it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

125 jobs found

Email me jobs like this
Refine Search
Current Search
itsm change manager
Senior Technical Infrastructure Project Manager: 26-00147
Platinum Resource Group Newport Beach, California
Job DescriptionJob Description SENIOR TECHNICAL INFRASTRUCTURE PROJECT MANAGER Location; Newport Beach, CA JOB DESCRIPTION As a Senior Technical Infrastructure Project Manager within the company's Infrastructure & Operations Tower, you'll lead the planning, execution, and delivery of complex infrastructure technology initiatives with a primary focus on End User Services (EUS) and Information Security & Operations, with secondary support for Network and working knowledge of Cloud and Compute initiatives. You will be embedded within the I&O Tower - one of the largest portfolios in the company's Technology - supporting infrastructure modernization, identity and access management, endpoint/user services, resiliency, service transition, and operational readiness outcomes aligned to enterprise technology priorities. This role requires more than traditional project coordination. We are looking for a consultative, technically fluent infrastructure PM who can facilitate technical working sessions, understand architecture and operational dependencies at a working level, ask probing and technically informed questions of engineers and architects, challenge assumptions, identify delivery gaps, and translate technical complexity into clear, executive-ready updates. The ideal candidate brings strong delivery experience across identity governance, IT service management, endpoint security, disaster recovery/business continuity, infrastructure readiness, cutover planning, and operational handoff. KEY RESPONSIBILITIES TECHNICAL INFRASTRUCTURE DELIVERY Lead delivery of complex, cross-functional infrastructure projects across End User Services and Information Security & Operations, with secondary support for Network and Cloud/Compute dependencies. Drive infrastructure modernization programs including Identity Governance & Administration (IGA) 2.0, EUS Global Expansion, User Access Management Automation, ITAM Optimization & Maturity, Service Design & Transition, Global DR Assessment, and broader DR/BC resilience initiatives. Develop and manage integrated project plans, technical workstream plans, milestones, dependencies, decision points, readiness criteria, and delivery risks across engineering, architecture, operations, security, and business stakeholders. Coordinate environment readiness, migration/cutover planning, change alignment, release coordination, validation activities, operational handoff, and service transition to ensure infrastructure solutions are production-ready and supportable. STAKEHOLDER & GOVERNANCE MANAGEMENT Lead and influence stakeholders across engineering, architecture, operations, cybersecurity, service management, and business teams while balancing global standards with regional needs in a matrixed operating model. Serve as a liaison between Technology, Re, Corporate Functions, vendors, and delivery partners; build strong relationships with project sponsors and technical leaders to support timely decisions and delivery alignment. Manage scope, schedule, budget, resources, risks, issues, dependencies, assumptions, decisions, and change impacts; escalate barriers early and facilitate governance forums, project reviews, and steering committee discussions. Translate technical status, risks, readiness gaps, and delivery tradeoffs into clear project communications, executive summaries, KPIs, Power BI dashboards, and management committee updates. RISK, READINESS, CHANGE & OPERATIONAL HANDOFF Drive infrastructure readiness planning, including technical prerequisites, operational acceptance criteria, support model alignment, service transition, runbook readiness, knowledge transfer, and production support handoff. Partner with change, release, service management, cybersecurity, and operations teams to ensure technical changes are sequenced, communicated, approved, validated, and transitioned effectively. Identify delivery process improvements, coach project team members on strong delivery discipline, and help raise the quality of planning, reporting, risk management, and execution across the Infrastructure Tower. QUALIFICATIONS CORE PROJECT MANAGEMENT COMPETENCIES 7-10+ years of progressive experience in project/program management, including demonstrated delivery of enterprise infrastructure and technology projects (Waterfall, Agile, and hybrid delivery models). Proven success managing $1M-$5M+ infrastructure programs with budgets, timelines, and cross-functional dependencies spanning 12-24 months. Strong understanding of Agile principles and practices, with the ability to coach teams on Agile adoption, Scrum, Kanban, and continuous improvement. Demonstrated experience applying multi-modal delivery (incremental waterfall, hybrid, agile) in enterprise technology environments. INFRASTRUCTURE DOMAIN KNOWLEDGE The ideal candidate brings strong depth in End User Services and Information Security & Operations, with working knowledge of Network and Cloud/Compute environments. Demonstrated project experience in two or more of the following areas is required: End User Services (PRIMARY FOCUS) Service / Technology AreaRelevant Delivery ScopeExample Transition Technologies Identity & Access Management Services Identity lifecycle management, access certification, privileged access, role-based provisioning, customer identity, and enterprise directory , Delinea, Okta, Microsoft Entra End User Services Delivery Global end-user service operations, regional onboarding, service desk enablement, incident/change alignment, endpoint support, and user experience improvements.ServiceNow, Microsoft Intune, Microsoft 365, Teams User Access & Workflow Automation Automation of access requests, application provisioning, onboarding/offboarding workflows, intelligent routing, self-service enablement, and shift-left support models.ServiceNow workflows, Moveworks, IVR AI, automation platforms IT Asset & Configuration Management Software and hardware asset lifecycle management, license optimization, CMDB data quality, business application mapping, dependency tracking, and configuration governance.ServiceNow ITAM, ServiceNow CMDB, discovery/mapping tools Directory & Collaboration Platform Modernization Directory consolidation, group and account migration, policy impacts, collaborationActive Directory, Microsoft Entra ID, Microsoft 365, Teams platform readiness, and related service transition activities. Information Security & Operations (PRIMARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Disaster Recovery & Business Continuity Services DR/BC capability assessments, application recovery planning, resiliency modernization, test strategy, business ownership alignment, and recovery readiness governance.Cloud-enabled DR platforms, backup/recovery tools, resiliency reporting dashboards Service Design & Operational Transition ITIL-aligned service design, production readiness, support model definition, operational acceptance criteria, runbook readiness, knowledge transfer, and handoff to ITSM/ITOM/CMDB, knowledge management, operational runbook tools Endpoint Security & Protection Services Endpoint detection and response, device protection, application control, cyber agent compliance, endpoint hardening, and operational controls for managed devices.Microsoft Defender, EDR/XDR platforms, endpoint management agents Vulnerability, Patch & Compliance Operations Operating system and third-party patching, compliance tracking, remediation coordination, vulnerability reduction, audit readiness, and control evidence support.Qualys/Tenable, Tanium, SCCM/Intune, ServiceNow vulnerability workflows Monitoring, Incident & Stability Management Proactive monitoring, alerting, root cause analysis, major incident reduction, operational stability improvements, and service health reporting. Splunk, Nexthink, ServiceNow ITOM, monitoring and observability platforms Network (SECONDARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Network Infrastructure for Workplace & Location Services Planning and delivery of network connectivity, switching, wireless, voice/video readiness, circuit coordination, and infrastructure support for office builds, return-to-office needs, and location expansions.Cisco networking, wireless platforms, LAN/WAN circuits, collaboration network services Enterprise WAN & Cloud Connectivity Modernization Modernization of global WAN connectivity, routing, segmentation, VPN access, cloud connectivity, failover design, and network readiness to support cloud-first and hybrid infrastructure operating models.SD-WAN, MPLS, VPN, cloud WAN, Azure/AWS connectivity, ExpressRoute/Direct Connect SOFT SKILLS & CONSULTING MINDSET Consultative mindset: strong problem-solving abilities, sound judgment, and the ability to identify practical solutions, evaluate alternatives, and recommend clear delivery paths. Prior experience with a Big Four or major consulting firm is preferred. Executive communication: excellent interpersonal skills, poise, diplomacy, and the ability to influence stakeholders toward consensus, manage conflict, and support timely decision-making. Delivery ownership: self-starter who is highly organized . click apply for full job details
09/22/2026
Full time
