We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and leading cybersecurity efforts to ensure compliance with the Cybersecurity Maturity Model Certification (CMMC) standards, focusing on protecting Controlled Unclassified Information (CUI) for organizations in the Defense Industrial Base (DIB).
Key Responsibilities
Design, implement, and monitor security controls aligned with CMMC requirements, including access controls, encryption, endpoint protection, and secure configurations.
Lead vulnerability assessments, scan remediation tracking, and continuous risk management across hybrid and cloud environments.
Support incident response, threat hunting, and forensic analysis for cybersecurity events.
Prepare for and facilitate CMMC assessments (self and third-party), maintain certification documentation (SSP, POA&M), and address audit findings.
Collaborate with compliance managers, legal/data protection officers, and operations teams to ensure continuous alignment with NIST SP 800-171/DFARS controls.
Oversee CMMC continuous monitoring programs and identify compliance gaps in workflows.
Provide security awareness training and promote a culture of cybersecurity vigilance across departments.
Required Skills
Deep understanding of CMMC 2.0 framework, NIST SP 800-171, and DFARS requirements.
Experience conducting technical assessments, vulnerability management, and implementing FedRAMP Moderate or equivalent systems for CUI.
Strong documentation skills for policies, procedures, and audit support.
Ability to communicate technical findings to both technical and non-technical stakeholders.
Knowledge of cloud (e.g., Azure, Microsoft 365) and on-premise security technologies.
Typical Qualifications
Bachelor's degree in Information Security, Computer Science, or a related field.
Professional certifications such as CISSP, CISM, GIAC, or CCA/CCP (CMMC-specific certifications preferred).
Experience supporting DoD compliance or federal contracts is highly valued.
Job Purpose
The role ensures a secure and compliant enclave for CUI, mitigates cybersecurity risks, leads compliance projects, and prepares for third-party assessments and audits under the evolving CMMC 2.0 regulations.
Numbers & Facts
Location
Los Angeles, CA (Remote)
Skills
Access Controlunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Scienceunmatched
Computer Securityunmatched
Cryptographyunmatched
Defense Federal Acquisition Regulations Supplement (DFARS)unmatched
Documentationunmatched
Endpoint Securityunmatched
Federal Contractsunmatched
Forensic Scienceunmatched
GIAC - Global Information Assurance Certificationunmatched
Huntingunmatched
Hybrid Cloudunmatched
Incident Responseunmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Maintain Complianceunmatched
Microsoft Windows Azureunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Risk Managementunmatched
Security Monitoringunmatched
Technical Analysisunmatched
Training/Teachingunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
United States Department of Defense (DoD)unmatched
Vulnerability Scannersunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.