Compliance Project Manager

M3 Technology Consultants

Fairfax (VA)

On-site

USD 80,000 - 115,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Very competitive compensation package
Annual paid training for continuing.
Collaborative team environment
Entrepreneurial work environment
Career growth with mentorship program
Health, dental, vision, sick and vacat
401(k) with generous employer match

Job summary

M3 Technology Consultants seeks a detail-oriented compliance professional to lead cybersecurity programs and client-ready documentation in Fairfax, VA. You will design and maintain programs aligned with CMMC Level 1 & 2, SOC 2, and NIST 800-171, while ensuring audit readiness and risk mitigation across cloud and on-prem environments.

You will collaborate with internal teams and clients, translate complex regulatory requirements into actionable guidance, and contribute to training, metrics, and

Qualifications

  • Bachelor’s degree in Information Security, IT, or related field (or equivalent experience).
  • Preferred certifications: CISA, CISSP, CMMC Certified Professional.

Responsibilities

  • Design, implement, and maintain compliance programs aligned with CMMC Level 1 & 2, SOC 2, NIST 800-171, and related frameworks for internal teams and clients.
  • Create and update audit ready documentation, including security policies, SOPs, SSPs, and standardized evidence templates.
  • Perform ongoing risk assessments, manage POA&Ms, and track remediation progress. Validate and support technical security implementations in Microsoft 365 and Intune, including RBAC, least privilege, and privileged access controls.
  • Work closely with internal teams and clients to ensure security configurations and workflows meet compliance requirements.
  • Collect, organize, and prepare audit evidence for internal reviews and external third party assessments.
  • Develop and deliver training on CUI handling, cybersecurity best practices, and secure use of Microsoft 365 and mobile devices.
  • Provide regular compliance updates, KPIs, and risk summaries to leadership and stakeholders.

Skills

Cybersecurity compliance
CMMC knowledge
NIST 800-171
SOC 2
Regulatory reporting

Education

Bachelor’s degree in Information Security

Tools

Microsoft 365
Intune
RBAC / least privilege

Job description

Job Details

Location: Headquarters - Fairfax, VA 22033

Position Type: Full Time

Education Level: 4 Year Degree

Salary Range: $80,000 - $115,000 per year

Job Category: Information Technology

Who are We?

M3 Technology Consultants is headquartered in Fairfax, VA, and was founded in 2003. We are a rapidly growing, dynamic company that has successfully built an industry reputation by providing our clients with unparalleled IT services to businesses across the Washington, D.C., and Denver, Colorado, areas. Our team of highly skilled IT professionals supports small and large businesses across numerous industries, providing comprehensive solutions for line of business applications, disaster recovery, physical server/network management, and network maintenance and management.

We foster an entrepreneurial work environment with a strong emphasis on customer service. And through empowering great employees, we have created a culture of dedicated, creative, dynamic, hardworking, and fun loving individuals.

What do we offer YOU?
  • Very competitive compensation package
  • Annual paid training for continuing education
  • Collaborative team environment
  • Entrepreneurial work environment
  • Career Growth with an active mentorship program to help guide your advancement as an IT Professional
  • Health, dental, vision, sick and vacation leave, cell phone reimbursement, gym membership, and more
  • 401(k) with a generous employer match
Who are YOU?

You are a detail oriented compliance professional with hands on experience managing cybersecurity and compliance frameworks such as CMMC (Level 1 & 2), NIST 800-171, and SOC 2. You’re comfortable designing and maintaining compliance programs, developing policies and procedures, and building audit ready documentation that supports both internal teams and client environments.

You bring practical technical knowledge to your compliance work, including supporting access and security controls within Microsoft 365 and Intune environments. You have experience performing risk assessments, identifying compliance gaps, tracking corrective actions through POA&Ms, and validating technical implementations such as RBAC, least privilege, MFA, Conditional Access, and device compliance. You understand how to prepare for audits, respond to assessor requests, and ensure evidence is accurate, organized, and complete.

You work collaboratively to deliver projects on time and within budget, and you’re comfortable coordinating with internal teams, clients, and external vendors to provide effective support services. You communicate clearly, support training and awareness initiatives, and can translate technical and regulatory requirements into actionable guidance, metrics, and reports that drive continuous improvement and strengthen the organization’s overall security posture.

Note: This position is full time, onsite in our headquarters office in Fairfax, VA, and requires U.S. Citizenship.

What does your day/week look like?
  • Design, implement, and maintain compliance programs aligned with CMMC Level 1 & 2, SOC 2, NIST 800-171, and related frameworks for internal teams and clients
  • Create and update audit ready documentation, including security policies, SOPs, SSPs, and standardized evidence templates
  • Perform ongoing risk assessments, identify compliance gaps, manage POA&Ms, and track remediation progress. Validate and support technical security implementations in Microsoft 365 and Intune, including RBAC, least privilege, and privileged access controls
  • Work closely with internal teams and clients to ensure security configurations and workflows meet compliance requirements
  • Collect, organize, and prepare audit evidence for internal reviews and external third party assessments
  • Develop and deliver training on CUI handling, cybersecurity best practices, and secure use of Microsoft 365 and mobile devices
  • Provide regular compliance updates, KPIs, and risk summaries to leadership and stakeholders.
Qualifications
Education
  • Bachelor’s degree in Information Security, IT, or related field (or equivalent experience).
  • Preferred certifications: CISA, CISSP, CMMC Certified Professional.
Technical Skills
  • Deep knowledge of CMMC Level 1 & 2, SOC 2, ISO 27001, NIST 800-171, and related cybersecurity compliance frameworks
  • Experience maintaining compliance across Microsoft 365 Commercial, GCC, and GCC High environments, including secure workflows
  • Hands on expertise with Microsoft 365 and Intune security controls (Conditional Access, MFA, DLP, device compliance, RBAC, least privilege, and PAM)
  • Ability to identify compliance and security gaps across cloud, endpoint, and on prem environments and recommend mitigations
  • Experience conducting risk assessments, managing POA&Ms, and tracking remediation progress and audit readiness
  • Strong technical documentation skills, including policies, SOPs, SSPs, configuration documentation, and audit evidence development
  • Proven ability to collect, organize, and present audit evidence for internal stakeholders and third party assessors (C3PAOs)
  • Skill in translating regulatory requirements into technical controls, user guidance, and leadership level compliance reporting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT and Security Manager
IT and Security Manager

Brightline Interactive • Ashburn (VA)

On-site
USD 120,000 - 190,000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
Cyber Security Compliance Engineer
Cyber Security Compliance Engineer

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Information Security Program Lead
Information Security Program Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
CMMC (Cybersecurity Maturity Model Certification) Consultant
CMMC (Cybersecurity Maturity Model Certification) Consultant

Tenacious Solutions, LLC • Arlington (VA)

Remote
USD 80,000 - 120,000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

Fortem Technologies • Lindon (UT)

On-site
USD 110,000 - 150,000
Implementation Specialist, CMMC
Implementation Specialist, CMMC

United States Digital Space LLC • United States

On-site
USD 85,000 - 120,000
Security Compliance Analyst III
Security Compliance Analyst III

Bridgehead IT • San Antonio (TX), Northern (KY)

Hybrid
USD 90,000 - 130,000
Security Compliance Analyst III
Security Compliance Analyst III

Bridgehead IT LLC • San Antonio (TX)

On-site
USD 90,000 - 135,000