More jobs:
Lead CMMC Certified Assessor Security Clearance
Job in
Oak Ridge, Anderson County, Tennessee, 37830, USA
Listed on 2026-06-04
Listing for:
Boston Government Services, LLC
Full Time
position Listed on 2026-06-04
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Job Description & How to Apply Below
Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Lead CMMC Certified Assessor to support our clients in multiple locations. BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects.
We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction.
Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection. If you align with BGS’ company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!
Overview:
The Lead CMMC Certified Assessor is responsible for the performance of cybersecurity framework assessments to determine compliance with Government-mandated cybersecurity regulatory requirements. This position is primarily responsible for Cybersecurity Maturity Model Certification (CMMC) for Maturity Levels 1, 2, and 3, National Institute of Standards and Technology Special Publication - NIST SP 800-171, and NIST SP 800-172 assessments but may also be asked to conduct assessments against NIST SP 800-53 Risk Management Framework (RMF), International Organization for Standardization - ISO 27001, Center for Internet Security, the NIST Cybersecurity Framework.
Responsibilities:
Maintain CMMC documentation for BGS as a Certified Third-Party Assessor Organization (C3
PAO) within the CMMC Ecosystem.
Conduct cybersecurity assessments for a broad range of customer environments to determine any gaps that exist between compliance requirements and actual implementation based on common NIST standards, such as NIST SP 800-53, NIST SP 800-82, and NIST SP 800-171.
Lead or participate in assessment teams to evaluate organizations against compliance standards.
Develop & manage assessment project plans.
Work with the customer to conduct interviews and observe technical implementations.
Provide guidance to customers, as needed, to facilitate compliance requirements.
Conduct compliance and cybersecurity workshops.
Create assessment reports and gap analysis reports.
Create System Security Plans, Plan of Action & Milestones, and security procedures.
Other duties as assigned. Requirements:
Associate’s degree or higher (equivalent experience/military will be considered)
4 years of direct cybersecurity or Information Technology experience are required.
Must have a Lead CMMC Certified Assessor (CCA).
Must have one or more of the following certifications:
Cybersecurity & Infrastructure Security Agency (CISA).
Certified Information Systems Security Professional (CISSP).
Certified Cloud Security Professional (CCSP).
Certified Information Security Manager (CISM).
CompTIA Advanced Security Practitioner (CASP+).
Certified Chief Information Security Officer (CCISO).
Global Information Assurance Certification (GIAC).
GIAC Certified Enterprise Defender (GCED).
GIAC Certified Incident Handler Certification (GCIH).
GIAC Security Leadership (GSLC).
Prior cybersecurity assessment experience is required.
Experience in technical document writing.
Experience in a security/compliance focused role with 3 to 5 years of experience performing technical security audits and risk assessments.
Minimum of 1 year of experience with cloud-based concepts with an…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×