Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

CMMC Assessment Lead

Paragone Solutions Inc

About SecureITSM
SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.

We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities.

Location and Travel: This is a remote position with occasional travel required to support customer assessments.

Position Summary
The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership.

This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible.

Key Responsibilities
Plan and Coordinate Assessments (Primary)
  • Maintain the master CMMC customer assessment schedule
  • Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams
  • Conduct readiness reviews and pre-assessment planning meetings
  • Track customer assessment milestones, dependencies, and remediation activities
  • Manage customer communications related to assessment preparation and scheduling
  • Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
  • Monitor assessment status and provide executive-level reporting on customer readiness
  • Assist customers in understanding assessment scope, boundary definitions, and enclave considerations
Prepare Assessment Packages (Primary)
  • Update implementation statements as needed
  • Gather and organize evidentiary artifacts
  • Coordinate customer evidence collection activities
  • Review SSPs, policies, procedures, and supporting documentation for assessment readiness
  • Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
  • Prepare assessor-ready evidence packages and artifact repositories
  • Conduct internal quality assurance reviews of documentation and evidence
  • Identify documentation gaps and coordinate remediation activities
  • Support development and maintenance of Plans of Action & Milestones (POA&Ms)
  • Ensure documentation aligns with evolving CMMC and NIST guidance
Support Customer Assessments (Primary)
  • Attend and actively support customer assessments
  • Actively defend implementations and evidence presented to assessors
  • Coordinate assessment interviews and technical demonstrations
  • Support mock assessments and readiness exercises for customers
  • Assist customers in responding to assessor requests and follow-up questions
  • Document assessment observations, findings, and remediation actions
  • Coordinate post-assessment remediation activities and evidence resubmissions when required
  • Serve as a trusted advisor throughout the certification lifecycle
Maintain SecureITSM's Authorization and Compliance (Secondary)
  • Conduct SecureITSM's annual self-assessment activities
  • Maintain internal compliance documentation and evidentiary artifacts
  • Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
  • Assist with internal policy and procedure updates
  • Support ongoing continuous monitoring and compliance validation activities
  • Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
Implementation Statement Management (Secondary)
  • Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance
  • Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)
  • Standardize implementation language and evidence expectations across customer environments
  • Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices
  • Validate implementation statements for technical accuracy, completeness, and assessor defensibility
  • Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library
Maintain and Improve Standard Operating Procedures (Secondary)
  • Develop and maintain assessment preparation Standard Operating Procedures (SOPs)
  • Continuously improve evidence collection and assessment support workflows
  • Create standardized templates, checklists, and assessment playbooks
  • Document lessons learned and incorporate process improvements
  • Maintain internal knowledge base articles and operational documentation
  • Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes
Required Qualifications
  • U.S. Citizenship required
  • Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies
  • 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171
  • Experience supporting compliance assessments, audits, or certification activities
  • Strong understanding of CMMC assessment methodology and evidence requirements
  • Excellent technical writing and communication skills
  • Strong project management and organizational abilities
  • Exceptional attention to detail
  • Ability to manage multiple customer engagements simultaneously
  • Experience working directly with external assessors, auditors, or regulatory bodies
  • Familiarity with secure project management and compliance collaboration platforms
Preferred Qualifications
  • PMP certification preferred
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred
  • CISSP, CISM, or equivalent cybersecurity certification preferred
  • Experience supporting DoD contractors or working within the Defense Industrial Base (DIB)
  • Familiarity with FedRAMP and DFARS View phone number on click.appcast.io
  • Experience with SIEM, vulnerability management, and endpoint protection technologies
Key Attributes
  • Strong leadership and customer engagement skills
  • Ability to remain composed and professional during high-pressure assessment activities
  • Analytical thinker with strong problem-solving capabilities
  • Self-motivated with ability to work independently
  • Collaborative team player with strong interpersonal skills
  • High level of integrity and professionalism
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law.

#ZR
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the CMMC Assessment Lead in United States vacancy
  •  ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting...  ...compliance platform designed to streamline assessment preparation, evidence management, and...  ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination... 
    Suggested
    For contractors
    Remote work

    Paragone Solutions, Inc.

    McLean, VA
    20 days ago
  • A trusted cybersecurity firm in Maryland is seeking a Certified CMMC Assessor to support client assessments for the Cybersecurity Maturity Model Certification (CMMC). This role requires strong attention to detail and experience with federal cybersecurity frameworks. The... 
    Suggested

    MNS Group

    Annapolis, MD
    3 days ago
  • DigiFlight, Inc. is seeking a Certified CMMC Assessor to lead CMMC assessments and provide advisory engagements. The role requires 7-10 years of experience in cybersecurity and IT audits, along with 3-5 years in a leadership position. Responsibilities include advising... 
    Suggested

    DigiFlight, Inc.

