Unapologetically Focused on the Microsoft Cloud! Security, Compliance, Office 365 Migrations, GCC High, CMMC, HIPAA, NI
CMMC Compliance Consultant
Location
California
Posted
9 days ago
Salary
$110K - $140K / year
Seniority
Senior
Job Description
CMMC Compliance Consultant
Agile IT
• Lead and execute CMMC Level 2 gap assessments against all 110 NIST SP 800-171 Rev 2 practices across the 14 control domains. • Conduct readiness reviews and deliver findings with prioritized remediation roadmaps. • Author and maintain SSPs, POA&Ms, policies, procedures, and implementation narratives using the NIST SP 800-171A examine, test, and interview methodology. • Build CMMC-scoped network diagrams, data flow diagrams, and CUI boundary documentation. • Evaluate client environments scoped to CUI systems, including Microsoft 365 GCC and GCC High, Intune and Microsoft Defender for Endpoint, and specialized platforms such as PreVeil. • Serve as the primary technical point of contact for assigned DIB accounts across the compliance lifecycle. • Facilitate interviews with client staff to validate controls and gather evidence, and present status and executive readouts with clarity. • Own data integrity in the GRC platform (e.g., IntelliGRC) for SSP management, POA&M tracking, and evidence management. • Improve internal CMMC methodologies, templates, and tooling. Mentor junior consultants, and track CMMC Program rule changes (32 CFR Part 170, DFARS 252.204-7021) and Cyber AB guidance updates so the practice stays current.
Job Requirements
- Active CMMC Certified Professional (CCP) credential in good standing with the Cyber AB
- Active CMMC Certified Assessor (CCA) credential in good standing with the Cyber AB
- Minimum 5 years of progressive IT experience, with at least 2 years focused on cybersecurity
- Minimum 1 year of direct CMMC, DFARS 252.204-7012/7021, NIST SP 800-171, or other compliance consulting experience
- Demonstrated expertise scoping CUI environments and applying NIST SP 800-171 Rev 2 across all 14 control families
- Hands-on experience with Microsoft 365 Commercial, GCC, and/or GCC High environments in a CMMC compliance context
- Working knowledge of Azure Sentinel, Microsoft Defender for Endpoint (MDE), and Intune within CMMC-scoped environments
- Strong proficiency writing SSP implementation narratives, NIST 800-171A-aligned assessment procedures, and POA&M documentation
- Familiarity with FedRAMP Moderate authorization requirements and cloud service provider boundary scoping
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a closely related field
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Risk and Compliance Team Lead
RWWARWWA is the Statutory Body regulating all greyhound, harness and thoroughbred racing in Western Australia.
• Lead the coordination and ongoing enhancement of RWWA’s enterprise risk management framework, ensuring risks are identified, assessed, monitored and reported in line with organisational risk appetite. • Partner with business areas to embed risk awareness and ownership into operational planning, decision making and change initiatives. • Support the identification and mitigation of strategic, operational, regulatory and reputational risks across the organisation. • Coordinate risk reporting, analysis and insights for senior management, committees and governance forums, escalating material risks where required. • Oversee the development and maintenance of risk registers, key risk indicators, control assurance processes and risk treatment plans. • Provide day‑to‑day leadership of the risk and compliance function, supporting specialist roles within the team.
• Research and verify carriers using multiple online platforms to ensure legitimacy and compliance with company standards. • Document our internal system to keep accurate records of carrier qualifications and compliance status. • Analyze data and make informed decisions regarding carrier approval and risk assessment. • Process requests efficiently in a fast-paced environment while maintaining accuracy and meeting established service levels. • Collaborate with internal teams to address and resolve any carrier compliance issues or discrepancies. • Prioritize and multitask effectively while handling a high volume of carrier approvals.
Senior Manager, Global Regulatory Strategy
Telix Pharmaceuticals LimitedDeveloping theranostics (nuclear medicine) for prostate, kidney, glioblastoma, haematologic cancers and rare diseases.
