Description
Systems Engineering has immediate availability for a Senior CMMC Compliance Consultant to join our growing Advisory Services team in Portland, Maine. This role leads clients through CMMC readiness, from initial scoping and CUI boundary definition through NIST SP 800-171 gap analysis, remediation planning, evidence development, and assessment preparation. While CMMC is a primary focus, the GRC consulting role supports clients across multiple industries, regulatory requirements, and cybersecurity frameworks.
The Senior CMMC Compliance Consultant serves as a trusted advisor to client executives and technical teams, helping them translate compliance requirements into practical security improvements while providing leadership, coaching, and quality oversight to the broader consulting team.
This is a hybrid role, which includes a mix of remote & onsite work at our Portland, Maine office as well as onsite client engagements which may require occasional travel.
Consulting Scope:
- Lead CMMC scoping, readiness, and NIST SP 800-171 gap assessments by identifying FCI and CUI, evaluating data flows, defining the assessment boundary, and documenting in-scope people, processes, technologies, facilities, and external service providers. Develop and maintain assessment-ready deliverables, including System Security Plans, policies, procedures, control narratives, Plans of Action and Milestones, boundary and data-flow documentation, and supporting evidence, while clearly communicating findings and risk to technical and executive stakeholders.
- Information security program development and oversight.
- Utilizing Governance, Risk, and Compliance (GRC) tools to track and communicate compliance program status.
- Participation or leadership on client security committees.
- Community and industry thought leadership.
- Internal organizational leadership.
- Technology compliance consultants work with clients to ensure technology, compliance, and security are expertly managed through organizational policies, strategic IT planning, and at times taking ownership over roadmap execution.
Duties and Responsibilities:
- Lead clients through the development of security documentation, policies, and operating practices by facilitating decisions, establishing ownership, and coordinating work across client stakeholders and internal cross-functional teams, from operational staff to C-suite leaders.
- Direct the NIST 800-171 implementation process by confirming FCI and CUI flows, establishing the system boundary, and ensuring all relevant personnel, processes, technologies, facilities, and external service providers are accurately represented. Translate identified gaps into practical solution options, recommend an appropriate path forward, and coordinate with the technical resources responsible for implementation.
- Lead GRC consulting engagements across multiple industries and regulatory environments. Develop and maintain information security, business continuity, cybersecurity workforce, and compliance programs; facilitate the creation and maintenance of business continuity plans and risk assessments; and identify gaps against applicable frameworks and client requirements.
- Provide strategic CISO-level consultation to clients. Work independently with clients to ensure an appropriate technology and security posture is developed and maintained.
- Assemble, analyze, and deliver comprehensive IT risk assessments documenting “State of the State” for clients and making appropriate recommendations. Provide guidance and context in prioritizing and determining complexity of cultural and technological problems.
- Oversee remediation planning by defining required security and business continuity outcomes, evaluating proposed solutions, communicating residual risk, and confirming that completed work is supported by appropriate documentation and evidence.
- Provide internal training and mentorship.
Requirements
- BS or similar degree with 8+ years of progressively responsible experience. Applicants without a degree may substitute additional experience, especially in leadership roles (10+ years expected).
- Demonstrated experience leading CMMC or NIST SP 800-171 readiness engagements, including scope definition, gap assessment, remediation planning, evidence review, and preparation for an external assessment.
- CMMC Certified Professional, CMMC Certified Assessor, CISSP, CISA, CRISC, or a comparable security or compliance certification is strongly preferred. Candidates without a current credential should demonstrate equivalent CMMC and NIST SP 800-171 experience and be willing to obtain an agreed certification after hire. Candidates with current credentials will be required to supply proof of credentials during the application process.
- Strong working knowledge of CMMC, NIST SP 800-171, common CUI environments, identity and access management, endpoint security, network security, logging and monitoring, vulnerability management, incident response, backup and recovery, and cloud security. Experience evaluating Microsoft 365, Azure, and related security configurations is strongly preferred.
