CMMC & Information Security Compliance Manager

Hidonix Industries

Santa Monica (CA)

On-site

USD 140,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible PTO

Job summary

Hidonix seeks a CMMC & Information Security Compliance Manager to lead and sustain CMMC Level 2 and NIST SP 800-171 compliance at our Santa Monica site. You will translate requirements into practical controls, policies, and day-to-day processes, coordinating with IT, Engineering, and Legal to close gaps and maintain readiness.

You will own the SSP, POA&Ms, and evidence repository, prepare for assessments, and serve as primary contact for external assessors and DoD-aligned partners.

Qualifications

  • Demonstrated hands-on experience implementing or managing NIST SP 800-171 requirements.
  • Direct experience preparing an organization for CMMC Level 2 certification or assessment.
  • Strong knowledge of CUI protection and federal cybersecurity compliance requirements.
  • Experience developing or maintaining SSPs, POA&Ms, policies, procedures, control evidence, and assessment documentation.
  • Ability to interpret security requirements and translate them into actionable technical and operational controls.
  • Experience conducting compliance gap assessments and managing remediation efforts.
  • Strong project-management and organizational skills, with the ability to coordinate requirements across multiple departments.
  • Excellent written communication and documentation skills.
  • Ability to communicate technical and compliance requirements clearly to both technical and non-technical stakeholders.

Responsibilities

  • Lead and manage Hidonix’s CMMC Level 2 compliance and assessment-readiness program.
  • Own and maintain the CMMC Level 2 assessment scope, including identifying and classifying in-scope assets, systems, CUI environments, and applicable External Service Providers (ESPs).
  • Maintain and continuously update the organization’s System Security Plan (SSP) to reflect environment and implementation of security requirements.
  • Develop, manage, and track Plans of Action & Milestones (POA&Ms) and remediation activities through completion.
  • Conduct internal gap assessments, security control assessments, and readiness reviews against CMMC and NIST requirements.
  • Coordinate and conduct internal examination, interview, and test activities to verify security controls are implemented correctly.
  • Map security-control implementations and supporting evidence to CMMC Level 2 objectives.
  • Establish and maintain an assessment-ready evidence repository.
  • Establish and maintain processes for securely handling, storing, transmitting, and accessing CUI.
  • Develop and maintain cybersecurity policies, procedures, standards, and supporting documentation.
  • Partner with IT, Cybersecurity, Engineering to ensure controls are implemented and maintained.
  • Validate controls related to access control, MFA, audit logging, configuration management, vulnerability management, encryption, incident response, physical security, and network protection.
  • Coordinate with accountable control owners to address deficiencies and drive remediation.
  • Ensure employees understand their information-security and CMMC responsibilities.
  • Coordinate CMMC Level 2 self-assessments and C3PAO assessments and closeout activities.
  • Serve as primary compliance contact for external assessors and partners.
  • Assist with supplier, vendor, and third-party cybersecurity requirements.
  • Track changes to CMMC/NIST/DFARS and evaluate impact on the program.
  • Develop training and guidance for employees on CMMC and information security.
  • Support incident-response readiness and documentation.
  • Continuously monitor and reassess controls for effectiveness and readiness.
  • Maintain CMMC/NIST control implementation matrices and CUI inventories.

Skills

NIST SP 800-171
CMMC Level 2
Compliance management
Policy development
Documentation
Gap assessments
Project management
Written communication
Stakeholder communication

Job description

CMMC & Information Security Compliance Manager

Location: Santa Monica, CA

Employment Type: Full- Time, On-site

Salary: 140K Annually

PTO: Flexible

About Hidonix

Hidonix is a deep tech defense company developing advanced solutions across AI, spatial computing, robotics, and immersive technologies. As we continue expanding our work within the defense and government sectors, we are seeking an experienced CMMC Compliance Manager to lead and maintain our cybersecurity compliance program and ensure ongoing readiness for CMMC requirements.

About the Role

The CMMC Compliance Manager will be responsible for leading Hidonix’s CMMC compliance efforts, with a primary focus on CMMC Level 2 and NIST SP 800-171 requirements.

This is a hands-on role for someone who understands not only the regulatory framework, but also how to translate requirements into practical controls, policies, documentation, evidence, and day-to-day processes.

You will work closely with our IT Systems & Security Administrator , Engineering, Operations, Legal, and leadership teams to identify compliance gaps, coordinate remediation efforts, maintain required documentation, and prepare the organization for CMMC assessments.