Job DescriptionJob Description SENIOR TECHNICAL INFRASTRUCTURE PROJECT MANAGER Location; Newport Beach, CA JOB DESCRIPTION As a Senior Technical Infrastructure Project Manager within the company's Infrastructure & Operations Tower, you'll lead the planning, execution, and delivery of complex infrastructure technology initiatives with a primary focus on End User Services (EUS) and Information Security & Operations, with secondary support for Network and working knowledge of Cloud and Compute initiatives. You will be embedded within the I&O Tower - one of the largest portfolios in the company's Technology - supporting infrastructure modernization, identity and access management, endpoint/user services, resiliency, service transition, and operational readiness outcomes aligned to enterprise technology priorities. This role requires more than traditional project coordination. We are looking for a consultative, technically fluent infrastructure PM who can facilitate technical working sessions, understand architecture and operational dependencies at a working level, ask probing and technically informed questions of engineers and architects, challenge assumptions, identify delivery gaps, and translate technical complexity into clear, executive-ready updates. The ideal candidate brings strong delivery experience across identity governance, IT service management, endpoint security, disaster recovery/business continuity, infrastructure readiness, cutover planning, and operational handoff. KEY RESPONSIBILITIES TECHNICAL INFRASTRUCTURE DELIVERY Lead delivery of complex, cross-functional infrastructure projects across End User Services and Information Security & Operations, with secondary support for Network and Cloud/Compute dependencies. Drive infrastructure modernization programs including Identity Governance & Administration (IGA) 2.0, EUS Global Expansion, User Access Management Automation, ITAM Optimization & Maturity, Service Design & Transition, Global DR Assessment, and broader DR/BC resilience initiatives. Develop and manage integrated project plans, technical workstream plans, milestones, dependencies, decision points, readiness criteria, and delivery risks across engineering, architecture, operations, security, and business stakeholders. Coordinate environment readiness, migration/cutover planning, change alignment, release coordination, validation activities, operational handoff, and service transition to ensure infrastructure solutions are production-ready and supportable. STAKEHOLDER & GOVERNANCE MANAGEMENT Lead and influence stakeholders across engineering, architecture, operations, cybersecurity, service management, and business teams while balancing global standards with regional needs in a matrixed operating model. Serve as a liaison between Technology, Re, Corporate Functions, vendors, and delivery partners; build strong relationships with project sponsors and technical leaders to support timely decisions and delivery alignment. Manage scope, schedule, budget, resources, risks, issues, dependencies, assumptions, decisions, and change impacts; escalate barriers early and facilitate governance forums, project reviews, and steering committee discussions. Translate technical status, risks, readiness gaps, and delivery tradeoffs into clear project communications, executive summaries, KPIs, Power BI dashboards, and management committee updates. RISK, READINESS, CHANGE & OPERATIONAL HANDOFF Drive infrastructure readiness planning, including technical prerequisites, operational acceptance criteria, support model alignment, service transition, runbook readiness, knowledge transfer, and production support handoff. Partner with change, release, service management, cybersecurity, and operations teams to ensure technical changes are sequenced, communicated, approved, validated, and transitioned effectively. Identify delivery process improvements, coach project team members on strong delivery discipline, and help raise the quality of planning, reporting, risk management, and execution across the Infrastructure Tower. QUALIFICATIONS CORE PROJECT MANAGEMENT COMPETENCIES 7-10+ years of progressive experience in project/program management, including demonstrated delivery of enterprise infrastructure and technology projects (Waterfall, Agile, and hybrid delivery models). Proven success managing $1M-$5M+ infrastructure programs with budgets, timelines, and cross-functional dependencies spanning 12-24 months. Strong understanding of Agile principles and practices, with the ability to coach teams on Agile adoption, Scrum, Kanban, and continuous improvement. Demonstrated experience applying multi-modal delivery (incremental waterfall, hybrid, agile) in enterprise technology environments. INFRASTRUCTURE DOMAIN KNOWLEDGE The ideal candidate brings strong depth in End User Services and Information Security & Operations, with working knowledge of Network and Cloud/Compute environments. Demonstrated project experience in two or more of the