CMMC Assessment Lead
Paragone Solutions, Inc.
Job Description
Job Description
About SecureITSM
SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary
The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities
Plan and Coordinate Assessments (Primary)
- Maintain the master CMMC customer assessment schedule
- Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams
- Conduct readiness reviews and pre-assessment planning meetings
- Track customer assessment milestones, dependencies, and remediation activities
- Manage customer communications related to assessment preparation and scheduling
- Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
- Monitor assessment status and provide executive-level reporting on customer readiness
- Assist customers in understanding assessment scope, boundary definitions, and enclave considerations
- Update implementation statements as needed
- Gather and organize evidentiary artifacts
- Coordinate customer evidence collection activities
- Review SSPs, policies, procedures, and supporting documentation for assessment readiness
- Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
- Prepare assessor-ready evidence packages and artifact repositories
- Conduct internal quality assurance reviews of documentation and evidence
- Identify documentation gaps and coordinate remediation activities
- Support development and maintenance of Plans of Action & Milestones (POA&Ms)
- Ensure documentation aligns with evolving CMMC and NIST guidance
- Attend and actively support customer assessments
- Actively defend implementations and evidence presented to assessors
- Coordinate assessment interviews and technical demonstrations
- Support mock assessments and readiness exercises for customers
- Assist customers in responding to assessor requests and follow-up questions
- Document assessment observations, findings, and remediation actions
- Coordinate post-assessment remediation activities and evidence resubmissions when required
- Serve as a trusted advisor throughout the certification lifecycle
- Conduct SecureITSM’s annual self-assessment activities
- Maintain internal compliance documentation and evidentiary artifacts
- Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
- Assist with internal policy and procedure updates
- Support ongoing continuous monitoring and compliance validation activities
- Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
- Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance
- Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)
- Standardize implementation language and evidence expectations across customer environments
- Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices
- Validate implementation statements for technical accuracy, completeness, and assessor defensibility
- Support continuous improvement of SecureITSM’s proprietary documentation platform and implementation content library
- Develop and maintain assessment preparation Standard Operating Procedures (SOPs)
- Continuously improve evidence collection and assessment support workflows
- Create standardized templates, checklists, and assessment playbooks
- Document lessons learned and incorporate process improvements
- Maintain internal knowledge base articles and operational documentation
- Assist in refining SecureITSM’s proprietary CMMC documentation platform workflows and processes
- U.S. Citizenship required
- Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies
- 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171
- Experience supporting compliance assessments, audits, or certification activities
- Strong understanding of CMMC assessment methodology and evidence requirements
- Excellent technical writing and communication skills
- Strong project management and organizational abilities
- Exceptional attention to detail
- Ability to manage multiple customer engagements simultaneously
- Experience working directly with external assessors, auditors, or regulatory bodies
- Familiarity with secure project management and compliance collaboration platforms
- PMP certification preferred
- CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred
- CISSP, CISM, or equivalent cybersecurity certification preferred
- Experience supporting DoD contractors or working within the Defense Industrial Base (DIB)
- Familiarity with FedRAMP and DFARS View phone number on ziprecruiter.com
- Experience with SIEM, vulnerability management, and endpoint protection technologies
- Strong leadership and customer engagement skills
- Ability to remain composed and professional during high-pressure assessment activities
- Analytical thinker with strong problem-solving capabilities
- Self-motivated with ability to work independently
- Collaborative team player with strong interpersonal skills