    Columbia, MD
    2 days ago
  • Paragone Solutions, Inc is seeking a CMMC Assessment Lead to oversee planning and support of customer assessments for compliance. This role requires strong cybersecurity expertise and project management skills, focusing on NIST standards. The position is primarily remote... 
    Suggested
    Remote job

    Paragone Solutions, Inc

    Mc Lean, VA
    1 day ago
  • Digiflight is seeking a Certified CMMC Assessor to lead formal assessments and support readiness reviews in Columbia, Maryland. The role requires 7-10 years of experience in cybersecurity, IT audits, and compliance programs, along with strong judgment and decision-making... 
    Suggested

    Digiflight

    Columbia, MD
    2 days ago
  •  ...Compliance Officer (ISSO) to oversee compliance programs aligned with CMMC Level 2, NIST SP 800‑171, and more. This remote position...  ...compliance. The candidate will manage the System Security Plan and assess compliance controls while ensuring documentation is audit-ready.... 
    Remote work

    Lynk Inc

    New York, NY
    3 days ago
  •  ...A cybersecurity organization is seeking a Lead Certified CMMC Assessor to guide assessment teams and government contractors in compliance and cybersecurity practices. The role requires over 10 years of experience in the federal contracting space, knowledge of NIST standards... 
    For contractors

    MNS Group

    New York, NY
    3 days ago
  • $105k - $165k

     ...office In support of our growing Risk Advisory practice, we are seeking an experienced Lead CMMC Certified Assessor (LCCA) to play a key role in expanding our CMMC assessment capabilities. This opportunity is best suited for someone with deep IT audit expertise and... 
    Work at office
    Local area
    Remote work
    Visa sponsorship

    Eide Bailly

    United States
    4 days ago
  •  ...for gathering qualified candidates for a position relating to Lead CMMC Certified Assessor to support our clients in multiple...  ...is responsible for the performance of cybersecurity framework assessments to determine compliance with Government-mandated cybersecurity... 
    Full time
    Temporary work
    Remote work
    Monday to Friday

    Boston Government Services

    Oak Ridge, TN
    4 days ago
  • $130k - $170k

     ...including Khosla Ventures and Footwork VC. As the FedRAMP & CMMC Compliance Lead, you will own our compliance function end-to-end and build...  ...start-up. Experience defining CUI boundaries and scoping assessment environments. Experience writing or substantially contributing... 
    For contractors
    Work at office

    WindBorne Systems

    Palo Alto, CA
    4 days ago
  • A cybersecurity services provider in San Antonio is seeking a CMMC Registered Practitioner to guide clients in achieving CMMC Level 2 certification. The role involves conducting gap assessments, supporting documentation development, and advising on compliance strategies... 

    Jbwfederal

    San Antonio, TX
    4 days ago
  • Nettitude Group is seeking a detail-oriented Certified CMMC Assessor (CCA) to support our cybersecurity consulting efforts. This role involves conducting compliance assessments and providing expert advisory services to clients in ensuring adherence to cybersecurity standards... 
    Remote job

    Nettitude Group

    Houston, TX
    1 day ago
  • A leading Managed IT and Cybersecurity Compliance provider is seeking a Certified CMMC Professional (CCP) to support clients through the CMMC 2.0 lifecycle from gap assessment to readiness. The role is client-facing and delivery-focused, requiring technical expertise to... 
    Flexible hours

    Isccorp Us

    Falls Church, VA
    21 hours ago
  • $105.79k - $141.05k

     ...future of AI‑ready connectivity, join us today. The Role The CMMC Compliance Analyst must have advanced practical experience in managing...  ...procedures, and technical artifacts Perform periodic control assessments, validation, and remediation tracking Support POA&M management... 
    Remote job
    Temporary work
    For contractors

    Lumen

    Phoenix, AZ
    3 days ago
  •  ...The Bronx District Attorney is seeking an experienced Administrative Supervisor for the Early Case Assessment Bureau (ECAB) to lead professional staff. This role requires overseeing staffing, evaluating performance, and ensuring compliance with District Attorney’s policies... 
    Full time
    Work experience placement
    Work at office

    Bronx District Attorney

    New York, NY
    3 days ago
  •  ...Financial Crimes Risk Assessment Manager Responsibilities include but are not limited to: Oversee the Financial Crimes risk assessment...  ...and effectively drive AML program design and strategy. Lead the identification, sourcing, and strategic use of critical... 