following areas is required: End User Services (PRIMARY FOCUS) Service / Technology AreaRelevant Delivery ScopeExample Transition Technologies Identity & Access Management Services Identity lifecycle management, access certification, privileged access, role-based provisioning, customer identity, and enterprise directory , Delinea, Okta, Microsoft Entra End User Services Delivery Global end-user service operations, regional onboarding, service desk enablement, incident/change alignment, endpoint support, and user experience improvements.ServiceNow, Microsoft Intune, Microsoft 365, Teams User Access & Workflow Automation Automation of access requests, application provisioning, onboarding/offboarding workflows, intelligent routing, self-service enablement, and shift-left support models.ServiceNow workflows, Moveworks, IVR AI, automation platforms IT Asset & Configuration Management Software and hardware asset lifecycle management, license optimization, CMDB data quality, business application mapping, dependency tracking, and configuration governance.ServiceNow ITAM, ServiceNow CMDB, discovery/mapping tools Directory & Collaboration Platform Modernization Directory consolidation, group and account migration, policy impacts, collaborationActive Directory, Microsoft Entra ID, Microsoft 365, Teams platform readiness, and related service transition activities. Information Security & Operations (PRIMARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Disaster Recovery & Business Continuity Services DR/BC capability assessments, application recovery planning, resiliency modernization, test strategy, business ownership alignment, and recovery readiness governance.Cloud-enabled DR platforms, backup/recovery tools, resiliency reporting dashboards Service Design & Operational Transition ITIL-aligned service design, production readiness, support model definition, operational acceptance criteria, runbook readiness, knowledge transfer, and handoff to ITSM/ITOM/CMDB, knowledge management, operational runbook tools Endpoint Security & Protection Services Endpoint detection and response, device protection, application control, cyber agent compliance, endpoint hardening, and operational controls for managed devices.Microsoft Defender, EDR/XDR platforms, endpoint management agents Vulnerability, Patch & Compliance Operations Operating system and third-party patching, compliance tracking, remediation coordination, vulnerability reduction, audit readiness, and control evidence support.Qualys/Tenable, Tanium, SCCM/Intune, ServiceNow vulnerability workflows Monitoring, Incident & Stability Management Proactive monitoring, alerting, root cause analysis, major incident reduction, operational stability improvements, and service health reporting. Splunk, Nexthink, ServiceNow ITOM, monitoring and observability platforms Network (SECONDARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Network Infrastructure for Workplace & Location Services Planning and delivery of network connectivity, switching, wireless, voice/video readiness, circuit coordination, and infrastructure support for office builds, return-to-office needs, and location expansions.Cisco networking, wireless platforms, LAN/WAN circuits, collaboration network services Enterprise WAN & Cloud Connectivity Modernization Modernization of global WAN connectivity, routing, segmentation, VPN access, cloud connectivity, failover design, and network readiness to support cloud-first and hybrid infrastructure operating models.SD-WAN, MPLS, VPN, cloud WAN, Azure/AWS connectivity, ExpressRoute/Direct Connect SOFT SKILLS & CONSULTING MINDSET Consultative mindset: strong problem-solving abilities, sound judgment, and the ability to identify practical solutions, evaluate alternatives, and recommend clear delivery paths. Prior experience with a Big Four or major consulting firm is preferred. Executive communication: excellent interpersonal skills, poise, diplomacy, and the ability to influence stakeholders toward consensus, manage conflict, and support timely decision-making. Delivery ownership: self-starter who is highly organized . click apply for full job details
Senior Technical Infrastructure Project Manager: 26-00147
Platinum Resource Group Irvine, California
