it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

126 jobs found

Email me jobs like this
Refine Search
Current Search
cmmc assessment lead
Cybersecurity Network Engineer
Addison Group Grapeland, Texas
Job Description Job Description Role: Cybersecurity / Network Engineer Location: Houston, TX (Hybrid) Pay Range: $120,000 - $125,000 / year Benefits: This position is eligible for medical, dental, vision and 401(k) About the Role We are seeking a Cybersecurity / Network Engineer to take ownership of a growing enterprise network and help shape the organization's long-term infrastructure and security strategy. This role combines hands-on network engineering with cybersecurity oversight, making it an excellent opportunity for someone who enjoys building secure, scalable environments while proactively identifying opportunities for improvement. The ideal candidate has experience managing enterprise network infrastructure, strengthening security posture, and partnering with third-party security providers to protect business operations. This position is best suited for someone who takes initiative, thinks strategically, and is comfortable serving as the technical owner of a complex network environment. Primary Responsibilities Manage, maintain, and optimize enterprise network infrastructure across multiple locations. Design, implement, and support secure networking solutions including firewalls, VPNs, wireless networks, and SD-WAN connectivity. Administer and support Cisco Meraki and Fortinet network environments. Partner with third-party security vendors to monitor, investigate, and respond to cybersecurity events. Lead vulnerability remediation efforts and support ongoing risk reduction initiatives. Develop and enhance security policies, standards, and best practices to strengthen the organization's cybersecurity posture. Support compliance initiatives including NIST and CMMC frameworks. Perform regular security assessments, identify infrastructure risks, and recommend improvements. Administer core Microsoft infrastructure including Active Directory, DNS, DHCP, and Group Policy. Troubleshoot network, server, and infrastructure issues across both on-premises and cloud environments. Maintain accurate network diagrams, technical documentation, and system inventories. Provide Tier II/III infrastructure support and collaborate with internal teams on technology initiatives. Participate in infrastructure planning, capacity management, and continuous improvement efforts. Required Background 5+ years of experience in Network Engineering, Cybersecurity, or Infrastructure Engineering. Experience administering Cisco Meraki networking environments. Hands-on experience managing Fortinet/FortiGate firewalls. Strong understanding of enterprise networking including routing, switching, VPNs, wireless networking, and SD-WAN. Experience supporting Microsoft Active Directory, DNS, DHCP, and Group Policy. Knowledge of cybersecurity frameworks such as NIST and/or CMMC. Experience working through a cybersecurity incident, including investigation, remediation, and recovery efforts. Experience coordinating with third-party security vendors or managed security providers. Strong troubleshooting skills across network and infrastructure technologies. Skills & Qualifications Strong understanding of network architecture, cybersecurity principles, and infrastructure best practices. Ability to proactively identify risks and implement long-term technical improvements. Excellent problem-solving and analytical skills. Strong verbal and written communication skills. Ability to work independently while collaborating with cross-functional teams. Experience with VMware, SAN/NAS storage, or cloud infrastructure is a plus. Familiarity with endpoint security platforms, vulnerability management, SIEM solutions, or email security tools is preferred. Comfortable supporting multiple locations and occasional travel to local data center facilities as needed. Self-motivated with a strong sense of ownership and accountability. Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request. IND 005-009
09/24/2026
Full time
Job Description Job Description Role: Cybersecurity / Network Engineer Location: Houston, TX (Hybrid) Pay Range: $120,000 - $125,000 / year Benefits: This position is eligible for medical, dental, vision and 401(k) About the Role We are seeking a Cybersecurity / Network Engineer to take ownership of a growing enterprise network and help shape the organization's long-term infrastructure and security strategy. This role combines hands-on network engineering with cybersecurity oversight, making it an excellent opportunity for someone who enjoys building secure, scalable environments while proactively identifying opportunities for improvement. The ideal candidate has experience managing enterprise network infrastructure, strengthening security posture, and partnering with third-party security providers to protect business operations. This position is best suited for someone who takes initiative, thinks strategically, and is comfortable serving as the technical owner of a complex network environment. Primary Responsibilities Manage, maintain, and optimize enterprise network infrastructure across multiple locations. Design, implement, and support secure networking solutions including firewalls, VPNs, wireless networks, and SD-WAN connectivity. Administer and support Cisco Meraki and Fortinet network environments. Partner with third-party security vendors to monitor, investigate, and respond to cybersecurity events. Lead vulnerability remediation efforts and support ongoing risk reduction initiatives. Develop and enhance security policies, standards, and best practices to strengthen the organization's cybersecurity posture. Support compliance initiatives including NIST and CMMC frameworks. Perform regular security assessments, identify infrastructure risks, and recommend improvements. Administer core Microsoft infrastructure including Active Directory, DNS, DHCP, and Group Policy. Troubleshoot network, server, and infrastructure issues across both on-premises and cloud environments. Maintain accurate network diagrams, technical documentation, and system inventories. Provide Tier II/III infrastructure support and collaborate with internal teams on technology initiatives. Participate in infrastructure planning, capacity management, and continuous improvement efforts. Required Background 5+ years of experience in Network Engineering, Cybersecurity, or Infrastructure Engineering. Experience administering Cisco Meraki networking environments. Hands-on experience managing Fortinet/FortiGate firewalls. Strong understanding of enterprise networking including routing, switching, VPNs, wireless networking, and SD-WAN. Experience supporting Microsoft Active Directory, DNS, DHCP, and Group Policy. Knowledge of cybersecurity frameworks such as NIST and/or CMMC. Experience working through a cybersecurity incident, including investigation, remediation, and recovery efforts. Experience coordinating with third-party security vendors or managed security providers. Strong troubleshooting skills across network and infrastructure technologies. Skills & Qualifications Strong understanding of network architecture, cybersecurity principles, and infrastructure best practices. Ability to proactively identify risks and implement long-term technical improvements. Excellent problem-solving and analytical skills. Strong verbal and written communication skills. Ability to work independently while collaborating with cross-functional teams. Experience with VMware, SAN/NAS storage, or cloud infrastructure is a plus. Familiarity with endpoint security platforms, vulnerability management, SIEM solutions, or email security tools is preferred. Comfortable supporting multiple locations and occasional travel to local data center facilities as needed. Self-motivated with a strong sense of ownership and accountability. Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request. IND 005-009
Infrastructure Manager
Vaco LLC Live Oak, Texas
Manager, Infrastructure Location: San Antonio, TX Employment Type: Full-Time, Direct Hire Work Authorization: No sponsorship available Position Overview We are seeking an experienced Manager, Infrastructure to lead and support an enterprise IT infrastructure environment. This position will be responsible for the strategy, reliability, security, and day-to-day operation of core infrastructure while leading and developing a technical team. The ideal candidate is a strong people leader who remains technically hands-on and can serve as an escalation point for complex infrastructure issues. Key Responsibilities Lead and develop the infrastructure team while providing technical direction and mentorship. Oversee enterprise networking, servers, cloud platforms, virtualization, storage, and related infrastructure. Manage and support Microsoft technologies including Azure, Microsoft 365, Intune, and Entra ID. Support virtualized environments utilizing technologies such as VMware, Hyper-V, and Nutanix. Ensure infrastructure environments are secure, reliable, scalable, and highly available. Lead infrastructure upgrades, migrations, implementations, and modernization initiatives. Support disaster recovery, business continuity, incident response, and infrastructure security initiatives. Partner with security, application, and business teams on technology projects and organizational priorities. Identify opportunities to improve infrastructure through automation and scripting. Manage vendors, technology partners, licensing, and infrastructure-related services. Qualifications 8+ years of experience in infrastructure, systems, network engineering, or a related technology discipline. 3+ years of experience leading or managing technical teams. Strong knowledge of enterprise networking, systems, cloud, virtualization, and storage. Experience with Microsoft Azure and Microsoft 365 technologies. Experience with enterprise virtualization platforms. Strong understanding of networking concepts, firewalls, VPNs, and network security. Experience with infrastructure security, disaster recovery, and business continuity. Familiarity with automation or scripting technologies such as PowerShell or Python. Strong troubleshooting, communication, and leadership skills. Ability to remain technically engaged while managing and developing a team. Preferred Qualifications Experience working within security or compliance frameworks such as NIST, CMMC, or SOC 2. Experience with infrastructure automation and Microsoft Graph API. Relevant certifications such as CCNP, Azure Solutions Architect Expert, or similar advanced infrastructure/cloud certifications. Experience supporting large or complex enterprise environments. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
09/24/2026
Full time
Manager, Infrastructure Location: San Antonio, TX Employment Type: Full-Time, Direct Hire Work Authorization: No sponsorship available Position Overview We are seeking an experienced Manager, Infrastructure to lead and support an enterprise IT infrastructure environment. This position will be responsible for the strategy, reliability, security, and day-to-day operation of core infrastructure while leading and developing a technical team. The ideal candidate is a strong people leader who remains technically hands-on and can serve as an escalation point for complex infrastructure issues. Key Responsibilities Lead and develop the infrastructure team while providing technical direction and mentorship. Oversee enterprise networking, servers, cloud platforms, virtualization, storage, and related infrastructure. Manage and support Microsoft technologies including Azure, Microsoft 365, Intune, and Entra ID. Support virtualized environments utilizing technologies such as VMware, Hyper-V, and Nutanix. Ensure infrastructure environments are secure, reliable, scalable, and highly available. Lead infrastructure upgrades, migrations, implementations, and modernization initiatives. Support disaster recovery, business continuity, incident response, and infrastructure security initiatives. Partner with security, application, and business teams on technology projects and organizational priorities. Identify opportunities to improve infrastructure through automation and scripting. Manage vendors, technology partners, licensing, and infrastructure-related services. Qualifications 8+ years of experience in infrastructure, systems, network engineering, or a related technology discipline. 