About Ace of Cloud: Ace of Cloud is a cybersecurity compliance and advisory firm supporting organizations across CMMC, FedRAMP, FISMA, GovRAMP, NIST SP 800-171, NIST SP 800-53, and related federal cybersecurity frameworks. Ace of Cloud is a C3PAO hiring a full-time CMMC Certified Assessor / Security Control Assessor to support active mock and formal C3PAO assessments. We currently have assessments on hand that require travel. Candidates must be willing and able to travel domestically and potentially internationally for mock and formal C3PAO assessments as needed.
We are looking for someone with real hands‑on assessment experience, not just certifications on paper.
Location: Herndon, VA / Hybrid Preferred / Remote Considered
Employment Type: Full-Time W-2
Role Overview
- Support active mock and formal C3PAO assessments
- Travel domestically and potentially internationally for assessments as required
- Work independently and with Ace of Cloud’s CMMC staff, LCCA, and QA team on assessment-related activities
- Review client evidence, documentation, policies, procedures, SSPs, POA&Ms, diagrams, and security artifacts
- Conduct stakeholder and control owner interviews
- Document clear assessment notes, observations, risks, and findings
- Communicate professionally with clients, technical teams, and internal leadership
- Support assessment planning, evidence review, scoping, and quality review activities
Required Qualifications
- Current CCP certification
- Current CCA certification
- Must be willing and able to travel domestically and potentially internationally for mock and formal C3PAO assessments
- Successfully completed Tier 3 background investigation, Public Trust suitability, Secret clearance investigation, or equivalent federal background investigation
- 5+ years of cybersecurity, compliance, audit, risk, or assessment experience
- Prior experience with one or more of the following: CMMC, FedRAMP, FISMA, RMF, NIST SP 800‑171, NIST SP 800‑53, GovRAMP / StateRAMP, DoD or federal cybersecurity assessments
- Strong written and verbal English communication skills
- Strong client-facing and interpersonal skills
- Ability to write clear assessment notes, observations, risks, and findings
Preferred Qualifications
- 7+ years of cybersecurity compliance, audit, risk, or assessment experience
- Experience working with C3PAOs, 3PAOs, RPOs, federal contractors, defense contractors, MSPs, MSSPs, or cloud service providers
- Experience with SSPs, POA&Ms, CUI, assessment scoping, control interviews, evidence reviews, security documentation, assessment workpapers
- Local to the DC Metro area and able to travel to Herndon, VA for meetings or occasional onsite work
Work Arrangement
- Hybrid preferred for candidates in the DC Metro area
- Remote candidates will be considered if highly qualified and able to work independently
- Must be available for client‑site travel, including domestic and potential international travel
- Must be able to travel to Herndon, VA and client sites as needed