CMMC Compliance Manager

Quantum Leap Research

Leesburg (VA)

On-site

USD 150,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

6% 401(k) company match with immediate
Educational assistance up to $7,000/yr
100% insurance premium subsidy for emp

Job summary

Quantum Leap Research is seeking a CMMC Compliance Manager to own and lead the organization’s CMMC Level 2 readiness and NIST SP 800-171 compliance across the CUI enclave. You will develop documentation, coordinate controls with IT and security teams, and ensure continuous monitoring and readiness for audits and C3PAO assessments.

The role emphasizes governance, documentation, and end-to-end ownership of the compliance program, with responsibilities spanning policy updates, risk assessments, and

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent combination of education and experience).
  • A minimum of 5 years of experience in cybersecurity, information security governance, risk, and compliance (GRC), or IT audit.
  • A minimum of 3 years of hands-on experience implementing or managing compliance with NIST SP 800-171.
  • Experience leading or supporting CMMC Level 2 readiness, assessments, or certification efforts.
  • Experience coordinating security control implementation across infrastructure, IT, engineering, and security teams.
  • Excellent documentation, organizational, communication, and project management skills.

Responsibilities

  • Own the organization's CMMC compliance program and maintain ongoing assessment readiness.
  • Develop and maintain the System Security Plan (SSP), Plan of Action & Milestones (POA&M), policies, procedures, inventories, network diagrams, and other required compliance documentation.
  • Coordinate implementation and validation of NIST SP 800-171 security controls with infrastructure, systems, and security teams.
  • Manage continuous monitoring activities, including vulnerability management, patch compliance, audit log reviews, account reviews, configuration management, and risk assessments.
  • Collect and maintain assessment evidence and serve as the primary point of contact for internal audits and C3PAO assessments.
  • Track remediation activities, ensure deficiencies are resolved, and maintain compliance metrics and reporting for leadership.
  • Monitor changes to CMMC, DFARS, and related cybersecurity requirements and recommend updates to policies and technical controls as needed.

Skills

GRC experience
Cybersecurity
Documentation
Project management
Communication
NIST SP 800-171

Education

Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, or related field

Tools

NIST SP 800-171

Job description

Quantum Leap is the leading technology services company focused on providing operationally focused solutions for select clientele within the United States Government (USG). Quantum Leap was founded by a team of technologists and engineers to focus exclusively on advancing USG interests against the Nation’s threats in an age of Strategic (Great Power) Competition.

We have built a highly collaborative workforce dedicated to countering those threats in an environment designed for success. This an entrepreneurial, fast-growing company, where the right candidate can join and really make a difference.

The CMMC Compliance Manger will be responsible for owning and managing the organization's CMMC compliance program for our Controlled Unclassified Information (CUI) enclave. The position serves as the primary lead for implementing, documenting, monitoring, and continuously maintaining compliance with CMMC Level 2 and NIST SP 800-171 requirements. While the CUI environment is limited in scope, this individual will have end-to-end ownership of the compliance program, including governance, documentation, continuous monitoring, assessment readiness, and coordination of technical control implementation.

Responsibilities:

  • Own the organization's CMMC compliance program and maintain ongoing assessment readiness.
  • Develop and maintain the System Security Plan (SSP), Plan of Action & Milestones (POA&M), policies, procedures, inventories, network diagrams, and other required compliance documentation.
  • Coordinate implementation and validation of NIST SP 800-171 security controls with infrastructure, systems, and security teams.
  • Manage continuous monitoring activities, including vulnerability management, patch compliance, audit log reviews, account reviews, configuration management, and risk assessments.
  • Collect and maintain assessment evidence and serve as the primary point of contact for internal audits and C3PAO assessments.
  • Track remediation activities, ensure deficiencies are resolved, and maintain compliance metrics and reporting for leadership.
  • Monitor changes to CMMC, DFARS, and related cybersecurity requirements and recommend updates to policies and technical controls as needed.

Qualifications:

Required:

  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent combination of education and experience).
  • A minimum of 5 years of experience in cybersecurity, information security governance, risk, and compliance (GRC), or IT audit.
  • A minimum of 3 years of hands-on experience implementing or managing compliance with NIST SP 800-171.
  • Experience leading or supporting CMMC Level 2 readiness, assessments, or certification efforts.
  • Experience coordinating security control implementation across infrastructure, IT, engineering, and security teams.
  • Excellent documentation, organizational, communication, and project management skills.

Preferred:

  • Experience leading a successful C3PAO assessment.
  • Experience with NIST SP 800-172 or preparing for higher-assurance government environments.
  • Experience supporting federal contractors or DoD suppliers.
  • Experience with FedRAMP, NIST CSF, ISO 27001, SOC 2, or other security frameworks.

Compensation and Benefits:

We seek the best-and-brightest professionals at all levels so offer highly competitive compensation and an excellent benefits package.

Salary Range: $150,000 - $170,000. Salary ranges reflect compensation for qualified candidates across a range of experience levels and are flexible; actual salary will be determined based on demonstrated skills, experience, and performance.

Company-sponsored benefits include: 6% 401(k) company match with immediate vesting, educational assistance up to $7,000 per year, 100% insurance premium subsidy for employees (75% for dependents), Anthem medical, Guardian dental, life and disability coverage, 3 weeks’ vacation, 2 weeks sick leave, and 11 holidays.

Quantum Leap is an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CMMC Compliance Lead – NIST 800-171 & Level 2
CMMC Compliance Lead – NIST 800-171 & Level 2

Quantum Leap Research • Leesburg (VA)

On-site
USD 150,000 - 170,000
6% 401(k) company match with immediate
Educational assistance up to $7,000/yr
100% insurance premium subsidy for emp
Cybersecurity Administrator
Cybersecurity Administrator

QED Systems Inc • Virginia Beach (VA)

On-site
USD 55,000 - 76,000
Competitive benefits package
Employee Assistance Program
CMMC Security Engineer
CMMC Security Engineer

Red Cup IT, Inc. • Los Angeles (CA)

On-site
USD 90,000 - 130,000
CMMC Security Engineer
CMMC Security Engineer

Red Cup IT, Inc. • United States

On-site
USD 90,000 - 120,000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
Associate Director – Cybersecurity Compliance Lead – $140-185K Plus Bonus & Pension
Associate Director – Cybersecurity Compliance Lead – $140-185K Plus Bonus & Pension

ACCsurance, LLC • United States

On-site
USD 140,000 - 185,000
CMMC Program Manager
CMMC Program Manager

Balfour Beatty US • Falls Church (VA), Northern (KY)

Hybrid
USD 125,000 - 195,000
Medical, Dental, Vision and Life
Health Savings Account
401(k) with company match
+4
CMMC (Cybersecurity Maturity Model Certification) Consultant
CMMC (Cybersecurity Maturity Model Certification) Consultant

Tenacious Solutions, LLC • Arlington (VA)

Remote
USD 80,000 - 120,000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

Fortem Technologies • Lindon (UT)

On-site
USD 110,000 - 150,000
CMMC Program Assistant
CMMC Program Assistant

Emerson Construction Company, Inc • Temple (TX)

On-site
USD 45,000 - 65,000