- High level of integrity and professionalism
Powered by JazzHR
0mriC7k8Mc
\nCompany DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Company Description
Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
- RMGS, Inc. is recruiting a Threat & Risk Assessment Specialist based in Quito, Ecuador, with in-country travel required and contingent upon contract award. The role focuses on designing structured threat-assessment methodologies and establishing risk-classification criteria...SuggestedContract work
- Position Overview We are seeking an applied behavioral scientist with expertise in non-invasive behavioral assessment, nonverbal communication, kinesics, and interview dynamics. This role will help translate behavioral research into practical measurement methods, product...SuggestedWork from homeFlexible hours
- Capital One’s Enterprise Learning & Development team seeks a Principal Associate to lead assessments and team effectiveness initiatives, partnering with learning consultants to analyze and design experiences for leaders and teams. You will manage day-to-day operations,...Suggested
- ...We are hiring a Cybersecurity Lead with CISO Potential The Cybersecurity Lead we're looking... ...with NIST 800-53, NIST 800-171, CMMC, CMMI, ISO 9K, ISO 20K, ISO 27K, RMF, and... ...with auditors and assessors Conduct risk assessments, vulnerability analysis, and risk mitigation...SuggestedFull timeWork at office
$110.18k - $183.63k
...want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Assessment and Authorization (A&A) Lead to join our team in Rockville, Maryland (US-MD), United States (US).Job Summary: NTT DATA is seeking an experienced...SuggestedFull timeTemporary workWork at officeRemote workFlexible hours$229.9k - $262.4k
...to our associates. What You’ll Do: Lead, mentor, and develop associates by setting... ...Lead cross-domain cybersecurity risk assessments and capability reviews, ensuring alignment... ...concepts such as NIST CSF, MITRE ATT&CK, CMMC, FedRAMP, etc. ~7+ years of experience...Full timePart timeH1bLocal area$220k - $250k
...Job Description Job Description Lead – Assessment and Impact Analytics The Bezos Earth Fund is committed to rigorous analysis and assessment as it strives for the highest impact nature and decarbonization outcomes. The Earth Fund is looking for a technical lead...Full timeWork experience placementLocal areaImmediate startVisa sponsorshipWork visaFlexible hours- ...Barbaricum is a rapidly growing government contractor providing leading-edge support to federal customers, with a particular focus on... .... Join our team. Barbaricum is seeking an experienced Assessment Lead Subject Matter Expert to lead assessment, analytics, and...Contract workFor contractorsWork at office
$155k - $175k
...foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Title : Vulnerability Assessment (VA) Team Lead (CBP) Clearance : Active Top Secret Clearance with SCI eligibility, ability to obtain and maintain a CBP Background...Temporary workImmediate startRelocation package- We are the leading provider of professional services to the middle market globally, our purpose... ...Communicate effectively with prospects, assess needs, and develop clear and accurate... ...Cybersecurity Maturity Model Certification (CMMC) Internal controls (DFARS business...Contract workFor contractorsLocal area
- ...an individual basis. Provide continuous coaching of the staff so they perform at the highest levels. Meet with direct reports to assess their performance and progress against expectations. Write and communicate performance reviews. Primary point of contact for offshore...For contractors
$200k - $250k
...Description Overview Director, Solution Lead – Critical Infrastructure Resilience... ...Mission Evidence Packs, Digital Twins, OT/ICS Assessment & Hardening, Exercise & Readiness... ...3, NIST guidance, CISA guidance, RMF, or CMMC. Experience building or integrating partner...Full timeContract workFor contractors- ...Description The Role: Location: Tysons Corner, VA The Floor Lead plays a pivotal role on our store leadership team, driving the... ...successful integration of new talent to our store teams. Assessing : Validate the regular and accurate assessment of our people...Full timeWeekend workAfternoon shift
- ...value to clients through tailored solutions based on industry-leading practices. We help forward-thinking clients solve problems and... ...ProSidian Consulting at DescriptionProSidian Seeks a Enterprise Assessment Cyber Security Evaluations Task Leader (Key) (SCA Code: -) in...Full timeTemporary workFor contractorsWork at officeFlexible hours
