Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

CMMC / NIST Consultant / Analyst

Hotman Group LLC

About the Role


Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements. We are looking for a mid-level CMMC and NIST practitioner who can step into active client delivery work, produce strong documentation, and help move projects forward without a lot of hand-holding.


This is a contract role that may be structured as part-time or full-time based on project needs and candidate availability.


What You Will Do


As a CMMC / NIST Consultant Analyst at Hotman Group you will contribute directly to active client engagements involving federal compliance frameworks. You will:

  • Support client engagements related to CMMC readiness, implementation, and documentation
  • Develop, update, and maintain System Security Plans
  • Assist with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and related deliverables
  • Gather, organize, and review evidence supporting control implementation
  • Support CUI scoping discussions, boundary definition, and enclave design
  • Draft and refine control narratives, policies, procedures, and related compliance documentation
  • Identify gaps and support development of POA&Ms and remediation tracking
  • Work directly with client stakeholders to collect information, validate details, and keep deliverables moving
  • Contribute to readiness efforts tied to assessments, documentation, and ongoing compliance activities
  • Participate in peer review of deliverables before they go to clients - your work will be reviewed and you will review others
This is hands-on delivery work in a remote consulting environment. You will be expected to step into active projects and contribute from day one.


What You Bring
  • 3 to 5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work
  • Hands-on experience with CMMC-related work -- this is required, not a nice to have
  • Direct experience developing or contributing to System Security Plans, evidence collection, remediation documentation, and compliance policies -- also required
  • Familiarity with NIST SP 800-171, NIST SP 800-53, and FedRAMP
  • Strong writing and documentation skills -- your deliverables are clear, accurate, and do not require heavy editing before they go to a client
  • The ability to work directly with client stakeholders, gather information, manage follow-through, and keep work moving
  • Strong organization and professionalism in a client-facing environment
  • Comfort stepping into projects that are already in motion and contributing independently with minimal ramp-up time
  • A default toward communication - you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client
Experience supporting CMMC Level 2 efforts, CUI scoping, enclaves, or boundary discussions is a strong plus. Familiarity with POA&Ms, assessment readiness, and control crosswalks is also valued.


Active certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one.


This role requires direct accountability for work product and outcomes. If your CMMC or NIST experience has been primarily observational or in a support capacity without ownership of documentation or deliverables, this role will be a significant adjustment.


Requirements
  • Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future
  • Able to pass a background check
  • Reliable high-speed internet and a secure, private remote workspace

Our Hiring Process


Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on active client engagements. If you are confident in your CMMC and NIST expertise, this is your opportunity to show it.


Why Hotman Group


At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.


You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.


The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.


If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard - this is the place.


No phone calls or emails please.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the CMMC / NIST Consultant / Analyst in United States vacancy
  •  ...Hotman Group is seeking a CMMC / NIST Consultant / Analyst to support client projects involving CMMC, SSP development, NIST SP 800-171, NIST SP 800-53, FedRAMP, evidence collection, control documentation, and remediation tracking. This is a contract role that may be structured... 
    Suggested
    Full time
    Contract work
    Part time
    Remote work

    Hotman Group

    Fort Worth, TX
    3 days ago
  • $100k - $125k

     ...Urrly is seeking a Cybersecurity Compliance Consultant to work 100% remote and help DoD contractors pass CMMC audits. Responsibilities include leading CMMC policy...  ...experience in cybersecurity GRC, a deep understanding of NIST 800-171 and CMMC, and hold a Security+... 
    Suggested
    For contractors
    Remote work

    Urrly

    Reston, VA
    1 day ago
  •  ...is hiring a Governance, Risk and Compliance Analyst in Boston. This hybrid role involves supporting compliance initiatives and NIST frameworks in government and higher education...  ...2-4 years of experience, and proficiency in CMMC. Responsibilities include conducting risk... 
    Suggested

    Northeastern University

    Boston, MA
    4 days ago
  • A leading consulting firm in Wakefield is looking for an experienced Information Security Analyst. You will lead the design, implementation, and management of the information...  ...program, ensuring compliance with NIST, CMMC, and SOC-2 frameworks. The successful candidate... 
    Suggested

    GEI Consultants

    Wakefield, MA
    14 hours ago
  • $70k - $95k

     ...CMMC , CCP Consultant Nashville, TN Description Description ABOUT US Redspin, a division of Clearwater, is a leading...  ...is required. In-depth knowledge of the CMMC framework, NIST SP 800-171, and DFARS 252.204-7012 regulations.... 
    Suggested
    Contract work
    For contractors
    For subcontractor
    Remote work
    Flexible hours

    Redspin

    United States
    5 days ago
  •  ...A company is looking for a Senior CMMC Consultant, Public Sector Advisory. Key Responsibilities Lead IT system security consultation in accordance...  ..., including CMMC and related frameworks Strong knowledge of NIST Special Publications 800-171, 800-30, 800-37, and 800-53... 
    Work experience placement
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...Description Vistrada is seeking a highly motivated and experienced CMMC Consultant to join our growing security team and work with our clients....  ...Certified Professional Extensive knowledge of CMMC practices, NIST 800-171, and related frameworks (e.g., ISO 27001). At least 3-... 

    VISTRADA

    New York, NY
    1 day ago
  • $125k - $160k

     ...At Atlantic Digital, we are a high-impact consulting partner dedicated to building secure, modern, and compliant IT environments for...  ...clients through Azure Government, Microsoft 365 GCC High, CMMC Level 2, NIST SP 800-171, and other mission-critical frameworks. Drive... 
    For contractors
    Local area
    Remote work

    Atlantic Digital

    Tampa, FL
    3 days ago
  • $115k - $140k

     ...Maestro Search is seeking a CMMC Advisory Consultant to support clients in preparing for C3PAO audits. This fully remote role requires over 5 years...  ..., along with significant knowledge of CMMC, DFARS, and NIST frameworks. You'll deliver CMMC gap assessments, collaborate... 
    Remote work

    Maestro Search

    New York, NY
    1 day ago
  •  ...customers’ business. About the Role As a GRC Consultant at Network Coverage, you will be part of...  ..., under the guidance of the Director of CMMC Compliance and Chief Advisory Officer....  ...Familiarity with regulatory frameworks such as NIST/CMMC, ISO 27001, HIPAA/Hitech, GDPR are a... 
    Work at office
    Remote work
    Overseas
    Flexible hours
    Shift work

    NetCov

    New York, NY
    6 days ago
  • $86k - $148k

     ...just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all...  ...Summary The Senior Consultant leads CMMC advisory consulting engagements, documentation...  ...environments in accordance with CMMC, NIST SP 800-171, NIST SP 800-53, 800- 37, DFARS... 
    Work experience placement
    Work at office
    Flexible hours

    Medium

    Chicago, IL
    2 days ago
  •  ...Description Ariento is seeking a Senior Consultant to join our Advisory and Consulting Team...  ...Cybersecurity Maturity Model Certification (CMMC) Subject Matter Expert (SME). This role...  ...compliance with CMMC, DFARS 252.204-7012, NIST SP 00-171, and FedRAMP Conduct... 

    Ariento Inc

    Franklin, TN
    17 days ago
  •  ...Job Summary The Business Systems Analyst - CMMC is responsible for defining system scope...  ...certification efforts, or implementing NIST SP 800171 controls in an enterprise environment...  ...customer service team for our Consultants that can address questions around benefits... 
    Contract work
    Work experience placement

    Apex Systems

    Saint Louis, MO
    2 days ago
  • $115k - $145k

     ...seeking a hands‑on technical leader for CMMC Business Analyst to maintain and continuously improve...  ...Responsibilities Risk Assessment - mapping CMMC and NIST 800‑171 controls to application...  .... Previous C3PAO, assessment, or consultancy experience. CISSP (Certified... 
    For contractors

    Zone 5 Technologies

    California, MO
    14 hours ago
  •  ...Job Title: Business Continuity & Dependency Risk Consultant Duration: 6 months Location: New York, NY 10010, USA Work Schedule:...  ...~ Knowledge of resilience frameworks and standards (ISO 22301, NIST, FFIEC, DORA, or similar). ~ Ability to integrate quickly into... 
    Full time

    Spectraforce Technologies

    Holtsville, NY
    9 days ago
  • $125k

    The University of Texas at Austin is seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance for its Controlled Research Program. The role involves maintaining security programs, conducting assessments, and collaborating with IT and research stakeholders... 
    Remote job

    University of Texas

    Austin, TX
    3 days ago
  • $75k - $95k

     ...Entry-Level Consultant/Analyst 1 We are seeking an entry-level Consultant/Analyst 1 to support the United States Coast Guard (USCG) Office of Intelligence, Surveillance, and Reconnaissance (ISR) Systems and Technology. This role involves assisting in the analysis of... 
    Work at office

    C.P. MARINE, INC.

