Jobgether
GRC Engineer (CMMC)
engineeringfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Accountabilities:
- Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to assess client architectures against federal security requirements.
- Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 requirements, translating regulatory expectations into practical and actionable security milestones.
- Author, maintain, and evaluate key compliance and authorization artifacts, including System Security Plans (SSPs), control implementation narratives, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).
- Conduct detailed readiness assessments and gap analyses to prepare clients for federal Authority to Operate (ATO), Joint Authorization Board (JAB), and CMMC assessment pathways.
- Define and document technical authorization boundaries, data flows, interconnectivity, and shared-responsibility models across FedRAMP and CMMC environments.
- Execute continuous monitoring activities, including vulnerability management tracking, incident response documentation, structural change workflows, and recurring compliance updates.
- Coordinate external assessment activities between clients, Cloud Service Providers, 3PAOs, C3PAOs, and relevant federal stakeholders.
- Develop structured compliance documentation and assessment-readiness materials for CMMC Level 1 and Level 2 engagements.
- Manage multiple client compliance initiatives simultaneously while maintaining strong documentation quality, deadlines, and delivery standards.
- Serve as a trusted client advisor, communicating complex security and compliance concepts clearly and helping stakeholders navigate evolving requirements.
- Stay current with changes to federal cybersecurity frameworks, regulatory requirements, cloud security practices, and defense compliance standards.
- 2+ years of direct experience in GRC, cybersecurity compliance, or related roles with hands-on exposure to FedRAMP, NIST SP 800-53, NIST SP 800-171, or federal authorization lifecycles.
- Practical experience authoring, evaluating, and maintaining federal compliance artifacts, particularly SSPs and POA&Ms.
- Foundational knowledge of CMMC 2.0 and NIST SP 800-171 requirements as they apply to defense contractors and Controlled Unclassified Information (CUI).
- Familiarity with DFARS requirements and CUI protection practices is strongly valued.
- Experience working with government cloud environments such as AWS GovCloud, Azure Government, or Microsoft GCC High.
- Understanding of cloud shared-responsibility models, technical security boundaries, data flows, and secure configurations.
- Experience supporting B2B SaaS providers, federal contractors, regulated technology organizations, or comparable clients.
- Strong project management and organizational skills, with the ability to manage several fast-moving compliance initiatives while maintaining attention to detail.
- Excellent written and verbal English communication skills, with confidence engaging directly with technical teams, clients, assessors, and other stakeholders.
- Ability to translate complex regulatory and technical requirements into clear, actionable guidance.
- Comfortable operating independently in a fast-growing consulting environment where priorities can evolve quickly and ownership is expected.
- CMMC credentials such as Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) are advantageous.
- Certifications such as CISSP, CISM, or CompTIA Security+ are a plus.
- Direct experience supporting JAB or federal Agency ATO processes is highly valued.
- Previous collaboration with 3PAO or C3PAO assessment teams is beneficial.
- Must be authorized to work in the United States without current or future visa sponsorship.
- Able to work a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time, with occasional flexibility as business needs require.
- Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities.
- Reliable high-speed internet and a professional home-office environment suitable for confidential client work and virtual collaboration.
- Competitive base salary with regular performance reviews and merit-based appraisal opportunities.
- Bonus opportunities based on performance.
- Remote-first culture with the flexibility to work from anywhere in the United States.
- Mentorship, training, and structured career development opportunities.
- Reimbursement for approved role-related training and professional certification courses.
- Opportunity to deepen expertise across CMMC, NIST, FedRAMP, and federal cybersecurity compliance.
- Growth opportunities within a fast-paced, early-stage environment.
- Collaborative culture with exposure to complex cybersecurity and compliance engagements.
Requirements:
Benefits:
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply