
GRC Engineer, CMMC
Posted Aug 19

Posted Aug 19
This is a fully remote position, open to applicants in United States.
• Conduct analysis and implement NIST SP 800-53 controls along with FedRAMP Moderate and High baselines to ensure client software architectures meet federal agency standards.
• Create and revise System Security Plans (SSPs), narratives for control implementation, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).
• Carry out readiness assessments and gap analyses for validation paths related to JAB or Agency Authorization to Operate (ATO).
• Design technical authorization boundaries and scoping profiles within FedRAMP and CMMC environments.
• Diagram data flows, interconnectivity, and models of shared responsibilities.
• Manage continuous monitoring cycles, overseeing vulnerability management logs, incident response documentation, and change-control processes.
• Facilitate external assessment workflows among clients, Cloud Service Providers, Third Party Assessment Organizations (3PAOs), and federal stakeholders.
• Provide guidance to defense contractor clients regarding CMMC 2.0 and NIST SP 800-171 controls.
• Convert regulatory terminology into actionable security objectives.
• Develop compliance documentation necessary for readiness in CMMC Level 1 and Level 2 assessments.
• Support SaaS providers and federal contractors in navigating FedRAMP readiness, authorization assistance, and ongoing monitoring.
• Deliver high-quality outcomes across various client projects.
• At least 2 years of hands-on experience in Governance, Risk, and Compliance (GRC) roles, actively involved in driving FedRAMP, NIST SP 800-53, and federal authorization processes.
• Practical experience in authoring, assessing, and maintaining System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
• Solid understanding of CMMC 2.0 and NIST SP 800-171 baselines as they pertain to defense contractors and supply chain data.
• Knowledge of shared responsibility frameworks, operational limitations, and secure configurations for AWS GovCloud, Azure Government, or Microsoft GCC High.
• Strong project management abilities to support multiple concurrent client compliance projects.
• Experience collaborating with B2B SaaS providers, federal contractors, or regulated tech firms.
• Background in dynamic consulting or rapidly growing startup environments.
• Exceptional written and verbal communication skills in English.
• Dependable, high-speed internet access and a professional home office setup conducive to confidential discussions and uninterrupted teamwork.
• Availability to work from 8:00 AM to 5:00 PM US Eastern Time, with occasional flexibility.
• Willingness and capability to travel locally for sporadic onsite meetings, team events, or business activities.
• Participation in live video interviews with the camera on and identity verification during the recruitment and onboarding process is required.
• Successful completion of identity verification and background checks, as permitted by law.
• Must have authorization to work in the U.S. without the need for current or future visa sponsorship.
• Direct experience in executing JAB or Agency ATO processes.
• Possession of CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) credentials.
• Holding an active CISSP, CISM, or CompTIA Security+ certification.
• Thorough knowledge of Controlled Unclassified Information (CUI) protections, DFARS regulatory clauses, and SPRS submission procedures.
• Previous experience collaborating directly with 3PAO or C3PAO assessment teams.
• Clear career progression with mentorship and training opportunities.
• Reimbursement for successful completion of approved training and certification programs pertinent to the current position.
• Competitive base salary with regular performance evaluations tied to merit-based appraisals and bonus potential.
• Significant opportunities for professional advancement.
• A remote-first culture that allows flexibility to work from any location while engaging with a global team.
IGS Energy
RMI
Rightpoint
VikingCloud
Get handpicked remote jobs straight to your inbox weekly.