GRC Engineer, CMMC

Posted Aug 19

This is a fully remote position, open to applicants in United States.

📋 Description

• Conduct analysis and implement NIST SP 800-53 controls along with FedRAMP Moderate and High baselines to ensure client software architectures meet federal agency standards.

• Create and revise System Security Plans (SSPs), narratives for control implementation, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).

• Carry out readiness assessments and gap analyses for validation paths related to JAB or Agency Authorization to Operate (ATO).

• Design technical authorization boundaries and scoping profiles within FedRAMP and CMMC environments.

• Diagram data flows, interconnectivity, and models of shared responsibilities.

• Manage continuous monitoring cycles, overseeing vulnerability management logs, incident response documentation, and change-control processes.

• Facilitate external assessment workflows among clients, Cloud Service Providers, Third Party Assessment Organizations (3PAOs), and federal stakeholders.

• Provide guidance to defense contractor clients regarding CMMC 2.0 and NIST SP 800-171 controls.

• Convert regulatory terminology into actionable security objectives.

• Develop compliance documentation necessary for readiness in CMMC Level 1 and Level 2 assessments.

• Support SaaS providers and federal contractors in navigating FedRAMP readiness, authorization assistance, and ongoing monitoring.

• Deliver high-quality outcomes across various client projects.


⛳️ Requirements

• At least 2 years of hands-on experience in Governance, Risk, and Compliance (GRC) roles, actively involved in driving FedRAMP, NIST SP 800-53, and federal authorization processes.

• Practical experience in authoring, assessing, and maintaining System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).

• Solid understanding of CMMC 2.0 and NIST SP 800-171 baselines as they pertain to defense contractors and supply chain data.

• Knowledge of shared responsibility frameworks, operational limitations, and secure configurations for AWS GovCloud, Azure Government, or Microsoft GCC High.

• Strong project management abilities to support multiple concurrent client compliance projects.

• Experience collaborating with B2B SaaS providers, federal contractors, or regulated tech firms.

• Background in dynamic consulting or rapidly growing startup environments.

• Exceptional written and verbal communication skills in English.

• Dependable, high-speed internet access and a professional home office setup conducive to confidential discussions and uninterrupted teamwork.

• Availability to work from 8:00 AM to 5:00 PM US Eastern Time, with occasional flexibility.

• Willingness and capability to travel locally for sporadic onsite meetings, team events, or business activities.

• Participation in live video interviews with the camera on and identity verification during the recruitment and onboarding process is required.

• Successful completion of identity verification and background checks, as permitted by law.

• Must have authorization to work in the U.S. without the need for current or future visa sponsorship.

• Direct experience in executing JAB or Agency ATO processes.

• Possession of CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) credentials.

• Holding an active CISSP, CISM, or CompTIA Security+ certification.

• Thorough knowledge of Controlled Unclassified Information (CUI) protections, DFARS regulatory clauses, and SPRS submission procedures.

• Previous experience collaborating directly with 3PAO or C3PAO assessment teams.


🏝️ Benefits

• Clear career progression with mentorship and training opportunities.

• Reimbursement for successful completion of approved training and certification programs pertinent to the current position.

• Competitive base salary with regular performance evaluations tied to merit-based appraisals and bonus potential.

• Significant opportunities for professional advancement.

• A remote-first culture that allows flexibility to work from any location while engaging with a global team.

People also viewed

IGS Energy22 hours ago

Regulatory Intern, Summer 2027

US flagOhio OnlyFull-timeCompliance$31.2k – $62.4k/year
ApplyView job
RMI22 hours ago

IT Governance, Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance$77.2k – $95.2k/year
ApplyView job
Rightpoint1 day ago

M365 Security, Governance Architect

US flagUnited States OnlyFull-timeCompliance
ApplyView job
VikingCloud1 day ago

PCI Compliance Specialist

US flagArizona, +2 more statesFull-timeCompliance$17 – $18/hour
ApplyView job
Gilead Sciences1 day ago

Manager, Regulatory Affairs

US flagUnited States OnlyFull-timeCompliance$133.2k – $172.4k/year
ApplyView job
EPIC Retirement Plan Services1 day ago

Compliance Specialist III – TPA, DPS

US flagAlabama, +18 more statesFull-timeCompliance$71.2k – $94.9k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers