CMMC / NIST Consultant / Analyst
Hotman Group LLC
About the Role
Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements. We are looking for a mid-level CMMC and NIST practitioner who can step into active client delivery work, produce strong documentation, and help move projects forward without a lot of hand-holding.
This is a contract role that may be structured as part-time or full-time based on project needs and candidate availability.
What You Will Do
As a CMMC / NIST Consultant Analyst at Hotman Group you will contribute directly to active client engagements involving federal compliance frameworks. You will:
What You Bring
Active certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one.
This role requires direct accountability for work product and outcomes. If your CMMC or NIST experience has been primarily observational or in a support capacity without ownership of documentation or deliverables, this role will be a significant adjustment.
Requirements
Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on active client engagements. If you are confident in your CMMC and NIST expertise, this is your opportunity to show it.
Why Hotman Group
At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.
You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.
The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.
If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard - this is the place.
No phone calls or emails please.
Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements. We are looking for a mid-level CMMC and NIST practitioner who can step into active client delivery work, produce strong documentation, and help move projects forward without a lot of hand-holding.
This is a contract role that may be structured as part-time or full-time based on project needs and candidate availability.
What You Will Do
As a CMMC / NIST Consultant Analyst at Hotman Group you will contribute directly to active client engagements involving federal compliance frameworks. You will:
- Support client engagements related to CMMC readiness, implementation, and documentation
- Develop, update, and maintain System Security Plans
- Assist with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and related deliverables
- Gather, organize, and review evidence supporting control implementation
- Support CUI scoping discussions, boundary definition, and enclave design
- Draft and refine control narratives, policies, procedures, and related compliance documentation
- Identify gaps and support development of POA&Ms and remediation tracking
- Work directly with client stakeholders to collect information, validate details, and keep deliverables moving
- Contribute to readiness efforts tied to assessments, documentation, and ongoing compliance activities
- Participate in peer review of deliverables before they go to clients - your work will be reviewed and you will review others
What You Bring
- 3 to 5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work
- Hands-on experience with CMMC-related work -- this is required, not a nice to have
- Direct experience developing or contributing to System Security Plans, evidence collection, remediation documentation, and compliance policies -- also required
- Familiarity with NIST SP 800-171, NIST SP 800-53, and FedRAMP
- Strong writing and documentation skills -- your deliverables are clear, accurate, and do not require heavy editing before they go to a client
- The ability to work directly with client stakeholders, gather information, manage follow-through, and keep work moving
- Strong organization and professionalism in a client-facing environment
- Comfort stepping into projects that are already in motion and contributing independently with minimal ramp-up time
- A default toward communication - you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client
Active certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one.
This role requires direct accountability for work product and outcomes. If your CMMC or NIST experience has been primarily observational or in a support capacity without ownership of documentation or deliverables, this role will be a significant adjustment.
Requirements
- Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future
- Able to pass a background check
- Reliable high-speed internet and a secure, private remote workspace
Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on active client engagements. If you are confident in your CMMC and NIST expertise, this is your opportunity to show it.
Why Hotman Group
At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.
You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.
The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.
If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard - this is the place.
