CMMC Continuous Compliance Analyst

Jobtailor

United States

On-site

USD 85,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in the United States is seeking a cybersecurity compliance professional to lead CMMC/NIST 800-171 alignment, evidence collection, and remediation coordination across IT and security teams. You will maintain SSPs, policies, and POA&Ms, and perform ongoing reviews to validate control effectiveness.

The role requires strong documentation, collaboration with stakeholders, and clear communication to support audit readiness and executive reporting.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or related field.
  • 3–6 years of experience in cybersecurity compliance, GRC, IT audit, security operations, infrastructure operations, or related technical security function.
  • Working knowledge of CMMC, NIST SP 800-171, or comparable cybersecurity compliance frameworks.
  • Ability to interpret security control requirements and translate them into practical validation activities, evidence collection, and remediation recommendations.
  • Understanding of core cybersecurity concepts including identity and access management, multifactor authentication, endpoint security, vulnerability management, logging, network security, asset management, backups, change management, and incident response.
  • Experience reviewing technical evidence and determining whether security controls are operating effectively.
  • Ability to collaborate with technical and business teams to investigate compliance gaps, coordinate remediation activities, and support audit readiness.
  • Strong analytical, organizational, documentation, and written communication skills with the ability to manage multiple priorities and deadlines.

Responsibilities

  • Review, maintain, and improve CMMC documentation, including the System Security Plan (SSP), policies, procedures, control narratives, evidence repositories, and Plans of Action and Milestones (POA&Ms).
  • Perform ongoing compliance reviews against CMMC and NIST SP 800-171 requirements, validating that documented controls align with actual technical and operational implementation.
  • Collect, organize, validate, and maintain compliance evidence from systems, logs, tickets, vulnerability reports, access reviews, training records, and other supporting sources to ensure audit readiness.
  • Partner with infrastructure, security, system owners, and business stakeholders to validate control implementation, identify compliance gaps, and support remediation efforts.
  • Track findings, POA&Ms, remediation activities, control exceptions, and risk acceptance decisions through resolution.
  • Review technical configurations and security tooling related to areas such as identity and access management, multifactor authentication, vulnerability management, endpoint protection, logging, configuration management, asset inventory, backups, incident response, and network security.
  • Support internal readiness assessments, external CMMC assessments, and continuous monitoring activities by maintaining accurate documentation and repeatable compliance processes.
  • Prepare compliance metrics, status reports, dashboards, and executive summaries that communicate compliance posture, audit readiness, remediation progress, and organizational risk.

Skills

GRC experience
Analytical skills
Documentation skills

Education

Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or related field

Job description

Responsibilities
  • Review, maintain, and improve CMMC documentation, including the System Security Plan (SSP), policies, procedures, control narratives, evidence repositories, and Plans of Action and Milestones (POA&Ms).
  • Perform ongoing compliance reviews against CMMC and NIST SP 800-171 requirements, validating that documented controls align with actual technical and operational implementation.
  • Collect, organize, validate, and maintain compliance evidence from systems, logs, tickets, vulnerability reports, access reviews, training records, and other supporting sources to ensure audit readiness.
  • Partner with infrastructure, security, system owners, and business stakeholders to validate control implementation, identify compliance gaps, and support remediation efforts.
  • Track findings, POA&Ms, remediation activities, control exceptions, and risk acceptance decisions through resolution.
  • Review technical configurations and security tooling related to areas such as identity and access management, multifactor authentication, vulnerability management, endpoint protection, logging, configuration management, asset inventory, backups, incident response, and network security.
  • Support internal readiness assessments, external CMMC assessments, and continuous monitoring activities by maintaining accurate documentation and repeatable compliance processes.
  • Prepare compliance metrics, status reports, dashboards, and executive summaries that communicate compliance posture, audit readiness, remediation progress, and organizational risk.
Requirements
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field, or an equivalent combination of education and experience.
  • Three to six years of experience supporting cybersecurity compliance, governance, risk and compliance (GRC), IT audit, security operations, infrastructure operations, or a related technical security function.
  • Working knowledge of CMMC, NIST SP 800-171, or comparable cybersecurity compliance frameworks.
  • Ability to interpret security control requirements and translate them into practical validation activities, evidence collection, and remediation recommendations.
  • Understanding of core cybersecurity concepts including identity and access management, multifactor authentication, endpoint security, vulnerability management, logging, network security, asset management, backups, change management, and incident response.
  • Experience reviewing technical evidence and determining whether security controls are operating effectively.
  • Ability to collaborate with technical and business teams to investigate compliance gaps, coordinate remediation activities, and support audit readiness.
  • Strong analytical, organizational, documentation, and written communication skills with the ability to manage multiple priorities and deadlines.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CMMC Program Assistant
CMMC Program Assistant

Emerson Construction Company, Inc • Temple (TX)

On-site
USD 45,000 - 65,000
CMMC Security Engineer
CMMC Security Engineer

Red Cup IT, Inc. • United States

On-site
USD 90,000 - 120,000
CMMC Security Engineer
CMMC Security Engineer

Red Cup IT, Inc. • Los Angeles (CA)

On-site
USD 90,000 - 130,000
Cyber Security Compliance Engineer
Cyber Security Compliance Engineer

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Senior Information Security Specialist
Senior Information Security Specialist

Insight Global • Horsham (PA)

On-site
USD 120,000 - 170,000
Cyber Security Engineer
Cyber Security Engineer

Daniels Manufacturing Corporation • Orlando (FL)

On-site
USD 80,000 - 110,000
Compliance Analyst
Compliance Analyst

Jobtailor • Austin (TX)

On-site
USD 85,000 - 120,000
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
IT and Security Manager
IT and Security Manager

brightline • Ashburn (VA)

On-site
USD 150,000 - 190,000
CMMC Compliance Lead
CMMC Compliance Lead

Brasfield & Gorrie, L.L.C. • Birmingham (AL)

Hybrid
USD 90,000 - 135,000