SonicJobs Logo
Left arrow iconBack to search

Certified CMMC Assessor

DigiFlight
Posted 5 months ago, valid for 11 days
Location

Columbia, MD, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Certified CMMC Assessor (CCA) leads formal CMMC assessments and supports readiness and pre-assessment advisory engagements while maintaining independence and objectivity.
  • Candidates must have 7–10 years of experience in cybersecurity, IT audit, risk management, and information security program management, with 3–5 years in a lead role.
  • The role requires strong judgment, decision-making authority, and deep expertise in control evaluation and evidence validation.
  • Familiarity with federal frameworks such as FedRAMP and DFARS is essential, along with experience assessing complex environments.
  • The position offers a competitive salary of $120,000 to $150,000 per year.

Duties and Responsibilities

The Certified CMMC Assessor (CCA) leads formal CMMC assessments and may also support readiness and pre-assessment advisory engagements, provided independence and objectivity are maintained. This role is responsible for assessment leadership, control evaluation, and final compliance determinations, while ensuring adherence to the CMMC Assessment Process (CAP).

Readiness & Pre-Assessment Advisory

  • Lead or support readiness reviews and mock assessments
  • Evaluate organizational preparedness for CMMC certification
  • Provide guidance on:
  • Certification boundary definition
  • Control implementation expectations
  • Policy and Procedure development and evaluation
  • Evidence sufficiency and documentation quality
  • Identifyrisks that mayimpactassessment outcomes
  • Ability to understand technical solutions to stratify controlimplantation


Minimum Experience

7–10 years of experience in:

  • Cybersecurity
  • IT audit or assessments
  • Risk management and compliance
  • Information security program management

3–5 years in a lead role involving:

  • Assessments, audits, or compliance programs
  • Decision-making authority over control evaluation


Required Skills

  • Experience working with or within3PAOs or accredited assessment bodies
  • Familiarity with federal frameworks such as:FedRAMP
  • DFARS 252.204-7012(Safeguarding) and DFARS 252.204-7021(CMMC Requirements) 
  • Experience assessing complex environments (cloud, hybrid, MSPs, enclaves)
  • Strong judgment and decision-making authority
  • Deepexpertisein control evaluation and evidence validation
  • Ability to assess ambiguous or partially implemented controls
  • Executive-level communication and stakeholder engagement
  • High ethical standards and professional integrity

Considerations

  • Must avoid conflicts of interestin accordance withapplicable CMMC ecosystem expectations



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.