CMMC Security Analyst
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, IT Consultant
* Top Skills' Details
* A successful candidate for this role is:
* A do-er, not just a strategist-comfortable rolling up their sleeves to get into technical details.
* Confident, able to make and defend architectural decisions.
* Technically deep, with current, relevant experience-not theoretical or outdated.
* A translator, who can turn strategic directives into concrete, implementable technical outcomes.
* A high bar setter, capable of enforcing standards and ensuring teams do things the right way.
NIST - Specifically NIST 800-171, if they have 2-3 years of CMMC compliance or exposure it would be even better
Risk Assessment - Mapping CMMC and NIST 800-171 controls to application security capabilities
CUI - Controlled Unclassified Information - Define technical security requirements (IAM, logging, encryption, boundary protection, vulnerability management) for CUI-tier systems.
* Description
* This role requires a true do-er-a hands-on technical leader who can translate strategy into actionable architecture decisions, guide teams through compliant solution design, and defend architectural requirements with confidence and clarity.
The ideal candidate brings deep, recent experience working within CMMC environments, supporting assessment readiness, and understanding what is materially required to satisfy control expectations. This individual must be able to navigate complex technical landscapes, challenge assumptions, and enforce architectural standards with authority.
Some of the responsibilities will include:
CMMC/C3
PAO
Experience:
* Leverage previous C3
PAO, assessment, or consultancy experience to guide teams through the "what" and "why" of compliance evidence and architectural expectations.
* Translate CMMC control requirements into actionable technical implementations for application, infrastructure, and security teams.
* Partner with compliance stakeholders to ensure architectures are audit-ready and enforceable.
Hands-On Technical Guidance:
* Act as a "technical translator" capable of bridging strategy and implementation.
* Provide detailed architectural deep dives, design validation, and solution recommendations for complex systems.
* Coach application owners, infrastructure engineers, and solution architects on best practices, required evidence, and compliant system design.
Cross-Functional Engagement:
* Engage in governance forums, ARBs/CABs, design reviews, and compliance working sessions.
* Influence stakeholders at all levels-from developers and engineers to executive leadership.
* Ensure that architecture principles are consistently understood, adopted, and executed across the organization.
* Skills
* NIST, Risk assessment, CUI, remediation, CMMC, system security plans, POAM
* Top Skills Details
* nist,Risk assessment,CUI,remediation
* Additional
Skills & Qualifications
* * Demonstrated experience working with or within a C3
PAO, assessment organization, or equivalent CMMC-focused consultancy.
* Strong, current knowledge of CMMC 2.0 Level 2, NIST SP 800-171, FedRAMP, and secure enclave architectures.
* Deep technical background across multiple domains:
oCloud (Azure/Azure Gov/AWS)
oApplication architectures (custom, SaaS, COTS)
oNetworking and identity security
oData protection and boundary segmentation
* Proven ability to defend architectural decisions using technical, security, and compliance rationale.
* Experience leading technical discussions with engineers, architects, auditors, and executive leadership.
Nice to have certifications:
CCP (Certified CMMC Professional)
CCA (Certified CMMC Assessor)
CISSP (Certified Information Systems Security Professional)
CISA (Certified Information Systems Auditor)
Microsoft Certified:
Azure Security Engineer Associate or Microsoft 365 Security Administrator Associate
* Job Type & Location
* This is a Contract position based out of Spring, TX.
* Pay and Benefits
* The pay range for this position is $60.00 - $70.00/hr.
Eligibility requirements apply to some benefits and may depend on your job
classification and length of employment. Benefits are subject to change and may be
subject to specific elections, plan, or program terms. If eligible, the benefits
available for this temporary role may…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).