Practice Manager, Director, Principal; NIST/CMMC
Listed on 2026-07-25
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant
112
Cyber is seeking an experienced Services leader and Cyber Compliance professional ready to lead the growth and execution of our CMMC Compliance practice and team members.
As titles vary across the industry, 112
Cyber is seeking someone with experience equivalent to a Practice Manager, Director, Principal, or similar leadership role.
In this role, you will be responsible for shaping and scaling our CMMC compliance services, owning customer delivery outcomes, and serving as a senior advisor to both clients and internal teams.
As the leader of the Compliance practice, you will drive strategic oversight of customer engagements, mentor and develop consultants, establish delivery standards, and partner closely with our platform and product teams to influence roadmap decisions based on customer needs.
How You'll Drive Success:Success in this role predicates that 112
Cyber will only consider applicants with a current or former background in leading and growing a successful professional services organization in the cyber risk and compliance domain. A mix of advisory and attestation experience is ideal.
- Oversee and govern cybersecurity compliance engagements executed by senior consultants, ensuring consistent quality, methodology, and client outcomes.
- Provide senior advisory oversight for customer programs supporting DFARS, CMMC, FedRAMP, NIST CSF and NIST SP 800-171 initiatives.
- Own engagement success by partnering with client leadership to align regulatory requirements with business goals and risk tolerance.
- Review and validate assessment approaches, control testing strategies, and evidence packages for readiness and formal certification efforts.
- Build and scale practice capability through the creation of repeatable delivery processes and ongoing consultant development.
- Advise 112
Cyber's ASCERA team on changing compliance requirements and rule interpretation to inform CMMC software development. - Manage practice resources and capacity, aligning consultant skills and availability to active projects while balancing utilization, delivery timelines, and customer priorities.
PAO Assessments
- Oversee formal CMMC assessments conducted by assessment teams, ensuring adherence to C3
PAO requirements, assessment methodology, and accreditation standards. - Own the implementation of quality standards and processes to ensure repeatable, successful outcomes and a high level of customer satisfaction
- Review and approve evidence packages, including technical artifacts such as system logs, incident reports, and audit trails, to confirm compliance and defensibility of conclusions.
- Ensure consistent and unbiased assessment execution, maintaining strict objectivity and evidence-based decision making throughout the assessment lifecycle.
- Oversee assessment documentation and submission readiness for CMMC-AB, ensuring completeness, quality, and regulatory compliance across all C3
PAO engagements. - Maintain assessment integrity and consistency across the practice by enforcing standardized procedures, quality controls, and continuous improvement of the C3
PAO program.
Cyber Risk and Compliance Domain Expertise
- 5-8+ years of experience in IT security controls testing and documentation, including responsibility for managing and overseeing client control testing efforts.
- 5+ years of experience leading and coordinating external and internal audit activities, including DFARS, CMMC, NIST 800-53, or similar regulatory assessments.
- 5+ years of experience producing high-quality technical documentation, compliance deliverables, and executive-level reports.
- 3+ years of experience in practice leadership, including managing consultant performance, capacity planning, delivery quality, and continuous improvement of service offerings.
- Self-directed leader with a strong sense of ownership and accountability for outcomes.
- Proven ability to engage executive stakeholders, build trusted relationships, and influence decision-making.
- Exceptional communicator, able to translate complex technical and regulatory concepts into clear, actionable guidance for non-technical audiences
- Active Lead CMMC Certified Assessor (CCA) credential; if not CCA certified, willingness to obtain.
- One or more industry certifications such as CISSP, CISM, CISA, CRISC, or equivalent.
Why 112
Cyber?
- The chance to be part of a winning team and a premier fast-growing Cyber Risk and Compliance firm (offering both Advisory and C3
PAO services). - One of only under (105) C3
PAOs in the United States approved by the CyberAB (DoD). [AB = Advisory Board, the organization set up by the DoD to manage and oversee the CMMC program.] - Strong culture tied to building an organization around top-performing human capital and customer success.
- Ability to help shape the business in terms of this individual and their direct impact…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).