freehire launches on Product Hunt on 26 August.

Follow →

GRC Engineer (CMMC)

Summary

Supports clients with cybersecurity and federal compliance, focusing on CMMC 2.0, NIST SP 800-171, FedRAMP, and related frameworks. Involves compliance engineering, documentation, assessments, and advisory work across SaaS, federal contractors, and cloud environments.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Engineer (CMMC) based in the United States.

This role offers the opportunity to help organizations strengthen cybersecurity and achieve demanding federal and defense compliance standards.
You will support clients across CMMC 2.0, NIST SP 800-171, NIST SP 800-53, and FedRAMP programs.
The position combines hands-on compliance engineering, technical documentation, readiness assessments, and client advisory work.
You will translate complex regulatory requirements into practical security actions and clear compliance roadmaps.
Working across SaaS providers, federal contractors, cloud environments, and independent assessment teams, you will manage multiple initiatives with significant client impact.
The environment is fast-paced and collaborative, with strong expectations for ownership, precision, and high-quality delivery.
This is an excellent opportunity for a GRC professional seeking to deepen expertise in federal and defense cybersecurity frameworks.

Accountabilities:

  • Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to assess client architectures against federal security requirements.
  • Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 requirements, translating regulatory expectations into practical and actionable security milestones.
  • Author, maintain, and evaluate key compliance and authorization artifacts, including System Security Plans (SSPs), control implementation narratives, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).
  • Conduct detailed readiness assessments and gap analyses to prepare clients for federal Authority to Operate (ATO), Joint Authorization Board (JAB), and CMMC assessment pathways.
  • Define and document technical authorization boundaries, data flows, interconnectivity, and shared-responsibility models across FedRAMP and CMMC environments.
  • Execute continuous monitoring activities, including vulnerability management tracking, incident response documentation, structural change workflows, and recurring compliance updates.
  • Coordinate external assessment activities between clients, Cloud Service Providers, 3PAOs, C3PAOs, and relevant federal stakeholders.
  • Develop structured compliance documentation and assessment-readiness materials for CMMC Level 1 and Level 2 engagements.
  • Manage multiple client compliance initiatives simultaneously while maintaining strong documentation quality, deadlines, and delivery standards.
  • Serve as a trusted client advisor, communicating complex security and compliance concepts clearly and helping stakeholders navigate evolving requirements.
  • Stay current with changes to federal cybersecurity frameworks, regulatory requirements, cloud security practices, and defense compliance standards.
  • Requirements:

    • 2+ years of direct experience in GRC, cybersecurity compliance, or related roles with hands-on exposure to FedRAMP, NIST SP 800-53, NIST SP 800-171, or federal authorization lifecycles.
    • Practical experience authoring, evaluating, and maintaining federal compliance artifacts, particularly SSPs and POA&Ms.
    • Foundational knowledge of CMMC 2.0 and NIST SP 800-171 requirements as they apply to defense contractors and Controlled Unclassified Information (CUI).
    • Familiarity with DFARS requirements and CUI protection practices is strongly valued.
    • Experience working with government cloud environments such as AWS GovCloud, Azure Government, or Microsoft GCC High.
    • Understanding of cloud shared-responsibility models, technical security boundaries, data flows, and secure configurations.
    • Experience supporting B2B SaaS providers, federal contractors, regulated technology organizations, or comparable clients.
    • Strong project management and organizational skills, with the ability to manage several fast-moving compliance initiatives while maintaining attention to detail.
    • Excellent written and verbal English communication skills, with confidence engaging directly with technical teams, clients, assessors, and other stakeholders.
    • Ability to translate complex regulatory and technical requirements into clear, actionable guidance.
    • Comfortable operating independently in a fast-growing consulting environment where priorities can evolve quickly and ownership is expected.
    • CMMC credentials such as Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) are advantageous.
    • Certifications such as CISSP, CISM, or CompTIA Security+ are a plus.
    • Direct experience supporting JAB or federal Agency ATO processes is highly valued.
    • Previous collaboration with 3PAO or C3PAO assessment teams is beneficial.
    • Must be authorized to work in the United States without current or future visa sponsorship.
    • Able to work a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time, with occasional flexibility as business needs require.
    • Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities.
    • Reliable high-speed internet and a professional home-office environment suitable for confidential client work and virtual collaboration.
    • Benefits:

      • Competitive base salary with regular performance reviews and merit-based appraisal opportunities.
      • Bonus opportunities based on performance.
      • Remote-first culture with the flexibility to work from anywhere in the United States.
      • Mentorship, training, and structured career development opportunities.
      • Reimbursement for approved role-related training and professional certification courses.
      • Opportunity to deepen expertise across CMMC, NIST, FedRAMP, and federal cybersecurity compliance.
      • Growth opportunities within a fast-paced, early-stage environment.
      • Collaborative culture with exposure to complex cybersecurity and compliance engagements.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available