Job DescriptionJob Description SENIOR TECHNICAL INFRASTRUCTURE PROJECT MANAGER Location; Newport Beach, CA JOB DESCRIPTION As a Senior Technical Infrastructure Project Manager within the company's Infrastructure & Operations Tower, you'll lead the planning, execution, and delivery of complex infrastructure technology initiatives with a primary focus on End User Services (EUS) and Information Security & Operations, with secondary support for Network and working knowledge of Cloud and Compute initiatives. You will be embedded within the I&O Tower - one of the largest portfolios in the company's Technology - supporting infrastructure modernization, identity and access management, endpoint/user services, resiliency, service transition, and operational readiness outcomes aligned to enterprise technology priorities. This role requires more than traditional project coordination. We are looking for a consultative, technically fluent infrastructure PM who can facilitate technical working sessions, understand architecture and operational dependencies at a working level, ask probing and technically informed questions of engineers and architects, challenge assumptions, identify delivery gaps, and translate technical complexity into clear, executive-ready updates. The ideal candidate brings strong delivery experience across identity governance, IT service management, endpoint security, disaster recovery/business continuity, infrastructure readiness, cutover planning, and operational handoff. KEY RESPONSIBILITIES TECHNICAL INFRASTRUCTURE DELIVERY Lead delivery of complex, cross-functional infrastructure projects across End User Services and Information Security & Operations, with secondary support for Network and Cloud/Compute dependencies. Drive infrastructure modernization programs including Identity Governance & Administration (IGA) 2.0, EUS Global Expansion, User Access Management Automation, ITAM Optimization & Maturity, Service Design & Transition, Global DR Assessment, and broader DR/BC resilience initiatives. Develop and manage integrated project plans, technical workstream plans, milestones, dependencies, decision points, readiness criteria, and delivery risks across engineering, architecture, operations, security, and business stakeholders. Coordinate environment readiness, migration/cutover planning, change alignment, release coordination, validation activities, operational handoff, and service transition to ensure infrastructure solutions are production-ready and supportable. STAKEHOLDER & GOVERNANCE MANAGEMENT Lead and influence stakeholders across engineering, architecture, operations, cybersecurity, service management, and business teams while balancing global standards with regional needs in a matrixed operating model. Serve as a liaison between Technology, Re, Corporate Functions, vendors, and delivery partners; build strong relationships with project sponsors and technical leaders to support timely decisions and delivery alignment. Manage scope, schedule, budget, resources, risks, issues, dependencies, assumptions, decisions, and change impacts; escalate barriers early and facilitate governance forums, project reviews, and steering committee discussions. Translate technical status, risks, readiness gaps, and delivery tradeoffs into clear project communications, executive summaries, KPIs, Power BI dashboards, and management committee updates. RISK, READINESS, CHANGE & OPERATIONAL HANDOFF Drive infrastructure readiness planning, including technical prerequisites, operational acceptance criteria, support model alignment, service transition, runbook readiness, knowledge transfer, and production support handoff. Partner with change, release, service management, cybersecurity, and operations teams to ensure technical changes are sequenced, communicated, approved, validated, and transitioned effectively. Identify delivery process improvements, coach project team members on strong delivery discipline, and help raise the quality of planning, reporting, risk management, and execution across the Infrastructure Tower. QUALIFICATIONS CORE PROJECT MANAGEMENT COMPETENCIES 7-10+ years of progressive experience in project/program management, including demonstrated delivery of enterprise infrastructure and technology projects (Waterfall, Agile, and hybrid delivery models). Proven success managing $1M-$5M+ infrastructure programs with budgets, timelines, and cross-functional dependencies spanning 12-24 months. Strong understanding of Agile principles and practices, with the ability to coach teams on Agile adoption, Scrum, Kanban, and continuous improvement. Demonstrated experience applying multi-modal delivery (incremental waterfall, hybrid, agile) in enterprise technology environments. INFRASTRUCTURE DOMAIN KNOWLEDGE The ideal candidate brings strong depth in End User Services and Information Security & Operations, with working knowledge of Network and Cloud/Compute environments. Demonstrated project experience in two or more of the following areas is required: End User Services (PRIMARY FOCUS) Service / Technology AreaRelevant Delivery ScopeExample Transition Technologies Identity & Access Management Services Identity lifecycle management, access certification, privileged access, role-based provisioning, customer identity, and enterprise directory , Delinea, Okta, Microsoft Entra End User