Compliance Consultant, CMMC

JobgetherVerified source: this listing comes from the employer's official hiring system or a verified company · United States · Remote
Listed via Lever
Posted Aug 19, 2026 · Apply by Nov 18
Recently checked

Last checked active on Aug 20, 2026.

Position Overview

Location: United States United States flag
Compensation: Not disclosed
Position: Mid
Type: Job
Employment: Full time
Practice Area: Compliance
Remote: Yes
Deadline: Nov 18, 2026

Job Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Compliance Consultant, CMMC based in United States.

This is an opportunity to play a lead role in strengthening cybersecurity, governance, risk, and compliance programs for organizations operating within the U.S. Defense Industrial Base. You will advise clients on complex regulatory and security requirements while helping them build practical, sustainable compliance programs. The role combines hands-on assessment, documentation, consulting, and stakeholder management across technical and business teams. You will work with frameworks and regulations including CMMC, NIST SP 800-171, DFARS, CUI requirements, and export controls. Success requires both technical depth and the ability to translate complex requirements into clear, actionable guidance. This is a remote consulting position with a collaborative, security-first environment and minimal U.S. travel.

Accountabilities:

    • Lead the development and ongoing management of client Governance, Risk, and Compliance programs, partnering with business leaders, IT teams, professional services teams, and third-party providers.
    • Document the flow of sensitive and controlled information through business processes and establish appropriate compliance system boundaries covering technology, people, and processes.
    • Assess the implementation of cybersecurity and compliance requirements, including CMMC, NIST SP 800-171, DFARS, FAR, CUI requirements, and applicable export controls.
    • Develop, maintain, and improve System Security Plans, security policies, procedures, compliance documentation, and supporting evidence.
    • Collaborate with technical and functional stakeholders to define, document, and deliver security controls, artifacts, and remediation activities.
    • Provide ongoing advisory services to clients, translating regulatory and cybersecurity requirements into practical recommendations and sustainable compliance practices.
    • Apply subject matter expertise in CMMC Levels 1 and 2, NIST frameworks, DFARS requirements, CUI classifications, ITAR, EAR, and related federal cybersecurity requirements.
    • Manage client expectations, project resources, schedules, deliverables, and third-party relationships to ensure successful engagements.
    • Stay current with evolving cybersecurity regulations, government policies, security practices, technologies, and vendor solutions relevant to the Defense Industrial Base.
    • Support colleagues with client requirements and contribute to cross-training and the development of broader consulting capabilities.
    • Requirements:

      • 3+ years of experience implementing cybersecurity requirements for Department of Defense contractors or federal information systems, including hands-on experience with NIST SP 800-171 or NIST SP 800-53.
      • Demonstrated subject matter expertise in CMMC assessment and certification requirements, including assessment objectives through Level 2, boundary scoping, and DFARS 252.204-7012 requirements.
      • Working knowledge of FedRAMP Moderate equivalency requirements for cloud service providers and DFARS requirements covering applicable incident reporting and information protection obligations.
      • Awareness of U.S. export control requirements under ITAR and EAR, as well as the CUI program, including CUI, CDI, CTI, and FCI concepts.
      • Strong written and verbal communication skills, with the ability to explain technical and regulatory concepts clearly to executives, technical teams, and other client stakeholders.
      • High emotional intelligence, empathy, and interpersonal skills, with a collaborative approach to client relationships and stakeholder coordination.
      • Strong organizational and time-management abilities, including the capacity to prioritize multiple projects, maintain deadlines, and deliver high-quality work under pressure.
      • Adaptability, resilience, sound judgment, and the ability to remain composed in fast-paced consulting environments.
      • Familiarity with cybersecurity products, vendors, current security practices, and relevant security frameworks such as CMMC, NIST, CIS, or MITRE ATT&CK.
      • Experience with Microsoft Azure and Office 365, particularly Azure Government and Microsoft 365 GCC High, is preferred.
      • Professional certifications such as Cyber AB CCP/CCA, CISSP, CISM, CISA, or similar credentials are advantageous.
      • Experience consulting with multiple clients simultaneously and a bachelor's degree or higher in technology, engineering, or a related field are preferred.
      • Ability to obtain a U.S. government security clearance is a plus; veteran candidates are preferred.
      • Willingness to travel occasionally to U.S. client sites, generally less than 10% of the time.
      • Benefits:

        • Remote work model with minimal travel.
        • Medical, dental, and vision insurance.
        • Four weeks of paid time off, including vacation and sick leave.
        • Four weeks of paid maternity and paternity leave.
        • Two paid volunteer days.
        • 401(k) plan with a 4% company match.
        • Company bonus structure.
        • Tuition reimbursement.
        • Employer-sponsored disability and life insurance.
        • Professional development and opportunities to expand cybersecurity and compliance expertise.
        • Collaborative, people-focused workplace culture centered on security, advocacy, adaptability, and resilience.
        • Opportunity to work on meaningful cybersecurity and compliance initiatives supporting organizations in the U.S. Defense Industrial Base.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1

Practice Area

Position

Mid

Industry

Legal

Applicant Location Requirements

Applicants must be located in: United States

Application Deadline

November 18, 2026

Employment Type

Full time

Work Arrangement

Remote/Telecommute Position

Application to Jobgether

Sign in to apply

See the complete description, requirements, and every detail of this role, then apply. Everything here is included with your account.

Apply to this job and future roles across 95 countries
Human CV / resume reviews from real experts
Application tracker, saved roles, and company watchlist
Return to this job the moment you are signed in
Report this job
Thank you. Our team will review this report.

Tell us if this listing is inaccurate, closed, fake, duplicated, or unsafe. You do not need an account to report it.