- Position Title: Supply Chain and Supplier Management Lead Location: Arlington, Virginia Category: FundedSchedule (FT/PT): Full Time Travel... ...unsupported assertions. Supplier Performance and Recovery: Assess supplier capability, capacity, production readiness, quality...Full timeTemporary workFor contractorsLocal areaRemote workFlexible hoursShift work
- ...public interest. With objectivity and integrity at our core, we lead federally funded research and development centers for U.S.... ...experiments, trade studies, Monte Carlo analyses, and sensitivity assessments to evaluate concepts, architectures, technologies, and capability...Work experience placementLocal area
$86.8k - $198k
...our strategic deterrence and nuclear integration team, you’ll lead the analysis and coordination of our client's official policy and... ....In this role, you'll be responsible for drafting and assessing treaties and arms control agreements that directly influence the...Full timeContract workPart timeWork at officeLocal areaRemote work- ...developing necessary software tools, and performing thorough and timely assessments to inform technology and acquisition governance decisions to... ...in the future.We have a near-term need for a Program Lead SETA to provide onsite support out of Arlington, VA.ResponsibilitiesThe...Contract workWork at officeFlexible hours
$139.5k - $188.7k
...Amazon’s regulatory reports in a rapidly evolving global environment. This will involve establishing external reporting processes, assessing and collecting key metrics from partner teams, resolving reporting decisions, and drafting disclosures. You will work cross-...WorldwideFlexible hours- ...Oracle practice (.)You Are:A senior Oracle Utilities Integration Lead who brings both the architectural vision and the hands-on... ...the primary integration SME for cross-system impact analysis — assessing how core Oracle CCS/C2M configuration and solution changes affect...Full timeWork experience placementLive inWork at officeLocal areaRemote work
$99k - $225k
...Join us. The world can’t wait. You Have: 8+ years of experience leading enterprise or program‑level quality management and process... ...fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity...Full timeContract workPart timeWork at officeLocal areaRemote work$140k - $175k
...members, leadership, and client stakeholders while supporting or leading practice, solution, and business development initiatives.Job... ...qualitative and quantitative research and detailed assessments of entities, transactions, programs, and proposals to identify...Work at officeFlexible hours$62k - $141k
...implementation, and continuous monitoringExperience supporting Assessment & Authorization (A&A) activities such as evidence collection,... ...Certified Practitioner (SSCP)CertificationNice If You Have:Experience leading RMF efforts across multiple systems, including providing...Full timeContract workPart timeWork at officeLocal areaRemote work$85k - $170k
OverviewWe are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops...$150k - $180k
OverviewAs an Integration Lead, you will work with our growing DevSecOps practice developing APIs and integration capabilities to connect... ..., you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity...$112k - $179k
ResponsibilitiesPeraton is a leading provider of Information Operations (IO) and Irregular Warfare (IW) capabilities to the U.S. government... ...bring a multidisciplinary approach to planning, executing, and assessing strategic communications operations, this program integrates...Contract workShift work$160.96k - $227.36k
...found here.Role Overview:ID.me is seeking a highly experienced SOC Lead to play a pivotal role in our advanced security operations. As... ...and implementing SOC SOPs and contributing to SOC maturity assessments.Ideal Candidate Will Thrive In Our Culture:Exhibits a deep passion...Full timeTemporary workWork at officeRemote workFlexible hours$112k - $179k
Responsibilities Peraton is now Hiring: TASO Team Lead - Federal Strategic Cyber Programs.Location: Arlington, VA. Hybrid schedule... ...domestic and international travel for Cyber Security Assessments (CSA), mission briefings, and consultations, ensuring personnel...Contract workImmediate startShift work$139.5k - $188.7k
...action at scale? AWS is looking for a Scope 3 Inventory Manager Lead to own the end-to-end management of supplier-level greenhouse... ...programs across global supply chains- Familiarity with life cycle assessment (LCA) methodologies and emissions factor databases (e.g., DEFRA...Flexible hours- ...third-party validation. is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the... ...Response Team in response to cybersecurity breaches, focusing on assessing and mitigating the impact of issues and afterwards analyzing root...Full timeContract workLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CMMC Assessment Lead. Be the first to apply!



