local area
    Remote work

    ACT-1

    Arlington, VA
    8 hours ago
  • $165k - $180k

     .... Great Hill Solutions is seeking a highly motivated Team Lead will serve in an advisory capacity to oversight to the team members...  ...and analysis to prepare and execute program reviews and assessments. Collect and organize data sent by email from customers and... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Flexible hours

    Seneca Holdings LLC

    Arlington, VA
    8 hours ago
  •  ...Studio Leads at JETSET Pilates are dynamic team members that help clients and assist instructors. Studio Leads are responsible for...  ...process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification... 
    Day shift
    Afternoon shift

    JetSet Pilates

    Falls Church, VA
    4 days ago
  •  ...MacMore is looking to fill a part-time position for an Experienced Lead eDiscovery Consultant/ Project Manager for a pending contract...  ...control on eDiscovery lifecycle. Document quality control assessments. Adhere to FCA’s policies, processes, and procedures in performance... 
    Contract work
    Part time
    For contractors
    Work at office

    MacMore

    McLean, VA
    19 days ago
  •  ...assets and ensure regulatory compliance. The role includes monitoring threats, implementing controls, supporting NIST SP 800-171/CMMC, and leading risk assessments across Microsoft 365, Azure, Entra ID, and on-prem #J-18808-Ljbffr Tlingit Haida Tribal Business Corporation
    Remote job

    Tlingit Haida Tribal Business Corporation

    Falls Church, VA
    3 days ago
  • $197.3k - $225.1k

     ...Overview Lead Cybersecurity Product Management (Network Security) Capital One is seeking a technical security product leader to...  ...addressing business and technology risks Develop and lead RFI/RFPs to assess the market and/or procure effective cyber solutions Lead... 
    Full time
    Part time
    H1b
    Local area

    Capital One

    McLean, VA
    19 days ago
  •  ...Description: Seeking an experienced Cross Domain Solution CDS Program Lead to serve as the technical and programmatic lead for the...  ...RMF A&A lifecycle for CDS environment Manage vulnerability assessment and penetration testing of the CDS environment Manage... 
    Remote work
    Flexible hours

    Sedulous Consulting Services LLC

    Arlington, VA
    4 days ago
  • $112.94k - $188.24k

     ...organization, apply now. We are currently seeking a IT CPIC Management Lead - Team Lead - SECRET Clearance to join our team in Arlington,...  ...and technical needs for cross-team collaboration. Assessing and improving business processes. NTT DATA provides a reasonable... 
    Temporary work
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Arlington, VA
    10 days ago
  •  ...Description Job Description Supply Chain Risk Management (SCRM) Lead Falls Church, Virginia Full-time Important Notice:...  ...develop and implement supply chain risk management programs assessing and mitigating risks from third-party vendors, commercial software... 
    Full time
    Contract work
    Work at office
    Remote work

    ZTI Solutions, LLC

    Falls Church, VA
    25 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to CMMC Assessment Lead. Be the first to apply!