Information Security Advisor III; CMMC
Indianapolis, Hamilton County, Indiana, 46262, USA
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, Information Security
Location: Indianapolis
Overview
At RAMPQuest, we partner with organizations to navigate complex cybersecurity and compliance frameworks, offering expert‑led consulting, advisory services, risk assessments, and program management. With deep experience across both public sector and commercial clients, we help organizations operationalize standards such as NIST SP 800‑53 and CMMC, including services as the Program Management Office (PMO) for GovRAMP. Our values—trust, community, and integrity—guide our engagement with clients, providers, and partners.
The Information Security Advisor III (CMMC) is a senior‑level advisory role responsible for leading complex CMMC readiness and compliance preparation engagements and serving as a subject matter expert for organizations preparing for future third‑party CMMC assessments. This position applies assessor‑informed expertise to evaluate CMMC implementation maturity, guide remediation efforts, and improve the quality and defensibility of client security programs.
While this role requires CMMC Certified Assessor (CCA) credentials, it does not perform certification assessments, validate assessment packages, or issue compliance determinations. Instead, the role operates strictly in an advisory and readiness capacity, helping organizations understand assessment expectations and prepare effectively for evaluation by an authorized C3
PAO. The role requires advanced technical knowledge, strong analytical capability, and the ability to clearly communicate complex regulatory and technical concepts to technical and non‑technical stakeholders.
The Information Security Advisor III leads CMMC‑focused client engagements, reviews and finalizes readiness documentation, and develops strategic remediation recommendations aligned with CMMC requirements and supporting standards. This role also provides mentorship to junior advisors, contributes to the continuous improvement of CMMC advisory methodologies, and collaborates cross‑functionally to ensure consistent, high‑quality service delivery. The position operates with a high degree of independence and is expected to exercise sound judgment, discretion, and influence in both client and internal interactions.
We are located in Indianapolis and are looking to fill the on‑site position, with local applicants given preference. For the right candidate, we will consider remote work.
Responsibilities- Lead and oversee complex CMMC advisory and readiness engagements, serving as the primary subject matter expert and escalation point for CMMC‑related client and internal inquiries.
- Conduct advanced CMMC readiness evaluations, gap analyses, and compliance assessments using assessor‑informed methodology to evaluate implementation maturity and preparedness for CMMC Level 1 and Level 2 requirements, without performing formal certification assessments.
- Develop, review, and approve CMMC‑related documentation, including policies, procedures, implementation narratives, evidence mappings, remediation plans, and readiness artifacts, ensuring accuracy, completeness, and alignment with CMMC expectations and supporting standards such as NIST SP 800‑171.
- Mentor, guide, and provide technical oversight to junior advisors supporting CMMC engagements, contributing to knowledge transfer, skill development, and overall team effectiveness.
- Lead and facilitate client advisory meetings, executive briefings, interviews, and readiness workshops, clearly communicating CMMC requirements, assessment expectations, and technical concepts to both technical and non‑technical audiences.
- Collaborate cross‑functionally with consulting, advisory, PMO, and program leadership teams to ensure alignment on CMMC engagement objectives, deliverables, and service quality.
- Identify opportunities for operational, methodological, or engagement‑level improvements and contribute to the refinement of CMMC advisory processes, standards, templates, and client‑facing materials.
- Ensure all advisory deliverables meet established quality standards, contractual requirements, organizational policies, and ethical boundaries related to non‑C3
PAO advisory services. - Maintain current knowledge of evolving CMMC requirements,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).