• Support the development and execution of regulatory strategies for assigned portfolio assets, ensuring alignment with program objectives and global regulatory requirements • Contribute to regulatory planning for new product development, global submissions, and lifecycle management activities across pipeline and commercial assets • Partner cross-functionally to help align regulatory strategies with clinical, CMC, and commercial plans • Maintain awareness of global regulatory frameworks (e.g., FDA, EMA, TGA, PMDA, CDE) and apply them to program-level strategy and execution • Identify regulatory risks and support development of mitigation plans in collaboration with senior regulatory leadership • Lead the preparation for Health Authority interactions and submissions, including preparation of briefing documents, dossiers and other documentation in alignment with regulatory requirements • Manage responses to Health Authority queries and support regulatory milestone deliverables • Ensure documentation and communications are complete, accurate, and aligned with agreed regulatory strategies • Serve as the regulatory lead on assigned R&D project teams and partner cross-functionally with Clinical, Quality, CMC, Commercial, non-clinical and regulatory functions • Provide input and recommendations on regulatory risks, opportunities, and implications across the global portfolio
Role Description An Australian healthcare business is searching for their next Compliance Specialist! This is a fully remote role requiring a work from home setup. - Manage the full contract lifecycle for NDIS services and commercial clients, ensuring contracts remain current and up to date. - Oversee employee documentation, manage purchase orders, and support the operations and finance areas. - Participate in the development of manuals, processes, and operational policies, as well as the optimisation of systems and projects. - Ensure compliance with health and safety policies, promoting a safe and efficient work environment. Primary Responsibilities - Manage the full lifecycle of contracts for NDIS participants and commercial clients, including preparation, filing, issuance, and renewals. - Coordinate with Plan Managers and Support Coordinators to ensure fund quarantining. - Monitor contract expiry dates and initiate renewals as required. Employee & Contractor Document Control - Coordinate onboarding documentation for all employees and contractors across both entities, ensuring all compliance requirements are met prior to commencement. - Maintain accurate personnel files and ensure all documents are verified, stored securely, and audit-ready. - Track and manage expiry of key compliance documents including NDIS Worker Screening, WWC Checks, First Aid, licences, visas, and insurances. - Monitor completion of inductions, mandatory training, and Code of Conduct acknowledgements. Report Review & Approval - Review and approve support worker progress reports and distribute to Support Coordinators. - Follow up with support workers to ensure reports are completed accurately and on time. Complaint Management - Record, classify, and follow up on complaints in line with NDIS requirements. - Maintain complete complaint and incident records ready for audit or review. Internal Audit & Document Tracking - Participate in internal compliance audits and maintain up-to-date records of findings and actions. - Support continuous improvement of documentation and compliance processes. Project Management & Systems - Support implementation and optimisation of new systems and projects across the organisation. WHS - Take reasonable steps to maintain personal and team safety and report hazards or incidents promptly. Qualifications - 1-2 years' experience in NDIS or aged care compliance (preferred). - Strong written English and ability to produce professional documents independently. - Highly organised with the ability to manage multiple compliance streams simultaneously. - Proactive, self-sufficient work style with strong follow-through. - Advanced Excel skills including compliance registers, reporting, and audit tracking. - Experience with LMS platforms such as Moodle (advantageous). - Comfortable working across dual-entity environments. - Confident communicating verbally with participants, workers, and team members. - Experience using NDIS Commission and Worker Screening portals (desirable). Requirements - Stable work-from-home setup (reliable internet, laptop/desktop, quiet workspace). - Strong written and verbal English communication skills. - Proactive attitude — able to follow up on open incidents, corrective actions, and compliance requirements without being prompted. Benefits - Full-time, work-from-home. - Long-term, stable opportunity with room for growth. - Professional, supportive team environment. - Training and support provided.



