Remote CMMC Compliance Analyst
Saint Paul, Ramsey County, Minnesota, 55199, USA
Listed on 2026-05-27
-
IT/Tech
Cybersecurity, Information Security
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities.
At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter.
This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today.
The RoleThe CMMC Compliance Analyst must have advanced practical experience in managing all phases of security integration to assist the Security Manager and Director with managing the personnel, physical, information, and information systems (IS) security requirements for DoD, SCI and SAP activities as applicable to the program supported. They will write all standard operating procedures, maintain fixed facility checklists (FFCs), and author systems security plans in accordance with ICDs, DCIDs, and NISPOM requirements.
They will serve as a liaison to government program security officers (PSO), information systems security counterparts, and Lumen internal and external clients. Conduct initial and recurring training, prepare and process access requests, conduct indoctrinations and debriefings, and investigate and report security violations. Conduct self‑inspections, maintain associated security paperwork and media control records, conduct virus scanning and computer security briefings, and provide data containment support, including coordinating clean‑up efforts and reporting requirements.
This is a remote opportunity open to candidates located anywhere in the U.S.
The Main ResponsibilitiesExecute continuous monitoring activities across a CMMC L2 enclave, ensuring ongoing compliance with NIST SP 800-171 controls
Maintain audit‑ready evidence repositories, including policies, procedures, and technical artifacts
Perform periodic control assessments, validation, and remediation tracking
Support POA&M management, including identification, documentation, and closure of findings
Leverage GRC tools to manage controls, track compliance status, and maintain evidence
Collaborate with system owners, engineers, and ISSOs to ensure proper control implementation and sustainment
Prepare for and support C3
PAO assessments, surveillance reviews, and re‑certification activitiesTrack and report compliance status, risks, and metrics to leadership
Assist in updating SSPs, network diagrams, data flow diagrams, and supporting documentation
Required Qualifications
CMMC Registered Practitioner Advanced (RPA)
CMMC Certified Professional (CCP) certification within the first six months
Demonstrated experience supporting a successful CMMC Level 2 C3
PAO assessmentExperience with continuous monitoring, audit preparation, and compliance documentation
Strong working knowledge of NIST SP 800-171 controls and assessment objectives
Working knowledge of FAR, DFARS, and CMMC‑related cybersecurity and contracting requirements for Defense Industrial Base contractors.
Familiarity with evolving CMMC requirements
Experience integrating GRC platforms into continuous monitoring workflows and reporting
Familiarity with POA&M management and remediation processes
Ability to work in a structured, compliance‑driven environment with strong attention to detail
CMMC Certified Assessor (CCA) certification
Experience supporting FedRAMP Moderate or High ATO environments
Hands‑on experience using GRC tools such as Service Now IRM, Diligent, Archer, or similar platforms
Understanding of cloud environments (Azure Gov, AWS Gov Cloud) in regulated enclaves
This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).