Services Delivery Global end-user service operations, regional onboarding, service desk enablement, incident/change alignment, endpoint support, and user experience improvements.ServiceNow, Microsoft Intune, Microsoft 365, Teams User Access & Workflow Automation Automation of access requests, application provisioning, onboarding/offboarding workflows, intelligent routing, self-service enablement, and shift-left support models.ServiceNow workflows, Moveworks, IVR AI, automation platforms IT Asset & Configuration Management Software and hardware asset lifecycle management, license optimization, CMDB data quality, business application mapping, dependency tracking, and configuration governance.ServiceNow ITAM, ServiceNow CMDB, discovery/mapping tools Directory & Collaboration Platform Modernization Directory consolidation, group and account migration, policy impacts, collaborationActive Directory, Microsoft Entra ID, Microsoft 365, Teams platform readiness, and related service transition activities. Information Security & Operations (PRIMARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Disaster Recovery & Business Continuity Services DR/BC capability assessments, application recovery planning, resiliency modernization, test strategy, business ownership alignment, and recovery readiness governance.Cloud-enabled DR platforms, backup/recovery tools, resiliency reporting dashboards Service Design & Operational Transition ITIL-aligned service design, production readiness, support model definition, operational acceptance criteria, runbook readiness, knowledge transfer, and handoff to ITSM/ITOM/CMDB, knowledge management, operational runbook tools Endpoint Security & Protection Services Endpoint detection and response, device protection, application control, cyber agent compliance, endpoint hardening, and operational controls for managed devices.Microsoft Defender, EDR/XDR platforms, endpoint management agents Vulnerability, Patch & Compliance Operations Operating system and third-party patching, compliance tracking, remediation coordination, vulnerability reduction, audit readiness, and control evidence support.Qualys/Tenable, Tanium, SCCM/Intune, ServiceNow vulnerability workflows Monitoring, Incident & Stability Management Proactive monitoring, alerting, root cause analysis, major incident reduction, operational stability improvements, and service health reporting. Splunk, Nexthink, ServiceNow ITOM, monitoring and observability platforms Network (SECONDARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Network Infrastructure for Workplace & Location Services Planning and delivery of network connectivity, switching, wireless, voice/video readiness, circuit coordination, and infrastructure support for office builds, return-to-office needs, and location expansions.Cisco networking, wireless platforms, LAN/WAN circuits, collaboration network services Enterprise WAN & Cloud Connectivity Modernization Modernization of global WAN connectivity, routing, segmentation, VPN access, cloud connectivity, failover design, and network readiness to support cloud-first and hybrid infrastructure operating models.SD-WAN, MPLS, VPN, cloud WAN, Azure/AWS connectivity, ExpressRoute/Direct Connect SOFT SKILLS & CONSULTING MINDSET Consultative mindset: strong problem-solving abilities, sound judgment, and the ability to identify practical solutions, evaluate alternatives, and recommend clear delivery paths. Prior experience with a Big Four or major consulting firm is preferred. Executive communication: excellent interpersonal skills, poise, diplomacy, and the ability to influence stakeholders toward consensus, manage conflict, and support timely decision-making. Delivery ownership: self-starter who is highly organized . click apply for full job details
09/22/2026
Full time
Job DescriptionJob Description SENIOR TECHNICAL INFRASTRUCTURE PROJECT MANAGER Location; Newport Beach, CA JOB DESCRIPTION As a Senior Technical Infrastructure Project Manager within the company's Infrastructure & Operations Tower, you'll lead the planning, execution, and delivery of complex infrastructure technology initiatives with a primary focus on End User Services (EUS) and Information Security & Operations, with secondary support for Network and working knowledge of Cloud and Compute initiatives. You will be embedded within the I&O Tower - one of the largest portfolios in the company's Technology - supporting infrastructure modernization, identity and access management, endpoint/user services, resiliency, service transition, and operational readiness outcomes aligned to enterprise technology priorities. This role requires more than traditional project coordination. We are looking for a consultative, technically fluent infrastructure PM who can facilitate technical working