CMMC Compliance Manager
Listed on 2026-07-19
-
IT/Tech
Cybersecurity
At PCL Construction Enterprises, Inc., part of the PCL Family of Companies (PCL), we don’t just build projects—we build opportunities, careers and communities.
We’re a team of builders who care deeply about what we create and who we build it with. That includes you. We are not only investing in what’s next in construction, we are investing in what’s next for your career.
We are seeking to hire a CMMC Compliance Manager for our U.S. Head Office located in Denver, CO. Reporting to the President & COO, U.S. Operations and Assistant General Counsel, you will work closely with the Sr. Manager, Cybersecurity and Networking Business Technology and the Government Contract Compliance Officer. The CMMC Compliance Manager will be responsible for supporting the company’s U.S. government cybersecurity compliance program, with primary focus on Cybersecurity Maturity Model Certification (CMMC), NIST SP 800‑171 compliance, DFARS cyber requirements, and related contractual safeguarding obligations.
This role helps coordinate the governance, documentation, readiness, and ongoing compliance activities required to support eligibility for U.S. government contract performance.
- Employee ownership opportunities that build long‑term value
- Annual discretionary performance bonuses
- 401(k) with company match
- Industry‑leading medical, dental and vision benefits
- Prescription drug coverage and telemedicine services
- Life, AD&DD and disability insurance
- Paid parental leave and family care support
- HSA or FSA for healthcare, dependent care and transportation
- Mental health and wellness support, including Employee Assistance Programs
- Career growth pathways, leadership development and mentorship programs
- Access to world‑class training through PCL’s College of Construction and professional development courses
- Ongoing opportunities to learn new skills, explore different roles and grow your career across sectors and regions
- Manages the company’s CMMC compliance and government cybersecurity program across the U.S. operations, with accountability for readiness, assessment preparation, and ongoing compliance.
- Establishes, maintains, and enforces the cybersecurity compliance framework, including policies, procedures, standards, workflows, control ownership models, system security plans, POA&Ms, compliance matrices, evidence inventories, and readiness trackers across the U.S.
- Owns implementation and sustainment of NIST SP 800‑171, CMMC, DFARS/FAR safeguarding requirements, and related CUI handling obligations across applicable U.S. government contract work.
- Leads day‑to‑day cross‑functional execution of required technical and administrative controls, coordinating with business technology, information technology, cybersecurity, legal/compliance, contracts, operations and other stakeholders to drive delivery, timelines, evidence collection and issue resolution.
- Owns CMMC readiness and assessment preparation, including boundary definition, control narratives, inheritance strategy, evidence organization, assessment support files, and engagement with assessors, customers and external auditors.
- Monitors cybersecurity requirements in solicitations, contracts, modifications and flow‑down provisions, including DFARS 252.204‑7012, 252.204‑7019, 252.204‑7020, 252.204‑7021, FAR 52.204‑21 and related safeguarding clauses.
- Coordinates subcontractor and supplier compliance activities where cybersecurity clauses, safeguarding requirements or CUI handling obligations apply.
- Tracks remediation items, follow‑up actions, milestone dates and compliance gaps to closure, and maintains audit‑ready records in designated repositories in accordance with company governance requirements.
- Supports incident reporting workflows, escalation paths and documentation related to government cybersecurity reporting obligations.
- Develops and administers role‑based training and awareness for CMMC, CUI handling, safeguarding obligations and project‑level compliance execution.
- Prepares recurring status reports, dashboards, metrics and executive summaries regarding cybersecurity compliance posture, readiness and program progress.
- Participates in internal working groups and stays…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).