Qualifications
Key Responsibilities
Lead initial client scoping engagements: identify personnel, processes, and assets interacting with Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Develop accountability matrices and data flow diagrams.
Collaborate with Security Engineers to provide enclave architecture recommendations (GCC, GCC High, hybrid, on-prem, full environment) based on CUI/FCI locations within the client’s environment.
Perform comprehensive gap assessments against all 320 objectives across 110 controls of NIST SP 800-171 Rev 2. Score each objective as Met, Not Met, or Partially Met, and submit SPRS scores.
Create detailed Plans of Action and Milestones (POA&Ms) based on gap assessment outcomes. Prioritize remediation tasks and establish milestones, resource needs, and completion timelines.
Translate assessment findings into specific, actionable remediation tasks aligned with Azure/M365 components using the team’s Control-Task Tracker, ensuring sufficient detail for execution by Security Engineers.
Develop and maintain System Security Plans (SSPs) documenting all 110 controls, implementation statuses, system boundaries, data flows, and organizational policies.
Establish and manage a comprehensive CMMC compliance policy library, including access control, incident response, configuration management, audit policies, and all required documentation.
Oversee the evidence collection process, determining necessary evidence per control, coordinating with Security Engineers for technical evidence capture, and organizing the evidence for audit readiness.
About the job
Job Description
We are actively looking for a skilled CMMC Governance, Risk, and Compliance (GRC) Consultant to spearhead our compliance advisory efforts within our CMMC practice. In this pivotal role, you will be the key liaison for our clients, guiding them from initial project scoping to preparing for C3PAO assessments. Your leadership will help organizations navigate the entire compliance lifecycle with precision and assurance.
Your responsibilities will include conducting thorough gap assessments across all 110 NIST SP 800-171 controls and their 320 objectives, creating and maintaining System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms), and managing the evidence collection process to ensure readiness for CMMC Level 2 assessments. This role emphasizes governance, risk, and compliance over technical implementation, necessitating your ability to translate assessment findings into clear, actionable remediation tasks that Security Engineers can implement using established SOPs and runbooks. The ideal candidate will possess extensive experience with CMMC or NIST SP 800-171, demonstrate confidence in managing client relationships, and have a knack for distilling complex compliance requirements into practical, results-oriented guidance.
About its
its is a leading provider of compliance and cybersecurity solutions, dedicated to helping organizations navigate the complexities of regulatory requirements. Our team of experts is committed to delivering high-quality services that empower our clients to achieve their compliance goals effectively and efficiently.