Key Responsibilities
  • Lead and manage Hidonix’s CMMC Level 2 compliance and assessment-readiness program.
  • The CMMC & Information Security Compliance Manager serves as the owner and orchestrator of the Company’s CMMC compliance program. The role is not expected to personally implement every technical security control; rather, the Manager defines requirements, assigns and coordinates responsible control owners, validates implementation and evidence, tracks remediation, and ensures the organization remains assessment ready.
  • Own and maintain the CMMC Level 2 assessment scope, including identifying and classifying in-scope assets, systems, CUI environments, and applicable External Service Providers (ESPs).
  • Maintain and continuously update the organization’s System Security Plan (SSP) to accurately reflect the environment and implementation of security requirements.
  • Develop, manage, and track Plans of Action & Milestones (POA&Ms) and associated remediation activities through completion.
  • Conduct internal gap assessments, security control assessments, and readiness reviews against CMMC and NIST requirements.
  • Coordinate and conduct internal examine, interview, and test activities to verify that security controls are implemented correctly, operating as intended, and supported by appropriate evidence.
  • Map Hidonix’s security-control implementations and supporting evidence to applicable CMMC Level 2 assessment objectives.
  • Establish and maintain an assessment-ready evidence repository, including policies, procedures, system configurations, logs, diagrams, training records, technical evidence, and other required artifacts.
  • Establish and maintain processes for securely handling, storing, transmitting, and accessing Controlled Unclassified Information (CUI).
  • Develop, maintain, and continuously improve cybersecurity and compliance policies, procedures, standards, and supporting documentation.
  • Partner closely with IT, Cybersecurity, Engineering, and other relevant teams to ensure required security controls are properly implemented, documented, and maintained.
  • Validate technical controls related to access control, MFA, audit logging, configuration management, vulnerability management, encryption, incident response, physical security, and system/network protection.
  • Identify, assign, and coordinate with accountable control owners across the organization to address deficiencies and drive remediation through completion.
  • Ensure employees and control owners understand their assigned information-security and CMMC responsibilities, including applicable role-based requirements.
  • Coordinate CMMC Level 2 self-assessments and C3PAO certification assessments, including assessment preparation, evidence coordination, assessor support, remediation, and POA&M closeout activities.
  • Serve as a primary compliance point of contact for external assessors, consultants, and other CMMC/compliance partners as necessary.
  • Assist with supplier, vendor, and third-party cybersecurity compliance requirements where applicable.
  • Track changes to CMMC, NIST, DFARS, and other applicable federal cybersecurity requirements and evaluate their impact on Hidonix’s systems, policies, and compliance program.
  • Develop, coordinate, and provide CMMC and information-security compliance training and guidance to employees, including security-awareness and role-based training.
  • Support incident-response preparedness and compliance activities, including appropriate documentation, reporting processes, evidence preservation, and coordination with responsible teams.
  • Continuously monitor the organization’s compliance posture and periodically reassess security controls to ensure they remain effective, properly implemented, and assessment-ready.
  • Maintaining CMMC/NIST control implementation matrices identifying applicability, implementation status, responsible control owners, implementation methods, evidence, deficiencies, and remediation actions.
  • Develop and maintain CUI/FCI inventories and data-flow diagrams identifying where regulated information is received, created, processed, stored, transmitted, and accessed.
Required Qualifications
  • Demonstrated hands-on experience implementing or managing NIST SP 800-171 requirements.
  • Direct experience preparing an organization for CMMC Level 2 certification or assessment.
  • Strong knowledge of CUI protection and federal cybersecurity compliance requirements.
  • Experience developing or maintaining SSPs, POA&Ms, policies, procedures, control evidence, and assessment documentation.
  • Ability to interpret security requirements and translate them into actionable technical and operational controls.
  • Experience conducting compliance gap assessments and managing remediation efforts.
  • Strong project-management and organizational skills, with the ability to coordinate requirements across multiple departments.
  • Excellent written communication and documentation skills.
  • Ability to communicate technical and compliance requirements clearly to both technical and non-technical stakeholders.
Preferred Qualifications
  • Experience working with defense contractors or organizations within the Defense Industrial Base (DIB).
  • Familiarity with DFARS 252.204-7012, NIST SP 800-171A, and related DoD cybersecurity requirements.
  • Experience participating directly in CMMC readiness assessments, mock assessments, or formal assessments.
  • CMMC-related certification or training, such as CCP or CCA, is strongly preferred.
  • Experience with security frameworks such as NIST SP 800-53, ISO 27001, SOC 2, or similar frameworks.
  • Experience working in a technology, engineering, AI, robotics, aerospace, or defense environment.
Other Requirements
  • Must be comfortable with working on site
  • Must be commuting distance of Santa Monica, CA.
  • Must be a US Citizen or valid green card holder.
What Success Looks Like

The successful candidate will establish a sustainable CMMC compliance program in which controls are not simply documented but can be consistently demonstrated through technical implementation, operational processes, and supporting evidence.

You will help ensure Hidonix remains continuously assessment-ready and that CMMC requirements are incorporated into the way our teams handle systems, data, vendors, personnel, and CUI.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CMMC Compliance Manager – Level 2 Readiness
CMMC Compliance Manager – Level 2 Readiness

Hidonix Industries • Santa Monica (CA)

On-site
USD 140,000 - 150,000
Flexible PTO
Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
CMMC Compliance & IT Support Specialist
CMMC Compliance & IT Support Specialist

Fathom Robotics • Fort Worth (TX)

Hybrid
USD 41,000 - 55,000
CMMC Security Engineer
CMMC Security Engineer

Red Cup IT, Inc. • Los Angeles (CA)

On-site
USD 90,000 - 130,000
CMMC Security Engineer
CMMC Security Engineer

Red Cup IT, Inc. • United States

On-site
USD 90,000 - 120,000
CMMC (Cybersecurity Maturity Model Certification) Consultant
CMMC (Cybersecurity Maturity Model Certification) Consultant

Tenacious Solutions, LLC • Arlington (VA)

Remote
USD 80,000 - 120,000
CMMC Compliance & IT Support Specialist
CMMC Compliance & IT Support Specialist

Socket.dev • Fort Worth (TX)

Hybrid
USD 41,000 - 55,000
Hybrid work model
CMMC Program Manager
CMMC Program Manager

Balfour Beatty US • Falls Church (VA), Northern (KY)

Hybrid
USD 125,000 - 195,000
CMMC Program Assistant
CMMC Program Assistant

Emerson Construction Company, Inc • Temple (TX)

On-site
USD 45,000 - 65,000
IT Security and Systems Engineer
IT Security and Systems Engineer

SilencerCo, LLC • West Valley City (UT)

On-site
USD 120,000 - 180,000