3+ years of experience leading or managing technical teams. Strong knowledge of enterprise networking, systems, cloud, virtualization, and storage. Experience with Microsoft Azure and Microsoft 365 technologies. Experience with enterprise virtualization platforms. Strong understanding of networking concepts, firewalls, VPNs, and network security. Experience with infrastructure security, disaster recovery, and business continuity. Familiarity with automation or scripting technologies such as PowerShell or Python. Strong troubleshooting, communication, and leadership skills. Ability to remain technically engaged while managing and developing a team. Preferred Qualifications Experience working within security or compliance frameworks such as NIST, CMMC, or SOC 2. Experience with infrastructure automation and Microsoft Graph API. Relevant certifications such as CCNP, Azure Solutions Architect Expert, or similar advanced infrastructure/cloud certifications. Experience supporting large or complex enterprise environments. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
Systems Security Engineer, Programs
Anduril Industries Costa Mesa, California
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM We're seeking a systems security engineer to will drive security engineering principles into design and integration with other systems internal and external to Anduril to ultimately secure our suite of advanced technologies including artificial intelligence systems, command and control platforms, aerospace vehicles, and long range sensors. The ideal candidate has a background in systems of systems, systems, electrical and/or software engineering with deep expertise in embedded systems security. They will perform in-depth security architecture assessments, identify and mitigate vulnerabilities and exploits, and work cross-functionally to bake security into Anduril products. ABOUT THE JOB WHAT YOU'LL DO This is not an ISSO or ISSM role. Own security end-to-end for assigned products-derive and decompose security requirements from customer needs and threat intelligence, design security architectures, and manage security through the full product lifecycle Implement security features and capabilities, develop and execute comprehensive security test strategies at multiple integration levels, and support major milestone deliveries (SRR, PDR, CDR, TRR, PRR) Brief security architectures and approaches to government customers and program leadership, translating complex security concepts for diverse audiences Collaborates and builds solutions with engineering teams to meet and exceed industry-standard security goals Collaborate with security assessment teams to assess Anduril's products and integrated components to uncover potential weaknesses Collaborate cross-functionally with engineering teams to translate architectural requirements into implementations, and coordinate with security teams on threat modeling, validation, and testing REQUIRED QUALIFICATIONS Experience in one or more of the following fields: Systems Security Engineering, Cybersecurity, Systems Engineering, Electrical Engineering, Software Engineering, Computer Engineering, Computer Science Familiarity with security-relevant features on embedded hardware / FPGAs (e.g., secure boot, key management, etc.) Previous work on security engineering and architecture for defense / national security systems and/or complex embedded commercial systems Ability to effectively brief and interact regularly with highly technical government customers Strong understanding of the "why" behind the product, systems, and security design A sincere commitment to a positive, inclusive, and collaborative culture Excellent verbal & written communication skills Currently possesses and is able to maintain at least a final active US Secret security clearance with SAP eligibility Must be able to obtain a Top Secret security clearance. PREFERRED QUALIFICATIONS Excels at the above listed Requirements Possesses and able to maintain a U.S. TS Security clearance with SCI and/or SAP eligibility Strong skills in one or more programming languages (e.g., Python, Rust, Go, C/C++). Experience assessing security of firmware, applications, network, IoT, or embedded systems Fluency in modern USG cyber methodologies, including Cyber Survivability guidance and related policy (JSIG, ICD 503, CSEIG, SSECG, NIST SP 800-160, Cyber T&E Guidebook, CMMC, etc.) Experience developing cyber documentation for USG customers Proven track record of excelling across the broader Systems Security Engineering domain, encompassing embedded Systems Engineering, Cybersecurity, Cyber Resiliency, Software Security Experience creating and integrating with system design documentation in MBSE tools Experience integrating with Software Assurance, Supply Chain Risk Management, Configuration Management, and System Test Experience executing the Anti-Tamper process and authoring associated documentation Experience with security testing on DoD systems (e.g. penetration testing, red teaming, vulnerability assessments) Experience working with unmanned aircraft Group 3 class and above Experience working with government or national security space systems US Salary Range $164,000-$194,000 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Protecting Yourself from Recruitment Scams Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information. To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates. Please always verify communications: Direct from Anduril: If you receive an email from one of our recruiters, it will only come from address. Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to . Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain before providing any personal information or clicking on links. What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to . Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts. Data Privacy To view Anduril's candidate data privacy policy, please visit By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
09/24/2026
Full time