    Valley National Bancorp

    Morristown, NJ
    21 hours ago
  •  ...Clinical Lead Schedule: 7pm- 7:30am (average 24 hours per week) At Children's, the region's only full-service pediatric healthcare...  ...and education to children and families and conducts clinical assessments when needed. Diagnose and treat patients independently.... 
    Part time
    Shift work
    Night shift

    Children’s Nebraska

    Omaha, NE
    1 day ago
  •  ...Koitecc Solutions in Jersey City is looking for a PCI Specialist to oversee compliance assessments and protect sensitive cardholder data. The ideal candidate will lead PCI assessment processes, ensuring adherence to regulations while developing relationships across the... 

    Koitecc Solutions

    Jersey City, NJ
    1 day ago
  •  ...Koniag IT Systems, LLC, a Koniag Government Services company , is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other... 
    Local area
    Flexible hours

    Koniag Government Services

    Oklahoma City, OK
    3 days ago
  • $170k - $210k

     ...X Energy LLC is seeking a Manager for Probabilistic Risk Assessment in Rockville, MD. This role involves leading safety analysis and risk assessment for advanced nuclear projects, as well as managing and developing engineering teams. The ideal candidate will have a Bachelor... 

    X Energy, LLC

    Rockville, MD
    1 day ago
  •  ...A leading Cyber Risk and Compliance firm in the United States is seeking an experienced Services Leader to manage its CMMC Compliance practice. This role involves leading compliance advisory and C3PAO services, ensuring client delivery excellence, and mentoring team members... 
    Remote work

    Ascera

    New York, NY
    3 days ago
  • $70k - $80k

     ...Pearson is seeking an Advanced Specialist in Partnership Management to oversee large-scale assessment programs. This remote position involves managing assessment activities, developing client relationships, and ensuring project deliverables are met. Ideal candidates will... 
    Remote work

    Pearson

    Hadley, MA
    2 days ago
  •  ...Urrly is seeking a Cybersecurity Compliance Consultant for a fully remote role. The consultant will lead CMMC policy development, manage multiple clients, and ensure audit readiness. The position requires 3-5 years of experience in cybersecurity GRC, strong NIST 800-17... 
    For contractors
    Remote work

    Urrly

    New York, NY
    3 days ago
  •  ...experienced IT & Compliance Manager to oversee daily IT operations, cybersecurity, and regulatory compliance. This role will lead the organization through CMMC Level 2 certification and manage relationships with external service providers. Ideal candidates should possess a... 

    LINK

    New York, NY
    3 days ago
  •  ...Position: Cybersecurity Assessments Lead Clearance: Top Secret, SCI eligible Job Location: Fort Meade, MD Client: DISA Project Job description Determines enterprise IA and security standards. Develops and implements IA/security... 
    Work at office

    CompQsoft

    Maryland
    1 day ago
  •  ...Description Tharros is seeking a Cybersecurity Assessment Lead for an upcoming program supporting a US Navy customer located at NAS Oceana. The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk... 

    ANALYGENCE Inc

    Virginia Beach, VA
    2 days ago
  •  ...Joint Staff directorates, Senior Executive Service leaders, and operational analysts. • This role directs enterprise vulnerability assessment operations using the Assured Compliance Assessment Solution (ACAS), Tenable Security Center, and Nessus scanning infrastructure... 
    Contract work

    ECS Limited

    Falls Church, VA
    21 hours ago
  • $130k - $160k

     ...The Vulnerability Assessment Team Lead manages enterprise vulnerability identification and remediation efforts to reduce risk across CBP systems. If you enjoy finding weaknesses before adversaries do, this role puts you in a position of real influence. As the Vulnerability... 

    UltraViolet Cyber

    Ashburn, VA
    2 days ago
  •  ...Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection... 
    Temporary work

    Gritter Francona

    Ashburn, VA
    3 days ago
  •  ...Lead- Assessment (MCAS) (CHS) (Internal Only) (SY26-27) Reports to: Building Principal Qualifications: The ideal candidate will be an experienced and licensed teacher with strong logistical and organizational skills. Lead Responsibilities: Seeking an educator... 

    Chelsea Public Schools

    Chelsea, MA
    16 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to CMMC Assessment Lead. Be the first to apply!