Agile IT logo

CMMC Compliance Consultant

Agile IT

Posted about 2 hours ago

Job Description

The CMMC Compliance Consultant is the subject matter expert who carries DIB clients through the full CMMC lifecycle. You own engagements end to end, from initial gap assessment through assessor-ready documentation, and you are the technical authority clients lean on when the requirements get hard.

This is practitioner-level work. You scope CUI environments, build the SSPs and POA&Ms an assessor will actually accept, and translate dense regulatory language into guidance a client can act on. You sit in pre-sales calls and executive readouts, you mentor the junior consultants coming up behind you, and you help sharpen the methodology the whole practice runs on. Active CCP and CCA credentials are non-negotiable for this role.

What You'll Own

Assessment and Advisory. Lead and execute CMMC Level 2 gap assessments against all 110 NIST SP 800-171 Rev 2 practices across the 14 control domains. Conduct readiness reviews and deliver findings with prioritized remediation roadmaps.

Assessor-Ready Documentation. Author and maintain SSPs, POA&Ms, policies, procedures, and implementation narratives using the NIST SP 800-171A examine, test, and interview methodology. Build CMMC-scoped network diagrams, data flow diagrams, and CUI boundary documentation.

CUI Environment Scoping. Evaluate client environments scoped to CUI systems, including Microsoft 365 GCC and GCC High, Intune and Microsoft Defender for Endpoint, and specialized platforms such as PreVeil.

Client Engagement. Serve as the primary technical point of contact for assigned DIB accounts across the compliance lifecycle. Facilitate interviews with client staff to validate controls and gather evidence, and present status and executive readouts with clarity.

GRC Platform Integrity. Own data integrity in the GRC platform (e.g., IntelliGRC) for SSP management, POA&M tracking, and evidence management.

Practice Development. Improve internal CMMC methodologies, templates, and tooling. Mentor junior consultants, and track CMMC Program rule changes (32 CFR Part 170, DFARS 252.204-7021) and Cyber AB guidance updates so the practice stays current.

Qualifications

Required

  • Active CMMC Certified Professional (CCP) credential in good standing with the Cyber AB
  • Active CMMC Certified Assessor (CCA) credential in good standing with the Cyber AB
  • Minimum 5 years of progressive IT experience, with at least 2 years focused on cybersecurity
  • Minimum 1 year of direct CMMC, DFARS 252.204-7012/7021, NIST SP 800-171, or other compliance consulting experience
  • Demonstrated expertise scoping CUI environments and applying NIST SP 800-171 Rev 2 across all 14 control families
  • Hands-on experience with Microsoft 365 Commercial, GCC, and/or GCC High environments in a CMMC compliance context
  • Working knowledge of Azure Sentinel, Microsoft Defender for Endpoint (MDE), and Intune within CMMC-scoped environments
  • Strong proficiency writing SSP implementation narratives, NIST 800-171A-aligned assessment procedures, and POA&M documentation
  • Familiarity with FedRAMP Moderate authorization requirements and cloud service provider boundary scoping
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a closely related field

Preferred

  • Experience with PreVeil, Lifeline, or other CUI-designated encrypted collaboration platforms
  • Experience supporting multi-site CMMC Level 2 assessments in manufacturing, defense electronics, or aerospace sectors
  • Prior experience as a C3PAO team member on an assessment
  • Experience with GRC platforms such as IntelliGRC or equivalent

 

Additional Information

Additional Information

  • Department: Compliance
  • Reports to the Lead CMMC Compliance Manager
  • Full-time, fully remote

Agile IT runs on its RISE values: Reliability, Integrity, Stewardship, and Excellence. We hire people who live them.

Job details

Workplace

Remote

Location

San Diego, CA, United States

Similar
Agile IT logo

Agile IT

IT Services and IT Consulting

About

Our Mission To empower organizations with secure, compliant, and modern IT solutions that reduce risk, accelerate growth, and enable lasting innovation. Agile IT is a leading provider of cloud, security, and compliance solutions, empowering organizations to modernize securely and efficiently. With deep expertise in Microsoft cloud technologies, cybersecurity, and compliance frameworks, we help businesses and government contractors navigate complex IT challenges while driving innovation and resilience. What We Do Cloud Transformation: Modernize IT infrastructure with secure, scalable Microsoft Azure, Microsoft 365, and hybrid cloud solutions. Cybersecurity & Zero Trust: Protect data and systems with advanced security, identity, and compliance architectures. CMMC, NIST & ITAR Compliance: Guide defense contractors and regulated industries through the complexities of CMMC 2.0, NIST SP 800-171, DFARS, ITAR, and other compliance mandates. Managed IT & Security Services: Provide support, monitoring, and proactive management to keep critical systems secure and available. Who We Serve Agile IT supports organizations of all sizes — from SMBs to enterprises and the U.S. Defense Industrial Base (DIB). We partner with commercial businesses, government contractors, and highly regulated industries that require secure, compliant, and efficient IT operations. Why Agile IT Microsoft Solutions Partner with advanced specializations in Security, Modern Work, and Infrastructure. Trusted by hundreds of organizations for over a decade. Recognized thought leader in cloud adoption, compliance, and cybersecurity. Focused on enabling digital transformation while maintaining compliance and protecting sensitive information.

Company Details

Employees
45
Industry
IT Services and IT Consulting
Headquarters
San Diego, CA
Founded
2006
Company location
4660 La Jolla Village Drive, Suite 500, San Diego, CA 92122, US
Specialties
Microsoft Consulting, Fixed Price IT Support, Office 365 Consulting, Office 365 Migration, Microsoft Office 365 Partner, Intune Management, Exchange Consulting, SharePoint Consulting, System Center Consulting, Azure Migration, Azure Security, Microsoft Teams, Cloud Managed Services, Zero Trust Security, CMMC, Defense Industrial Base, and Government Compliance

Key Team Members

Madhu Gogulapati, MBA, PMP

Madhu Gogulapati, MBA, PMP

Zeev Turchinsky

Zeev Turchinsky

John Gilham

John Gilham

Kevin O'Shea, CISSP, LCCA, PMP

Kevin O'Shea, CISSP, LCCA, PMP

Jobr Assistant extension

Get the extension →