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM We're seeking a systems security engineer to will drive security engineering principles into design and integration with other systems internal and external to Anduril to ultimately secure our suite of advanced technologies including artificial intelligence systems, command and control platforms, aerospace vehicles, and long range sensors. The ideal candidate has a background in systems of systems, systems, electrical and/or software engineering with deep expertise in embedded systems security. They will perform in-depth security architecture assessments, identify and mitigate vulnerabilities and exploits, and work cross-functionally to bake security into Anduril products. ABOUT THE JOB WHAT YOU'LL DO This is not an ISSO or ISSM role. Own security end-to-end for assigned products-derive and decompose security requirements from customer needs and threat intelligence, design security architectures, and manage security through the full product lifecycle Implement security features and capabilities, develop and execute comprehensive security test strategies at multiple integration levels, and support major milestone deliveries (SRR, PDR, CDR, TRR, PRR) Brief security architectures and approaches to government customers and program leadership, translating complex security concepts for diverse audiences Collaborates and builds solutions with engineering teams to meet and exceed industry-standard security goals Collaborate with security assessment teams to assess Anduril's products and integrated components to uncover potential weaknesses Collaborate cross-functionally with engineering teams to translate architectural requirements into implementations, and coordinate with security teams on threat modeling, validation, and testing REQUIRED QUALIFICATIONS Experience in one or more of the following fields: Systems Security Engineering, Cybersecurity, Systems Engineering, Electrical Engineering, Software Engineering, Computer Engineering, Computer Science Familiarity with security-relevant features on embedded hardware / FPGAs (e.g., secure boot, key management, etc.) Previous work on security engineering and architecture for defense / national security systems and/or complex embedded commercial systems Ability to effectively brief and interact regularly with highly technical government customers Strong understanding of the "why" behind the product, systems, and security design A sincere commitment to a positive, inclusive, and collaborative culture Excellent verbal & written communication skills Currently possesses and is able to maintain at least a final active US Secret security clearance with SAP eligibility Must be able to obtain a Top Secret security clearance. PREFERRED QUALIFICATIONS Excels at the above listed Requirements Possesses and able to maintain a U.S. TS Security clearance with SCI and/or SAP eligibility Strong skills in one or more programming languages (e.g., Python, Rust, Go, C/C++). Experience assessing security of firmware, applications, network, IoT, or embedded systems Fluency in modern USG cyber methodologies, including Cyber Survivability guidance and related policy (JSIG, ICD 503, CSEIG, SSECG, NIST SP 800-160, Cyber T&E Guidebook, CMMC, etc.) Experience developing cyber documentation for USG customers Proven track record of excelling across the broader Systems Security Engineering domain, encompassing embedded Systems Engineering, Cybersecurity, Cyber Resiliency, Software Security Experience creating and integrating with system design documentation in MBSE tools Experience integrating with Software Assurance, Supply Chain Risk Management, Configuration Management, and System Test Experience executing the Anti-Tamper process and authoring associated documentation Experience with security testing on DoD systems (e.g. penetration testing, red teaming, vulnerability assessments) Experience working with unmanned aircraft Group 3 class and above Experience working with government or national security space systems US Salary Range $164,000-$194,000 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: Benefits At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits. Protecting Yourself from Recruitment Scams Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information. To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates. Please always verify communications: Direct from Anduril: If you receive an email from one of our recruiters, it will only come from address. Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to . Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain before providing any personal information or clicking on links. What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to . Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts. Data Privacy To view Anduril's candidate data privacy policy, please visit By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
Network Security Engineer
EF Johnson Technologies Inc. Irving, Texas
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
09/24/2026
Full time
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
CMMC Assessment Lead
Paragone Solutions, Inc. Chattanooga, Tennessee
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Rockford, Illinois
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Akron, Ohio
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Jackson, Mississippi
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Fort Lauderdale, Florida
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Lincoln, Nebraska
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Santa Clara, California
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Saint Paul, Minnesota
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Jersey City, New Jersey
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Albany, Georgia
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Buffalo, New York
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Providence, Rhode Island
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Worcester, Massachusetts
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Everett, Washington
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Bismarck, North Dakota
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Boise, Idaho
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board