CMMC Assessor; Certified CCA
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, IT Consultant
Coalfire Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with leading cloud and technology providers including Amazon, Microsoft, IBM, Google and Oracle and Federal agencies.
Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the United States and Europe and is committed to making the world a safer place by solving our clients’ toughest security challenges.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
Coalfire Federal is both an authorized
C3
PAO and CMMC RPO - and we’re on the lookout for Certified CCA and LCCA CMMC Assessors to join our growing team.
As a Certified CCA / LCCA Assessor
, you’ll work with leading manufacturing, IT, Cloud Service, and professional service organizations that compromise the Defense Industrial Base (DIB) serving the United States Department of Defense (DOD). You will be an integral part of a team that leads the efforts of these organizations to satisfy DOD's Cybersecurity Maturity Model Certification and related government regulations as an assessor to certify organizations’ compliance with CMMC requirements.
CMMC assessor positions are typically remote. Occasional or limited travel may vary based on client needs.
What you'll do- As an assessor you will work with and support team members in assessing whether members of the DIB have adequately prepared for compliance with CMMC regulations
- Assessors participate in the team that will evaluate an organization’s readiness for assessment, which include the experience and capability for tasks such as:
- Collect and examine evidence, observe, test and analyze results
- Clearly and effectively score OSC practices and validate preliminary results
- Generate preliminary report findings
- Finalize findings for an assessment report and deliver recommended assessment results
- Ability to work independently and as a part of a team
- Professional and polished interpersonal and communication skills with team members and stakeholders
- Experience, self-leadership, and enthusiasm in being part of our CMMC program that leads engagements, builds capabilities, and serves as a trusted advisor
- Strong working knowledge of the controls and implementation of DFARS Clause (NIST 800-171)
- Direct involvement with building reports that clearly communicate met and not met objectives in accordance with assessment guidelines
- Ability to track detailed tasks and ensure timely delivery of project deliverables
- Excellent communication and problem-solving skills
- Critical thinking, and ability to balance security requirements with mission needs
- Must be well-organized and detail-oriented with the ability to coordinate, prioritize multiple tasks, and be adaptable to change to accomplish assignments
- Hands on risk management and assessment experience
Completed Bachelor’s degree from an accredited university, preferably in an IT related field.
Clearance / Suitability Requirements- Currently possess completed Tier 3 Suitability with the CyberAB
- Required
:
Cyber
AB Certified CCA or LCCA - Candidates with the experience and the pre-requisites to become certified for the LCCA are also considered
- Additional cybersecurity certifications and experience highly desired
- Minimum 5+ years of experience in the IT Security / Cybersecurity industry
- To include at minimum 2 years in a Client facing role providing risk assessment, advisory services, and/or consulting - ideally in a federal environment
- Previous experience working for a CMMC RPO or C3
PAO (Candidate or Authorized) or other 3
PAO assessments is highly desired
- CISSP or other industry recognized Cybersecurity certifications
Our people make…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).