CMMC/NIST Consultant, Analyst

Posted 3ds ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

CMMC / NIST Consultant supporting client cybersecurity projects and documentation in a remote consulting environment. Seeking mid-level practitioner for various tasks including SSP development, evidence collection, and remediation tracking.

Responsibilities:

  • Support client engagements related to CMMC readiness, implementation, and documentation
  • Develop, update, and maintain System Security Plans (SSPs)
  • Assist with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and related deliverables
  • Gather, organize, and review evidence supporting control implementation
  • Draft and refine control narratives, policies, procedures, and related compliance documentation
  • Identify gaps and support development of POA&Ms and remediation tracking
  • Work with client stakeholders to collect information, validate details, and keep deliverables moving
  • Contribute to readiness efforts tied to assessments, documentation, and ongoing compliance activities

Requirements:

  • 3-5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work
  • Hands-on experience with CMMC-related work (Required)
  • Experience working with SSPs, policies, procedures, evidence collection, and remediation documentation (Required)
  • Familiarity with NIST SP 800-171, NIST SP 800-53, and FedRAMP
  • Strong writing and documentation skills
  • Ability to work independently in a remote environment
  • Strong organization, follow-through, and professionalism in client-facing work
  • Comfort stepping into active projects and supporting delivery work with minimal hand-holding
  • Authorized to work in the U.S.
  • Able to pass a background check
  • Reliable high-speed internet and a secure remote work setup.

Benefits:

  • Strong writing, quality work, collaboration, sound judgment, and practical execution.