CMMC Assessment Lead
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-06-12
-
IT/Tech
Cybersecurity, IT Support, Systems Analyst
About SecureITSM
Secure
ITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). Secure
ITSM is a CMMC Certified Organization (CMMC UID #L) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.
We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3
PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities.
Location and TravelThis is a remote position with occasional travel required to support customer assessments.
Position SummaryThe CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership.
This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible.
Key Responsibilities Plan and Coordinate Assessments (Primary)- Maintain the master CMMC customer assessment schedule
- Coordinate assessment timelines with customers, C3
PAOs, and internal Secure
ITSM teams - Conduct readiness reviews and pre‑assessment planning meetings
- Track customer assessment milestones, dependencies, and remediation activities
- Manage customer communications related to assessment preparation and scheduling
- Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
- Monitor assessment status and provide executive‑level reporting on customer readiness
- Assist customers in understanding assessment scope, boundary definitions, and enclave considerations
- Update implementation statements as needed
- Gather and organize evidentiary artifacts
- Coordinate customer evidence collection activities
- Review SSPs, policies, procedures, and supporting documentation for assessment readiness
- Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
- Prepare assessor‑ready evidence packages and artifact repositories
- Conduct internal quality assurance reviews of documentation and evidence
- Identify documentation gaps and coordinate remediation activities
- Support development and maintenance of Plans of Action & Milestones (POA&Ms)
- Ensure documentation aligns with evolving CMMC and NIST guidance
- Attend and actively support customer assessments
- Actively defend implementations and evidence presented to assessors
- Coordinate assessment interviews and technical demonstrations
- Support mock assessments and readiness exercises for customers
- Assist customers in responding to assessor requests and follow‑up questions
- Document assessment observations, findings, and remediation actions
- Coordinate post‑assessment remediation activities and evidence resubmissions when required
- Serve as a trusted advisor throughout the certification lifecycle
ITSM’s Authorization and Compliance (Secondary)
- Conduct Secure
ITSM’s annual self‑assessment activities - Maintain internal compliance documentation and evidentiary artifacts
- Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
- Assist with internal policy and procedure updates
- Support ongoing continuous monitoring and compliance validation activities
- Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
- Maintain and update…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).