CMMC Program Manager
Dallas, Dallas County, Texas, 75201, USA
Listed on 2026-08-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection
CMMC Program Manager
Balfour Beatty Construction, LLC (Company), a member of the Balfour Beatty plc group of companies, is searching for a CMMC Program Manager to support its compliance with cyber and physical security requirements for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) associated with the Company's Federal construction contracts, as well as equivalent requirements in private contracts. Candidates must have a strong working knowledge of FAR and DFARS requirements for the handling of FCI and CUI, excellent analytical, project management, communication, and organizational skills.
The selected candidate will ideally work out of our Falls Church, VA, office, but candidates based in Dallas, TX, will be considered as well. This is a hybrid position that requires working in the office three days per week and working from home two days per week.
The CMMC Program Manager is responsible for managing, maintaining, and continuously improving the organization's Cybersecurity Maturity Model Certification (CMMC) compliance program for the secure enclave supporting Department of Defense (DoD) and other Federal agency CUI, as well as the Company's policies and procedures for handling FCI. The CMMC Program Manager will serve as the primary liaison between compliance & ethics, IT, legal, and operations as it relates to governance, reporting, monitoring, assessment and organizational adoption of security requirements necessary to maintain ongoing compliance with NIST SP 800-171, NIST SP 800-137, FAR and DFARS requirements, and CMMC Level 1 and Level 2.
Essential Functions
- Serve as the organization's primary internal authority for CMMC compliance within the secure enclave, providing guidance to IT, IT Security, Operations, Human Resources, Legal, Procurement, Communications and executive leadership regarding FCI, CUI and equivalent compliance obligations and governance requirements.
- Own the organization's CMMC compliance program for the secure enclave, ensuring governance activities remain aligned with organizational objectives, contractual obligations, regulatory requirements, and evolving cybersecurity risks.
- Develop, maintain, and periodically review the Continuous Monitoring Plan (CMP) and support ISCM procedures.
- Develop, review, maintain, and coordinate approval of CMMC-related policies, standards, procedures, and supporting documentation.
- Define and manage ISCM strategy, risk tolerance, and reporting cadence in coordination with the CIO, CISO, CLO, and US Compliance Team.
- Lead initial implementation, as well as ongoing assessment of security control effectiveness, including vulnerability identification and reporting, configuration compliance, access reviews, and incident monitoring.
- Lead annual CMMC self-assessments, risk assessments, internal audits, certification readiness activities, and coordination with Certified Third-Party Assessment Organizations (C3
PAOs) for external CMMC assessments, as applicable. - Present compliance status, risk posture, and strategic recommendations to executive leadership and governance committees.
- Develop and maintain evidence repositories supporting ongoing internal assessments, external certification activities, and audit readiness.
- Ensure compliance documentation—including the System Security Plan (SSP), POA&Ms, policies, procedures, system inventories, data flow diagrams, asset inventories, evidence repositories, and assessment records—remains complete, accurate, and current.
- Track, report, coordinate, and validate remediation of deviations, exceptions, and findings discovered during monitoring or risk assessments.
- Prepare metrics dashboards and executive reports summarizing enclave risk posture and compliance trends.
- Coordinate compliance activities involving third-party service providers supporting the enclave, including review of agreements, security documentation, and shared responsibility requirements.
- Review proposed changes to enclave architecture, systems, applications, and operational processes to evaluate potential impacts to CMMC compliance and update compliance documentation as necessary.
- Coordinate with IT Operations and IT Security teams to ensure configuration baselines, asset inventories, and system changes remain aligned with approved security configurations and compliance requirements.
- Coordinate or participate in periodic incident response tabletop exercises involving IT, Legal, Human Resources, Executive Leadership, and applicable business stakeholders.
- Collect evidence management, control documentation, and audit preparation.
- Coordinate post-incident reviews, track corrective actions, and ensure lessons learned are incorporated into security controls, policies, procedures, training, and continuous monitoring activities to improve the organization's overall CMMC compliance posture.
- Collaborate with internal stakeholders:
- Business Stakeholders: program managers, project managers, and functional owners using enclave resources. Assist with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).