- Consulting experience strongly preferred.
- Ability to distil complex technical information into broadly comprehensible concepts, and vice versa.
- Must be an excellent written and oral communicator.
- Experience with HIPAA, GLBA, PCI, GDPR and NIST compliance is a plus.
- Project management experience preferred.
- Passion for security, governance, compliance, and risk required!
- Meet hybrid work requirements - ability to work onsite at our Portland, Maine office and travel occasionally for onsite client engagements. Reliable transportation is required.
Our Culture & Benefits
The employees of Systems Engineering are its most valuable resources who have collectively made Systems Engineering a Best Places to Work company in Maine for over a decade. We pride ourselves on delivering great outcomes for our culture, clients, and our community by cultivating a high-performing culture focused on continuous learning, collaboration, and community impact.
Our headquarters is in Portland, Maine, where we're located in the heart of the Old Port in downtown Portland, positioned centrally to the waterfront, trails, parks, cultural events, and restaurants.
Compensation & Pay Transparency Statement
Systems Engineering offers a competitive compensation package that reflects both the market and the experience you have. Base salary will be discussed during the interview process and is complemented by a comprehensive benefits package, hybrid flexibility, and the opportunity to do high-impact work for our clients. Systems Engineering is committed to fair, equitable, and competitive pay, reviewed regularly to ensure internal alignment and market relevance.
The base salary range for this position is $110,000 to $125,000 per year.
Benefits & Total Rewards
In addition to base pay, Systems Engineering supports people through benefits designed to sustain both work and life:
- Health & Wellbeing – Competitive medical, dental, & vision benefits, employer-paid life, short-term, and long-term disability insurance, 24/7 Employee Assistance Program (EAP), onsite fitness facilities, and wellness programs.
- Financial Wellbeing – Employer 401k matching contributions, short-term incentive plans (STIP), and free financial advising.
- Time & Flexibility – Paid Time Off starting with 17 days PTO, nine paid holidays, and hybrid work arrangements.
- Family Support – Paid parental leave & dependent care FSA programs.
- Professional Development & Growth Opportunities – Career mobility and professional development, with employer-supported training, learning, and certification opportunities, including tuition reimbursement benefits.
- Community & Culture – Paid community volunteer time, employer-charitable match programs, corporate golf membership, company-provided season tickets to local sports teams, employer provided parking, and regular company gatherings.
Due to the nature of our business and the requirements of ITAR regulations, this role may require access to controlled information and technology. Candidates must be U.S. citizens or lawful permanent residents and be willing to undergo a thorough background check as part of the employment process.
Systems Engineering values diversity and is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other status protected by law.
Skills Required
- Bachelor’s degree or similar degree, or additional experience in lieu of a degree
- 8+ years of progressively responsible experience; 10+ years expected without a degree
- Experience leading CMMC or NIST SP 800-171 readiness engagements
- Experience with scope definition, gap assessment, remediation planning, evidence review, and external assessment preparation
- Strong working knowledge of CMMC, NIST SP 800-171, CUI environments, identity and access management, endpoint security, network security, logging and monitoring, vulnerability management, incident response, backup and recovery, and cloud security
- Excellent written and oral communication skills
- Ability to translate complex technical information into broadly comprehensible concepts
- Passion for security, governance, compliance, and risk
- Ability to meet hybrid work requirements at the Portland, Maine office
- Reliable transportation
- U.S. citizenship or lawful permanent residency
- Willingness to undergo a thorough background check
- CMMC Certified Professional, CMMC Certified Assessor, CISSP, CISA, CRISC, or comparable security or compliance certification
- Experience evaluating Microsoft 365, Azure, and related security configurations
- Consulting experience
- Experience with HIPAA, GLBA, PCI, GDPR, and NIST compliance
- Project management experience
- Willingness to obtain an agreed security or compliance certification after hire if not currently credentialed
What We Do
Systems Engineering is a managed IT and cybersecurity services provider delivering world-class technical & business solutions to businesses.








