Jobgether
Jobgether

GRC Engineer (CMMC)

engineeringfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

Accountabilities:

    • Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to assess client architectures against federal security requirements.
    • Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 requirements, translating regulatory expectations into practical and actionable security milestones.
    • Author, maintain, and evaluate key compliance and authorization artifacts, including System Security Plans (SSPs), control implementation narratives, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).
    • Conduct detailed readiness assessments and gap analyses to prepare clients for federal Authority to Operate (ATO), Joint Authorization Board (JAB), and CMMC assessment pathways.
    • Define and document technical authorization boundaries, data flows, interconnectivity, and shared-responsibility models across FedRAMP and CMMC environments.
    • Execute continuous monitoring activities, including vulnerability management tracking, incident response documentation, structural change workflows, and recurring compliance updates.
    • Coordinate external assessment activities between clients, Cloud Service Providers, 3PAOs, C3PAOs, and relevant federal stakeholders.
    • Develop structured compliance documentation and assessment-readiness materials for CMMC Level 1 and Level 2 engagements.
    • Manage multiple client compliance initiatives simultaneously while maintaining strong documentation quality, deadlines, and delivery standards.
    • Serve as a trusted client advisor, communicating complex security and compliance concepts clearly and helping stakeholders navigate evolving requirements.
    • Stay current with changes to federal cybersecurity frameworks, regulatory requirements, cloud security practices, and defense compliance standards.
    • Requirements:

      • 2+ years of direct experience in GRC, cybersecurity compliance, or related roles with hands-on exposure to FedRAMP, NIST SP 800-53, NIST SP 800-171, or federal authorization lifecycles.
      • Practical experience authoring, evaluating, and maintaining federal compliance artifacts, particularly SSPs and POA&Ms.
      • Foundational knowledge of CMMC 2.0 and NIST SP 800-171 requirements as they apply to defense contractors and Controlled Unclassified Information (CUI).
      • Familiarity with DFARS requirements and CUI protection practices is strongly valued.
      • Experience working with government cloud environments such as AWS GovCloud, Azure Government, or Microsoft GCC High.
      • Understanding of cloud shared-responsibility models, technical security boundaries, data flows, and secure configurations.
      • Experience supporting B2B SaaS providers, federal contractors, regulated technology organizations, or comparable clients.
      • Strong project management and organizational skills, with the ability to manage several fast-moving compliance initiatives while maintaining attention to detail.
      • Excellent written and verbal English communication skills, with confidence engaging directly with technical teams, clients, assessors, and other stakeholders.
      • Ability to translate complex regulatory and technical requirements into clear, actionable guidance.
      • Comfortable operating independently in a fast-growing consulting environment where priorities can evolve quickly and ownership is expected.
      • CMMC credentials such as Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) are advantageous.
      • Certifications such as CISSP, CISM, or CompTIA Security+ are a plus.
      • Direct experience supporting JAB or federal Agency ATO processes is highly valued.
      • Previous collaboration with 3PAO or C3PAO assessment teams is beneficial.
      • Must be authorized to work in the United States without current or future visa sponsorship.
      • Able to work a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time, with occasional flexibility as business needs require.
      • Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities.
      • Reliable high-speed internet and a professional home-office environment suitable for confidential client work and virtual collaboration.
      • Benefits:

        • Competitive base salary with regular performance reviews and merit-based appraisal opportunities.
        • Bonus opportunities based on performance.
        • Remote-first culture with the flexibility to work from anywhere in the United States.
        • Mentorship, training, and structured career development opportunities.
        • Reimbursement for approved role-related training and professional certification courses.
        • Opportunity to deepen expertise across CMMC, NIST, FedRAMP, and federal cybersecurity compliance.
        • Growth opportunities within a fast-paced, early-stage environment.
        • Collaborative culture with exposure to complex cybersecurity and compliance engagements.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now
GRC Engineer (CMMC) at Jobgether — Remote