No phone calls or emails please.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the CMMC / NIST Consultant / Analyst in United States vacancy
- ...Hotman Group is seeking a CMMC / NIST Consultant / Analyst to support client projects involving CMMC, SSP development, NIST SP 800-171, NIST SP 800-53, FedRAMP, evidence collection, control documentation, and remediation tracking. This is a contract role that may be structured...SuggestedFull timeContract workPart timeRemote work
$100k - $125k
...Urrly is seeking a Cybersecurity Compliance Consultant to work 100% remote and help DoD contractors pass CMMC audits. Responsibilities include leading CMMC policy... ...experience in cybersecurity GRC, a deep understanding of NIST 800-171 and CMMC, and hold a Security+...SuggestedFor contractorsRemote work- ...is hiring a Governance, Risk and Compliance Analyst in Boston. This hybrid role involves supporting compliance initiatives and NIST frameworks in government and higher education... ...2-4 years of experience, and proficiency in CMMC. Responsibilities include conducting risk...Suggested
- A leading consulting firm in Wakefield is looking for an experienced Information Security Analyst. You will lead the design, implementation, and management of the information... ...program, ensuring compliance with NIST, CMMC, and SOC-2 frameworks. The successful candidate...Suggested
$70k - $95k
...CMMC , CCP Consultant Nashville, TN Description Description ABOUT US Redspin, a division of Clearwater, is a leading... ...is required. In-depth knowledge of the CMMC framework, NIST SP 800-171, and DFARS 252.204-7012 regulations....SuggestedContract workFor contractorsFor subcontractorRemote workFlexible hours- ...A company is looking for a Senior CMMC Consultant, Public Sector Advisory. Key Responsibilities Lead IT system security consultation in accordance... ..., including CMMC and related frameworks Strong knowledge of NIST Special Publications 800-171, 800-30, 800-37, and 800-53...Work experience placementRemote work
- ...Description Vistrada is seeking a highly motivated and experienced CMMC Consultant to join our growing security team and work with our clients.... ...Certified Professional Extensive knowledge of CMMC practices, NIST 800-171, and related frameworks (e.g., ISO 27001). At least 3-...
$125k - $160k
...At Atlantic Digital, we are a high-impact consulting partner dedicated to building secure, modern, and compliant IT environments for... ...clients through Azure Government, Microsoft 365 GCC High, CMMC Level 2, NIST SP 800-171, and other mission-critical frameworks. Drive...For contractorsLocal areaRemote work$115k - $140k
...Maestro Search is seeking a CMMC Advisory Consultant to support clients in preparing for C3PAO audits. This fully remote role requires over 5 years... ..., along with significant knowledge of CMMC, DFARS, and NIST frameworks. You'll deliver CMMC gap assessments, collaborate...Remote work- ...customers’ business. About the Role As a GRC Consultant at Network Coverage, you will be part of... ..., under the guidance of the Director of CMMC Compliance and Chief Advisory Officer.... ...Familiarity with regulatory frameworks such as NIST/CMMC, ISO 27001, HIPAA/Hitech, GDPR are a...Work at officeRemote workOverseasFlexible hoursShift work
$86k - $148k
...just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all... ...Summary The Senior Consultant leads CMMC advisory consulting engagements, documentation... ...environments in accordance with CMMC, NIST SP 800-171, NIST SP 800-53, 800- 37, DFARS...Work experience placementWork at officeFlexible hours- ...Description Ariento is seeking a Senior Consultant to join our Advisory and Consulting Team... ...Cybersecurity Maturity Model Certification (CMMC) Subject Matter Expert (SME). This role... ...compliance with CMMC, DFARS 252.204-7012, NIST SP 00-171, and FedRAMP Conduct...
- ...Job Summary The Business Systems Analyst - CMMC is responsible for defining system scope... ...certification efforts, or implementing NIST SP 800171 controls in an enterprise environment... ...customer service team for our Consultants that can address questions around benefits...Contract workWork experience placement
$115k - $145k
...seeking a hands‑on technical leader for CMMC Business Analyst to maintain and continuously improve... ...Responsibilities Risk Assessment - mapping CMMC and NIST 800‑171 controls to application... .... Previous C3PAO, assessment, or consultancy experience. CISSP (Certified...For contractors- ...Job Title: Business Continuity & Dependency Risk Consultant Duration: 6 months Location: New York, NY 10010, USA Work Schedule:... ...~ Knowledge of resilience frameworks and standards (ISO 22301, NIST, FFIEC, DORA, or similar). ~ Ability to integrate quickly into...Full time
$125k
The University of Texas at Austin is seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance for its Controlled Research Program. The role involves maintaining security programs, conducting assessments, and collaborating with IT and research stakeholders...Remote job$75k - $95k
