Job Description
The CMMC Compliance Consultant is the subject matter expert who carries DIB clients through the full CMMC lifecycle. You own engagements end to end, from initial gap assessment through assessor-ready documentation, and you are the technical authority clients lean on when the requirements get hard.
This is practitioner-level work. You scope CUI environments, build the SSPs and POA&Ms an assessor will actually accept, and translate dense regulatory language into guidance a client can act on. You sit in pre-sales calls and executive readouts, you mentor the junior consultants coming up behind you, and you help sharpen the methodology the whole practice runs on. Active CCP and CCA credentials are non-negotiable for this role.
What You'll Own
Assessment and Advisory. Lead and execute CMMC Level 2 gap assessments against all 110 NIST SP 800-171 Rev 2 practices across the 14 control domains. Conduct readiness reviews and deliver findings with prioritized remediation roadmaps.
Assessor-Ready Documentation. Author and maintain SSPs, POA&Ms, policies, procedures, and implementation narratives using the NIST SP 800-171A examine, test, and interview methodology. Build CMMC-scoped network diagrams, data flow diagrams, and CUI boundary documentation.
CUI Environment Scoping. Evaluate client environments scoped to CUI systems, including Microsoft 365 GCC and GCC High, Intune and Microsoft Defender for Endpoint, and specialized platforms such as PreVeil.
Client Engagement. Serve as the primary technical point of contact for assigned DIB accounts across the compliance lifecycle. Facilitate interviews with client staff to validate controls and gather evidence, and present status and executive readouts with clarity.
GRC Platform Integrity. Own data integrity in the GRC platform (e.g., IntelliGRC) for SSP management, POA&M tracking, and evidence management.
Practice Development. Improve internal CMMC methodologies, templates, and tooling. Mentor junior consultants, and track CMMC Program rule changes (32 CFR Part 170, DFARS 252.204-7021) and Cyber AB guidance updates so the practice stays current.
Qualifications
Required
Preferred
Additional Information
Additional Information
Agile IT runs on its RISE values: Reliability, Integrity, Stewardship, and Excellence. We hire people who live them.