    Washington DC
    4 days ago
  •  ...Consultant - Analyst Basic Function/Purpose: Under general direction, performs a wide variety of complex, difficult, and specialized advanced level professional financial, accounting, analytical, and administrative duties in support of the Grid Modernization Engineering... 
    Contract work
    Work at office
    Local area

    EnerNex

    Knoxville, TN
    7 days ago
  •  ...Senior Consultant - Epic Him Analyst Make a difference. Be happy. Grow your career. A Nordic consultant is more than just an Epic expert. Our analysts take ownership for their work and the greater success of the organization. We're also looking for someone who listens... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Night shift
    Weekday work

    Nordic

    United States
    2 days ago
  • $95k - $120k

     ...Consultant / Analyst 3 We are seeking a skilled Consultant / Analyst 3 to support the United States Coast Guard (USCG) Office of Intelligence, Surveillance, and Reconnaissance (ISR) Systems and Technology. This role involves analyzing complex technical and business... 
    For contractors
    Work at office
    Flexible hours

    C.P. MARINE, INC.

    Washington DC
    4 days ago
  •  ...Make a difference. Be happy. Grow your career. THE ROLE The Senior MEDITECH Consultant provides consulting services to clients on MEDITECH-related projects, clinically based as a subject matter expert, to deliver solutions to achieve defined benefits. The Senior MEDITECH... 
    Local area

    HealthTech

    New York, NY
    4 days ago
  •  ...EDI Analyst / Integration Consultant Position: EDI Analyst / Integration Consultant Locations: 100% Remote Position Type: Long-Term Contract with Right to Hire Perm down the road NetSuite experience is mandatory. EDI experience must have or be willing to learn... 
    Long term contract
    Permanent employment
    Remote work

    RIT Solutions

    United States
    5 days ago
  • $48k - $89.5k

     ...plan sponsors and participants (clients) through advising and consulting, in support of business unit sales goals. Works effectively with...  ...to a full-time schedule. The national salary range for Sr Analyst, Regional Internal : $48,000.00-$89,500.00 The expected... 
    Full time
    Temporary work
    Part time
    Casual work
    Work at office
    Remote work

    Nationwide

    United States
    1 day ago
  •  ...A company is looking for an HRIS Analyst Consultant. Key Responsibilities Refine and execute weekly audits of data fields within the ADP system to ensure data accuracy and integrity Communicate data audit findings to the HR team and recommend process improvements to... 
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  • $85k - $110k

     ...Junior Consultant/Analyst We are seeking a motivated and detail-oriented Junior Consultant/Analyst to support the United States Coast Guard (USCG) Office of Intelligence, Surveillance, and Reconnaissance (ISR) Systems and Technology. This entry-level role involves... 
    Work at office

    C.P. MARINE, INC.

    Washington DC
    5 days ago
  •  ...Informatica Analyst Consultant SonSoft Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. SonSoft Inc is growing at a steady pace specializing in the fields of Software Development, Software Consultancy, and Information Technology... 
    Permanent employment
    Full time
    H1b

    SonSoft

    Austin, TX
    5 days ago
  •  ...Technology Analyst If you're passionate about being part of a dynamic organization that enables a Fortune 100 company with nearly...  ...who are passionate about delivering extraordinary care. The Consultant, Technology Analyst supports both Run (incident management,... 
    Work experience placement
    Work at office
    Flexible hours

    Nationwide

    Des Moines, IA
    4 days ago
  • $85k - $110k

     ...Daymark Energy Advisors is a successful, growing consultancy. We are looking for a Senior Analyst or a Consultant to join our team. This role has the opportunity to engage in projects across our six practice areas, with emphasis on our rates and pricing practice. Candidates... 
    Work at office
    Remote work
    Flexible hours

    Xodus Group

    Worcester, MA
    4 days ago
  • $90k

     ...Join to apply for the Senior Consultant - MyChart Analyst - Remote role at Nordic Global Join to apply for the Senior Consultant - MyChart Analyst - Remote role at Nordic Global Make a difference. Be happy. Grow your career. Job Description Summary A Nordic consultant... 
    Full time
    Contract work
    Local area
    Remote work

    Nordic Global

    New York, NY
    1 day ago
  •  ...About Us Niti Global Consulting Pvt. Ltd. is a pragmatic consulting firm bridging the gap between strategic policy insights and commercial decision-making. We provide high-stakes Risk Intelligence and data-driven Market Strategy to help global clients navigate... 
    Remote work

    Niti Global Consulting Pvt. Ltd.

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to CMMC / NIST Consultant / Analyst. Be the first to apply!