...Entry-Level Consultant/Analyst 1 We are seeking an entry-level Consultant/Analyst 1 to support the United States Coast Guard (USCG) Office of Intelligence, Surveillance, and Reconnaissance (ISR) Systems and Technology. This role involves assisting in the analysis of...Work at office- ...Consultant - Analyst Basic Function/Purpose: Under general direction, performs a wide variety of complex, difficult, and specialized advanced level professional financial, accounting, analytical, and administrative duties in support of the Grid Modernization Engineering...Contract workWork at officeLocal area
- ...Senior Consultant - Epic Him Analyst Make a difference. Be happy. Grow your career. A Nordic consultant is more than just an Epic expert. Our analysts take ownership for their work and the greater success of the organization. We're also looking for someone who listens...Work experience placementWork at officeLocal areaRemote workNight shiftWeekday work
$95k - $120k
...Consultant / Analyst 3 We are seeking a skilled Consultant / Analyst 3 to support the United States Coast Guard (USCG) Office of Intelligence, Surveillance, and Reconnaissance (ISR) Systems and Technology. This role involves analyzing complex technical and business...For contractorsWork at officeFlexible hours- ...Make a difference. Be happy. Grow your career. THE ROLE The Senior MEDITECH Consultant provides consulting services to clients on MEDITECH-related projects, clinically based as a subject matter expert, to deliver solutions to achieve defined benefits. The Senior MEDITECH...Local area
- ...EDI Analyst / Integration Consultant Position: EDI Analyst / Integration Consultant Locations: 100% Remote Position Type: Long-Term Contract with Right to Hire Perm down the road NetSuite experience is mandatory. EDI experience must have or be willing to learn...Long term contractPermanent employmentRemote work
$48k - $89.5k
...plan sponsors and participants (clients) through advising and consulting, in support of business unit sales goals. Works effectively with... ...to a full-time schedule. The national salary range for Sr Analyst, Regional Internal : $48,000.00-$89,500.00 The expected...Full timeTemporary workPart timeCasual workWork at officeRemote work- ...A company is looking for an HRIS Analyst Consultant. Key Responsibilities Refine and execute weekly audits of data fields within the ADP system to ensure data accuracy and integrity Communicate data audit findings to the HR team and recommend process improvements to...Remote work
$85k - $110k
...Junior Consultant/Analyst We are seeking a motivated and detail-oriented Junior Consultant/Analyst to support the United States Coast Guard (USCG) Office of Intelligence, Surveillance, and Reconnaissance (ISR) Systems and Technology. This entry-level role involves...Work at office- ...Informatica Analyst Consultant SonSoft Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. SonSoft Inc is growing at a steady pace specializing in the fields of Software Development, Software Consultancy, and Information Technology...Permanent employmentFull timeH1b
- ...Technology Analyst If you're passionate about being part of a dynamic organization that enables a Fortune 100 company with nearly... ...who are passionate about delivering extraordinary care. The Consultant, Technology Analyst supports both Run (incident management,...Work experience placementWork at officeFlexible hours
$85k - $110k
...Daymark Energy Advisors is a successful, growing consultancy. We are looking for a Senior Analyst or a Consultant to join our team. This role has the opportunity to engage in projects across our six practice areas, with emphasis on our rates and pricing practice. Candidates...Work at officeRemote workFlexible hours$90k
...Join to apply for the Senior Consultant - MyChart Analyst - Remote role at Nordic Global Join to apply for the Senior Consultant - MyChart Analyst - Remote role at Nordic Global Make a difference. Be happy. Grow your career. Job Description Summary A Nordic consultant...Full timeContract workLocal areaRemote work- ...About Us Niti Global Consulting Pvt. Ltd. is a pragmatic consulting firm bridging the gap between strategic policy insights and commercial decision-making. We provide high-stakes Risk Intelligence and data-driven Market Strategy to help global clients navigate...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CMMC / NIST Consultant / Analyst. Be the first to apply!
Related searches
- sailpoint consultant United States
- lead analytics consultant United States
- iam consultant United States
- sox consultant United States
- consultant part time United States
- lean consultant United States
- power bi consultant United States
- therapy consultant United States
- loss control consultant United States
- ocm consultant United States


