CMMC / NIST Consultant / Analyst

Reposted 3 Days Ago
Fort Worth, TX, USA
In-Office
Mid level
Information Technology • Consulting • Cybersecurity
The Role
The role involves providing consulting for CMMC and NIST compliance, developing and maintaining SSPs, and conducting evidence collection. The consultant will draft compliance documentation and support remediation tracking in a remote environment.
Summary Generated by Built In

About the Role 

Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements. We are looking for a mid-level CMMC and NIST practitioner who can step into active client delivery work, produce strong documentation, and help move projects forward without a lot of hand-holding. 

This is a contract role that may be structured as part-time or full-time based on project needs and candidate availability. 

What You Will Do 

As a CMMC / NIST Consultant Analyst at Hotman Group you will contribute directly to active client engagements involving federal compliance frameworks. You will: 

  • Support client engagements related to CMMC readiness, implementation, and documentation 
  • Develop, update, and maintain System Security Plans 
  • Assist with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and related deliverables 
  • Gather, organize, and review evidence supporting control implementation 
  • Support CUI scoping discussions, boundary definition, and enclave design 
  • Draft and refine control narratives, policies, procedures, and related compliance documentation 
  • Identify gaps and support development of POA&Ms and remediation tracking 
  • Work directly with client stakeholders to collect information, validate details, and keep deliverables moving 
  • Contribute to readiness efforts tied to assessments, documentation, and ongoing compliance activities 
  • Participate in peer review of deliverables before they go to clients — your work will be reviewed and you will review others 

This is hands-on delivery work in a remote consulting environment. You will be expected to step into active projects and contribute from day one. 

What You Bring 

  • 3 to 5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work 
  • Hands-on experience with CMMC-related work -- this is required, not a nice to have 
  • Direct experience developing or contributing to System Security Plans, evidence collection, remediation documentation, and compliance policies -- also required 
  • Familiarity with NIST SP 800-171, NIST SP 800-53, and FedRAMP 
  • Strong writing and documentation skills -- your deliverables are clear, accurate, and do not require heavy editing before they go to a client 
  • The ability to work directly with client stakeholders, gather information, manage follow-through, and keep work moving 
  • Strong organization and professionalism in a client-facing environment 
  • Comfort stepping into projects that are already in motion and contributing independently with minimal ramp-up time 
  • A default toward communication — you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client 

Experience supporting CMMC Level 2 efforts, CUI scoping, enclaves, or boundary discussions is a strong plus. Familiarity with POA&Ms, assessment readiness, and control crosswalks is also valued. 

Active certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one. 

This role requires direct accountability for work product and outcomes. If your CMMC or NIST experience has been primarily observational or in a support capacity without ownership of documentation or deliverables, this role will be a significant adjustment. 

Requirements 

  • Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future 
  • Able to pass a background check 
  • Reliable high-speed internet and a secure, private remote workspace 

Our Hiring Process 

Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on active client engagements. If you are confident in your CMMC and NIST expertise, this is your opportunity to show it. 

Why Hotman Group 

At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions. 

You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it. 

The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable. 

If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard — this is the place. 

No phone calls please. 

Skills Required

  • 3-5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work
  • Hands-on experience with CMMC-related work
  • Experience working with SSPs, policies, procedures, evidence collection, and remediation documentation
  • Familiarity with NIST SP 800-171, NIST SP 800-53, and FedRAMP
  • Strong writing and documentation skills
  • Authorized to work in the U.S.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Worth, Texas
14 Employees
Year Founded: 2016

What We Do

Since 2016, Hotman Group has worked with hundreds of business leaders to help them feel more confident in their cybersecurity programs. We take the build - implement - run approach to ensure each client is fully equipped to do the right thing when it comes to cybersecurity. First, we start with an assessment to determine where you are based on a benchmark within a security compliance framework like SOC 2, NIST CSF, and others. Then, we strategically prioritize your action items based on the risks to your business. Lastly, we help you set the bar based on the objective you'd like to reach.From a self-governed discipline to an all-inclusive cybersecurity program to the strictest audits, we help you handle it all. Most companies look at their cybersecurity piecemeal, inadvertently putting themselves at risk. With Hotman Group, we approach cybersecurity strategically, with a plan so you can be fully protected. Specialities: vCISO/ Fractional CISO, Cybersecurity, Risk Assessment, Gap Assessment, Maturity, Assessment, SOC 2, HITRUST, HIPAA, NIST CSF, NIST 800-53, ISO 27001, FFIEC, SOC 2 Readiness, Remediation, Auditor Support, Regulator Support, SOC 2 Audit, Data Protection (PHI, PII, PI), Risk Management (ERM), Privacy (GDPR, CCPA, SOC 2), GRC, Third Party Risk Management (TPRM), Supply Chain Risk, Vendor Risk, Business Continuity, Disaster Recovery, Business Impact Analysis (BIA), Metrics, Breach Support, Incident Response (IR), Tabletops

Similar Jobs

Cox Enterprises Logo Cox Enterprises

Search Engine Optimization Specialist

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
22-33 Hourly

Lansweeper Logo Lansweeper

Senior Quality Assurance Engineer

Cloud • Information Technology • Software
Hybrid
Austin, TX, USA
404 Employees

Optimum Logo Optimum

Product Manager

AdTech • Digital Media • Internet of Things • Marketing Tech • Mobile • Retail • Software
Hybrid
3 Locations
9000 Employees
123K-203K Annually

Optimum Logo Optimum

Site Reliability Engineer

AdTech • Digital Media • Internet of Things • Marketing Tech • Mobile • Retail • Software
Hybrid
2 Locations
9000 Employees
84K-137K Annually

Similar Companies Hiring

Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account