This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a detail-oriented CMMC Level 2 Compliance Specialist to lead and support our organization’s efforts to achieve and maintain compliance with the Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements. This role will work cross-functionally with IT, security, legal, compliance, and business stakeholders to assess current controls, identify gaps, implement remediation plans, and prepare for certification assessments.
Job Responsibility:
Lead CMMC Level 2 compliance initiatives across the organization
Assess and document the implementation of NIST SP 800-171 security controls and related practices
Perform gap assessments, readiness reviews, and internal audits to evaluate compliance posture
Develop, maintain, and update required compliance documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, standards, and procedures
Coordinate remediation efforts with internal teams to address control deficiencies and strengthen cybersecurity processes
Support evidence collection and audit preparation for external assessors and certification activities
Track compliance milestones, risks, and dependencies, and provide regular status reporting to leadership
Partner with IT and security teams to validate technical, administrative, and operational controls
Monitor regulatory updates and changes to CMMC, DFARS, FAR, and related federal cybersecurity requirements
Help promote security awareness and compliance best practices throughout the organization
Requirements:
Bachelor’s degree in cybersecurity, information technology, information assurance, compliance, or a related field preferred
3+ years of experience in cybersecurity compliance, information security, risk management, or audit
Hands-on experience with CMMC Level 2, NIST SP 800-171, and federal contractor compliance requirements
Strong understanding of security frameworks, control testing, risk assessments, and documentation requirements
Experience creating and maintaining SSPs, POA&Ms, and related compliance artifacts
Familiarity with DFARS 252.204-7012, NARA 800-171 requirements, and handling Controlled Unclassified Information (CUI)
Strong project management, organizational, and communication skills
Relevant certifications such as CISSP, CISA, CISM, Security+, CCP, or related credentials are a plus
Nice to have:
Experience supporting DoD contractors or organizations operating in regulated federal environments
Ability to translate technical control requirements into practical business processes
Strong analytical and problem-solving skills with high attention to detail
Experience working with cross-functional stakeholders and external auditors or assessors