sessions, understand architecture and operational dependencies at a working level, ask probing and technically informed questions of engineers and architects, challenge assumptions, identify delivery gaps, and translate technical complexity into clear, executive-ready updates. The ideal candidate brings strong delivery experience across identity governance, IT service management, endpoint security, disaster recovery/business continuity, infrastructure readiness, cutover planning, and operational handoff. KEY RESPONSIBILITIES TECHNICAL INFRASTRUCTURE DELIVERY Lead delivery of complex, cross-functional infrastructure projects across End User Services and Information Security & Operations, with secondary support for Network and Cloud/Compute dependencies. Drive infrastructure modernization programs including Identity Governance & Administration (IGA) 2.0, EUS Global Expansion, User Access Management Automation, ITAM Optimization & Maturity, Service Design & Transition, Global DR Assessment, and broader DR/BC resilience initiatives. Develop and manage integrated project plans, technical workstream plans, milestones, dependencies, decision points, readiness criteria, and delivery risks across engineering, architecture, operations, security, and business stakeholders. Coordinate environment readiness, migration/cutover planning, change alignment, release coordination, validation activities, operational handoff, and service transition to ensure infrastructure solutions are production-ready and supportable. STAKEHOLDER & GOVERNANCE MANAGEMENT Lead and influence stakeholders across engineering, architecture, operations, cybersecurity, service management, and business teams while balancing global standards with regional needs in a matrixed operating model. Serve as a liaison between Technology, Re, Corporate Functions, vendors, and delivery partners; build strong relationships with project sponsors and technical leaders to support timely decisions and delivery alignment. Manage scope, schedule, budget, resources, risks, issues, dependencies, assumptions, decisions, and change impacts; escalate barriers early and facilitate governance forums, project reviews, and steering committee discussions. Translate technical status, risks, readiness gaps, and delivery tradeoffs into clear project communications, executive summaries, KPIs, Power BI dashboards, and management committee updates. RISK, READINESS, CHANGE & OPERATIONAL HANDOFF Drive infrastructure readiness planning, including technical prerequisites, operational acceptance criteria, support model alignment, service transition, runbook readiness, knowledge transfer, and production support handoff. Partner with change, release, service management, cybersecurity, and operations teams to ensure technical changes are sequenced, communicated, approved, validated, and transitioned effectively. Identify delivery process improvements, coach project team members on strong delivery discipline, and help raise the quality of planning, reporting, risk management, and execution across the Infrastructure Tower. QUALIFICATIONS CORE PROJECT MANAGEMENT COMPETENCIES 7-10+ years of progressive experience in project/program management, including demonstrated delivery of enterprise infrastructure and technology projects (Waterfall, Agile, and hybrid delivery models). Proven success managing $1M-$5M+ infrastructure programs with budgets, timelines, and cross-functional dependencies spanning 12-24 months. Strong understanding of Agile principles and practices, with the ability to coach teams on Agile adoption, Scrum, Kanban, and continuous improvement. Demonstrated experience applying multi-modal delivery (incremental waterfall, hybrid, agile) in enterprise technology environments. INFRASTRUCTURE DOMAIN KNOWLEDGE The ideal candidate brings strong depth in End User Services and Information Security & Operations, with working knowledge of Network and Cloud/Compute environments. Demonstrated project experience in two or more of the following areas is required: End User Services (PRIMARY FOCUS) Service / Technology AreaRelevant Delivery ScopeExample Transition Technologies Identity & Access Management Services Identity lifecycle management, access certification, privileged access, role-based provisioning, customer identity, and enterprise directory , Delinea, Okta, Microsoft Entra End User Services Delivery Global end-user service operations, regional onboarding, service desk enablement, incident/change alignment, endpoint support, and user experience improvements.ServiceNow, Microsoft Intune, Microsoft 365, Teams User Access & Workflow Automation Automation of access requests, application provisioning, onboarding/offboarding workflows, intelligent routing, self-service enablement, and shift-left support models.ServiceNow workflows, Moveworks, IVR AI, automation platforms IT Asset & Configuration Management Software and hardware asset lifecycle management, license optimization, CMDB data quality, business application mapping, dependency tracking, and configuration governance.ServiceNow ITAM, ServiceNow CMDB, discovery/mapping tools Directory & Collaboration Platform Modernization Directory consolidation, group and account migration, policy impacts, collaborationActive Directory, Microsoft Entra ID, Microsoft 365, Teams platform readiness, and related service transition activities. Information Security & Operations (PRIMARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Disaster Recovery & Business Continuity Services DR/BC capability assessments, application recovery planning, resiliency modernization, test strategy, business ownership alignment, and recovery readiness governance.Cloud-enabled DR platforms, backup/recovery tools, resiliency reporting dashboards Service Design & Operational Transition ITIL-aligned service design, production readiness, support model definition, operational acceptance criteria, runbook readiness, knowledge transfer, and handoff to ITSM/ITOM/CMDB, knowledge management, operational runbook tools Endpoint Security & Protection Services Endpoint detection and response, device protection, application control, cyber agent compliance, endpoint hardening, and operational controls for managed devices.Microsoft Defender, EDR/XDR platforms, endpoint management agents Vulnerability, Patch & Compliance Operations Operating system and third-party patching, compliance tracking, remediation coordination, vulnerability reduction, audit readiness, and control evidence support.Qualys/Tenable, Tanium, SCCM/Intune, ServiceNow vulnerability workflows Monitoring, Incident & Stability Management Proactive monitoring, alerting, root cause analysis, major incident reduction, operational stability improvements, and service health reporting. Splunk, Nexthink, ServiceNow ITOM, monitoring and observability platforms Network (SECONDARY FOCUS) Service / Technology Area Relevant Delivery ScopeExample Transition Technologies Network Infrastructure for Workplace & Location Services Planning and delivery of network connectivity, switching, wireless, voice/video readiness, circuit coordination, and infrastructure support for office builds, return-to-office needs, and location expansions.Cisco networking, wireless platforms, LAN/WAN circuits, collaboration network services Enterprise WAN & Cloud Connectivity Modernization Modernization of global WAN connectivity, routing, segmentation, VPN access, cloud connectivity, failover design, and network readiness to support cloud-first and hybrid infrastructure operating models.SD-WAN, MPLS, VPN, cloud WAN, Azure/AWS connectivity, ExpressRoute/Direct Connect SOFT SKILLS & CONSULTING MINDSET Consultative mindset: strong problem-solving abilities, sound judgment, and the ability to identify practical solutions, evaluate alternatives, and recommend clear delivery paths. Prior experience with a Big Four or major consulting firm is preferred. Executive communication: excellent interpersonal skills, poise, diplomacy, and the ability to influence stakeholders toward consensus, manage conflict, and support timely decision-making. Delivery ownership: self-starter who is highly organized . click apply for full job details
CMMC Assessment Lead
Paragone Solutions, Inc. Buffalo, New York
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. York, Pennsylvania
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Providence, Rhode Island
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Chattanooga, Tennessee
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Jackson, Mississippi
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Fort Lauderdale, Florida
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Lincoln, Nebraska
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Santa Clara, California
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Saint Paul, Minnesota
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Jersey City, New Jersey
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Worcester, Massachusetts
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Akron, Ohio
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Rockford, Illinois
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Albany, Georgia
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Oakland, California
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Anchorage, Alaska
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Spokane, Washington
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Chandler, Arizona
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/21/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board