CMMC Cybersecurity Lead Assessor

Location

United States

Posted

51 days ago

Salary

$155K - $165K / year

Seniority

Lead

No structured requirement data.

Job Description

CMMC Cybersecurity Lead Assessor

Kieri Solutions

Role Description As a Lead CMMC Cybersecurity Assessor (LCCA), you will serve as the senior authority responsible for directing and executing formal CMMC Level 2 assessments for organizations required to have the CMMC certification. In this role, you will lead assessment teams, validate compliance with Department of War (DoW/DoD) cybersecurity requirements, and make final determinations regarding certification readiness. You will oversee the full assessment lifecycle, including: - Scoping - Evidence review - Technical validation - Final reporting This position requires deep expertise in cybersecurity frameworks, strong leadership capabilities, and the ability to communicate complex findings clearly and objectively to both internal teams and client stakeholders. The LCCA plays a critical role in maintaining the integrity, consistency, and rigor of the CMMC assessment process while ensuring assessments align with: - 32 CFR Part 170 - The CMMC Assessment Process (CAP) - C3PAO Professional Code of Conduct - Kieri Solutions ethical standards Qualifications - Lead CMMC Certified Assessor (LCCA) certification required - Previous certification as a CMMC Certified Assessor (CCA) - Listed in the Cyber AB Marketplace as a LCCA - Active security clearance - 7+ years of hands-on IT or cybersecurity experience, including networking, servers, virtualization, cloud or hybrid environments, and user endpoints - Demonstrated experience with cybersecurity compliance frameworks such as: NIST SP 800-171, RMF, FedRAMP, ISO 27001, SOC, PCI - Strong ability to interpret technical and compliance requirements and evaluate control implementation objectively - Excellent analytical, technical writing, and documentation skills - Ability to lead complex assessment engagements and coordinate cross-functional technical teams - Strong attention to detail, time management, and ability to perform under structured assessment timelines - Team-oriented mindset with a commitment to collaboration and assessment integrity Requirements - Lead CMMC Certified Assessor (LCCA) certification required - Previous certification as a CMMC Certified Assessor (CCA) - Listed in the Cyber AB Marketplace as a LCCA - Active security clearance - 7+ years of hands-on IT or cybersecurity experience, including networking, servers, virtualization, cloud or hybrid environments, and user endpoints - Demonstrated experience with cybersecurity compliance frameworks such as: NIST SP 800-171, RMF, FedRAMP, ISO 27001, SOC, PCI - Strong ability to interpret technical and compliance requirements and evaluate control implementation objectively - Excellent analytical, technical writing, and documentation skills - Ability to lead complex assessment engagements and coordinate cross-functional technical teams - Strong attention to detail, time management, and ability to perform under structured assessment timelines - Team-oriented mindset with a commitment to collaboration and assessment integrity Benefits - Base Pay: $155,000-$165,000 - Remote Work & Flexible Schedule: Work from home full-time with the option to travel - Work-Life Balance: We prioritize work-life balance with flex-time policies and strictly limited overtime - Competitive Benefits: Enjoy benefits, including 401(k) match, health insurance, and more

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Engineer - Detection and Response

Carsales.com

Carsales.com, founded in 1997 in Melbourne, Australia, is a digital marketplace for buying and selling vehicles including cars, bikes, boats, caravans, and heav

Lead investigations and remediation efforts, champion AI and automation in SecOps, develop detection engineering and threat hunting capabilities, and operationalize threat intelligence to identify emerging threats across the attack surface.

Australia
n8n logo

Senior Product Security Engineer

n8n

Your low-code automation tool for connecting anything to everything.

Full TimeRemoteTeam 11-50Since 2019H1B No Sponsor

• Your main goal will be to strengthen n8n’s product and platform security by driving hands-on security work that helps engineering teams reduce risk, ship securely, and build a growing security practice from an early stage. • Vulnerability management and disclosure • Own day-to-day vulnerability intake and triage workflows, including the security inbox and bug bounty submissions. • Coordinate remediation with engineering teams and help track issues through to resolution with clear priorities and follow-through. • Support coordinated disclosures, GitHub Security Advisories, and researcher communication in a timely and structured way. • Security tooling and technical assessments • Operate and improve security tooling across the SDLC, including scanning, alert triage, and workflow tuning. • Run practical security assessments such as targeted reviews, validation of findings, and remediation tracking from internal or external testing. • Help improve visibility into product and platform risk through actionable findings, documentation, and technical recommendations. • Secure product development support • Partner with engineers to embed security into design, development, and release processes in pragmatic ways. • Support threat modeling, secure coding guidance, and lightweight security reviews across product and platform areas. • Create clear, useful documentation that helps teams understand risks and apply secure development practices. • Security operations and team foundations • Support the coordination of security incidents by helping with investigation, tracking, communication, and follow-up actions. • Contribute to playbooks, runbooks, and internal processes that improve security readiness over time. • Help shape how the security function works in practice as the team grows, together with the Head of Security and future hires.

Germany
Full TimeRemoteTeam 501-1,000H1B Sponsor

• Support development and documentation of physical security, technical security, life safety, and guard force program elements. • Assist with onsite risk assessments, gap analyses, security audits, and facility reviews at offices, retail branches, campuses, and data centers. • Help analyze security risks and prepare mitigation recommendations. • Participate in client meetings to gather information and understand requirements. • Build working relationships with client security teams, property management, and law enforcement under senior guidance. • Assist with preparing reports, executive summaries, presentations, and status updates. • Collect and organize security-related data to support program improvements. • Support internal and external security training activities. • Stay informed on emerging security technologies and industry trends.

Texas
Job Closed

• Provide expert-level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. • Develop, enhance, and maintain standard operating procedures (SOPs) to support assessment execution and implementation. • Conduct security assessments and hands-on testing, analyze results, document risks, and recommend appropriate countermeasures. • Identify, evaluate, and report on system vulnerabilities, threats, and security gaps. • Review and provide recommendations on program-level documentation, including: o Requirements specifications o System architecture and design documents o Test plans and security plans • Develop and document security evaluation test plans and procedures. • Support the development and implementation of information security policies, standards, and guidance. • Ensure compliance with applicable frameworks and regulations (e.g., FISMA, NIST, OMB). • Perform risk assessments, including analyzing threats, vulnerabilities, and potential impacts. • Coordinate with cross-functional teams and stakeholders to support security testing and program objectives. • Lead or participate in technical exchange meetings, documenting outcomes and action items. • Prepare and deliver briefings to leadership on project status, risks, and key findings. • Analyze and synthesize data from multiple sources to produce clear, actionable insights for both technical and non-technical audiences. • Provide oversight for the design, development, and implementation of security support systems. • Collaborate with stakeholders to map system functionality to security controls and compliance requirements.

Maryland