CMMC Compliance Consultant

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in San Diego, CA, USA
In-Office or Remote
Senior level
Information Technology
The Role
Lead end-to-end CMMC Level 2 assessments for Defense Industrial Base clients: scope CUI environments, author assessor-ready SSPs/POA&Ms, perform gap assessments using NIST SP 800-171A methodology, manage GRC evidence, advise on remediation roadmaps, present to executives, and mentor junior consultants.
Summary Generated by Built In
Company Description

Agile IT is a Microsoft AOS-G partner and Cyber AB Registered Practitioner Organization (RPO) built for the Defense Industrial Base. As one of six original AOS-G resellers for GCC High and a C3PAO candidate, we help defense contractors meet CMMC compliance and operate securely in Microsoft cloud environments. Our customers build fighter jet components, naval propulsion systems, satellite payloads, and aerospace platforms that support the Department of War. We make sure their Microsoft environments are ready for the job.

We are in a high-growth phase, and we are stacking the team to match. The next chapter is a compliance-oriented MSP, purpose-built for the regulated workloads our customers run. We are hiring the people who will build it.

Job Description

The CMMC Compliance Consultant is the subject matter expert who carries DIB clients through the full CMMC lifecycle. You own engagements end to end, from initial gap assessment through assessor-ready documentation, and you are the technical authority clients lean on when the requirements get hard.

This is practitioner-level work. You scope CUI environments, build the SSPs and POA&Ms an assessor will actually accept, and translate dense regulatory language into guidance a client can act on. You sit in pre-sales calls and executive readouts, you mentor the junior consultants coming up behind you, and you help sharpen the methodology the whole practice runs on. Active CCP and CCA credentials are non-negotiable for this role.

What You'll Own

Assessment and Advisory. Lead and execute CMMC Level 2 gap assessments against all 110 NIST SP 800-171 Rev 2 practices across the 14 control domains. Conduct readiness reviews and deliver findings with prioritized remediation roadmaps.

Assessor-Ready Documentation. Author and maintain SSPs, POA&Ms, policies, procedures, and implementation narratives using the NIST SP 800-171A examine, test, and interview methodology. Build CMMC-scoped network diagrams, data flow diagrams, and CUI boundary documentation.

CUI Environment Scoping. Evaluate client environments scoped to CUI systems, including Microsoft 365 GCC and GCC High, Intune and Microsoft Defender for Endpoint, and specialized platforms such as PreVeil.

Client Engagement. Serve as the primary technical point of contact for assigned DIB accounts across the compliance lifecycle. Facilitate interviews with client staff to validate controls and gather evidence, and present status and executive readouts with clarity.

GRC Platform Integrity. Own data integrity in the GRC platform (e.g., IntelliGRC) for SSP management, POA&M tracking, and evidence management.

Practice Development. Improve internal CMMC methodologies, templates, and tooling. Mentor junior consultants, and track CMMC Program rule changes (32 CFR Part 170, DFARS 252.204-7021) and Cyber AB guidance updates so the practice stays current.

Qualifications

Required

  • Active CMMC Certified Professional (CCP) credential in good standing with the Cyber AB
  • Active CMMC Certified Assessor (CCA) credential in good standing with the Cyber AB
  • Minimum 5 years of progressive IT experience, with at least 2 years focused on cybersecurity
  • Minimum 1 year of direct CMMC, DFARS 252.204-7012/7021, NIST SP 800-171, or other compliance consulting experience
  • Demonstrated expertise scoping CUI environments and applying NIST SP 800-171 Rev 2 across all 14 control families
  • Hands-on experience with Microsoft 365 Commercial, GCC, and/or GCC High environments in a CMMC compliance context
  • Working knowledge of Azure Sentinel, Microsoft Defender for Endpoint (MDE), and Intune within CMMC-scoped environments
  • Strong proficiency writing SSP implementation narratives, NIST 800-171A-aligned assessment procedures, and POA&M documentation
  • Familiarity with FedRAMP Moderate authorization requirements and cloud service provider boundary scoping
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a closely related field

Preferred

  • Experience with PreVeil, Lifeline, or other CUI-designated encrypted collaboration platforms
  • Experience supporting multi-site CMMC Level 2 assessments in manufacturing, defense electronics, or aerospace sectors
  • Prior experience as a C3PAO team member on an assessment
  • Experience with GRC platforms such as IntelliGRC or equivalent

 

Additional Information

Additional Information

  • Department: Compliance
  • Reports to the Lead CMMC Compliance Manager
  • Full-time, fully remote

Agile IT runs on its RISE values: Reliability, Integrity, Stewardship, and Excellence. We hire people who live them.

Skills Required

  • Active CMMC Certified Professional (CCP) credential in good standing with the Cyber AB
  • Active CMMC Certified Assessor (CCA) credential in good standing with the Cyber AB
  • Minimum 5 years of progressive IT experience, with at least 2 years focused on cybersecurity
  • Minimum 1 year of direct CMMC, DFARS 252.204-7012/7021, NIST SP 800-171, or other compliance consulting experience
  • Demonstrated expertise scoping CUI environments and applying NIST SP 800-171 Rev 2 across all 14 control families
  • Hands-on experience with Microsoft 365 Commercial, GCC, and/or GCC High environments in a CMMC compliance context
  • Working knowledge of Azure Sentinel, Microsoft Defender for Endpoint (MDE), and Intune within CMMC-scoped environments
  • Strong proficiency writing SSP implementation narratives, NIST 800-171A-aligned assessment procedures, and POA&M documentation
  • Familiarity with FedRAMP Moderate authorization requirements and cloud service provider boundary scoping
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a closely related field
  • Experience with PreVeil, Lifeline, or other CUI-designated encrypted collaboration platforms
  • Experience supporting multi-site CMMC Level 2 assessments in manufacturing, defense electronics, or aerospace sectors
  • Prior experience as a C3PAO team member on an assessment
  • Experience with GRC platforms such as IntelliGRC or equivalent
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
San Diego, CA
36 Employees
Year Founded: 2006

What We Do

Doing IT right — the first time. We’re defined by the work we do for our customers. It’s why hundreds of companies rely on us for cloud managed IT services. Here’s what a few of our customers have to say. “We’ve had a strong relationship with Agile IT for two years. The team takes their jobs seriously. They’re knowledgeable in many areas and transparent about what falls outside their expertise.” - Harry Tchira, President, Dotchi “Downtime has been incredibly reduced… my costs have decreased, also. It solved a lot of little problems we were having all in one-shot, which was cool.” -- John Merritt, SVP / CIO YMCA of San Diego County “The money we spent on Agile IT’s help is far less than it would have cost us in downtime, or productivity on my part.” -- Chris Burtch, CTO, TrendSource Our goal is simple. Help business tap the full potential of their software and systems. At Agile IT, we’re not only experts in the cloud, we provide services that have a deep impact on your bottom line, including business automation, data, integration and intelligence.

Similar Jobs

Tulip Logo Tulip

Senior Account Executive

Enterprise Web • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
US
310 Employees
100K-150K Annually

Dropbox Logo Dropbox

Account Executive

Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Remote
United States
2500 Employees
147K-198K Annually

Hiya Inc. Logo Hiya Inc.

Marketing Manager

Artificial Intelligence • Cloud • Mobile • Security • Software
Remote or Hybrid
United States
145 Employees
96K-139K Annually

Riot Platforms, Inc. Logo Riot Platforms, Inc.

Thermal & Cooling Liquid Engineer (SME)

Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Remote
United States
800 Employees

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account