Job Description Job Description Hansen Gress is a fast-growing, Alaska-based Managed Services Provider with deep roots in Juneau and active expansion into Anchorage. We're 30 people today, scaling quickly, and investing in the people and systems needed to serve our clients with consistency and excellence. We run lean, trust our team, and believe in leadership that works alongside people-not above them. We're relationship-first, execution-focused, and allergic to bureaucracy. If you want to own your work, improve how things get done, and grow into something bigger, this is the right place. The Role The MSP Technical Lead (L3) is our highest individual-contributor technical role and one of the most important seats in the company. You will operate across our three core technical functions-Help Desk, Projects, and Centralized Services-but will typically be hired into one or two concentrated areas. In this role, you'll be the person we trust with our hardest problems, most complex client environments, and most critical escalations. You're the person who holds the line when things get hard and makes things better when they're not. This isn't just a "senior tech" role. You're expected to identify patterns across clients, build and improve processes, reduce key-person risk through documentation and training, and proactively raise the technical bar across the team. You bring structure and repeatability to everything you touch. Successful and consistent performance at this level will position you for future leadership and specialization opportunities, including roles like Onboarding Manager, Help Desk Manager, Centralized Services Manager, and others as the company grows. What You'll Do Technical Execution Take ownership of complex, high-priority escalations from L1 and L2 technicians across Help Desk, Project, and Centralized Services functions. Resolve advanced issues involving Windows Server environments, Microsoft 365, Active Directory, Group Policy, DNS, and enterprise security configurations. Configure, maintain, and support virtualization platforms including Hyper-V-VM builds, migrations, and ongoing maintenance. Administer and troubleshoot Azure Virtual Desktop (AVD) environments and related Microsoft cloud technologies. Configure and troubleshoot firewalls, switches, VLANs, VPN connectivity, and LAN/WAN infrastructure across platforms including SonicWall and Ubiquiti. Utilize PowerShell and CMD scripting for automation, troubleshooting, and system administration tasks. Leverage AI tools actively and fluently to force-multiply your output-whether that's accelerating documentation, automating repetitive work, diagnosing complex issues faster, or building better client-facing materials. At L3, AI proficiency is a professional expectation, not a nice-to-have. Anticipate technical risks before they become client problems-evaluate business impact, flag issues proactively, and maintain clear records of outcomes and contributions. Process, Documentation & Knowledge Create and improve processes-not just follow them. At L3, you're expected to lead documentation standards and build repeatable systems that reduce key-man risk. Actively train and teach teammates. You're responsible for helping others grow, not just solving problems yourself. Build playbooks, standardize delivery, and identify opportunities for automation that improve consistency and scale across the team. Document client environments, recurring issues, and resolutions so that institutional knowledge lives in the system, not just in your head. Communication & Client Experience Communicate clearly and proactively with clients and internal staff-especially in high-pressure situations where confidence and clarity matter most. Set and manage client expectations accurately, keeping relevant stakeholders informed on timelines, risks, and progress. Communicate trends, risks, and service improvements upward to leadership with context and clarity. Understand your clients' businesses, not just their technology. L3 technicians are expected to know how a client operates, what matters to their leadership, and how a technical issue or recommendation translates into real business impact. Represent Hansen Gress professionally in every client interaction-this role carries real weight in how clients experience us. Ownership & Accountability Own your outcomes-not just your tasks. You're accountable for the quality, completeness, and follow-through on everything you touch. Prioritize effectively across competing demands. Help Desk volume, project timelines, and centralized service delivery all require judgment about what matters most. Proactively identify what's not working-across your own work, team processes, and client environments-and do something about it. Mentor junior technicians and invest in their development as a direct expression of your own leadership potential. Who You Are You have substantial IT support experience-typically 5-10+ years-with meaningful time in an MSP or IT services environment. We care more about the depth of what you've built and solved than the number of years on your resume. You've earned the L3 designation through demonstrated capability-not just tenure. You operate at this level consistently, not occasionally. You identify patterns across tickets and client environments and use them to prevent problems, not just react to them. You're a strong communicator in both directions-clear with clients, and clear with leadership. You don't let things fall through the cracks silently. You take documentation seriously. You understand that knowledge trapped in one person's head is a liability, and you build systems that outlast any individual. You mentor others naturally. Sharing what you know isn't a burden-it's part of how you define doing a good job. You're organized, detail-oriented, and process-driven-but you can also move fast when the situation calls for it. You're adaptable. In an MSP environment, no two days are the same, and you're energized rather than frustrated by that reality. You are a recognized subject matter expert across the full Hansen Gress technology stack-not a generalist who knows a little about everything, but someone the team and our clients can point to and say "ask them." You hold deep, current, hands-on expertise across the platforms and disciplines we deliver. You are technically reliable-the kind of person who doesn't speculate out loud, doesn't guess under pressure, and doesn't put wrong information into the world. At L3, the team and our clients defer to you. That trust is earned and protected by a consistent commitment to getting it right. Living in Alaska is either a passion of yours or a dream you want to fulfill. We are looking for someone who is "all in" on Alaska and fits our team and culture. Technical Qualifications Deep, hands-on expertise in Microsoft 365/O365 administration-including Exchange Online, Teams, SharePoint, Intune, Entra ID (Azure AD), licensing management, and tenant-level configuration and troubleshooting. Hands-on experience managing Hyper-V environments, including VM builds, migrations, and maintenance. Strong understanding of LAN/WAN networking with experience configuring and troubleshooting VLANs, managed switches, and connectivity issues across platforms such as Ubiquiti and SonicWall. Advanced experience configuring and troubleshooting firewalls, including routing, VPN, access policies, and network segmentation. Experience administering Azure Virtual Desktop (AVD) and Microsoft 365 cloud technologies. Basic to intermediate scripting and automation experience using PowerShell and CMD. What You'll Need Ability to pass a basic background check for airport security badging Valid driver's license (or willingness to get one) and the ability to drive. Driver policies apply. Where You'll Work Must be based in Juneau or Anchorage, Alaska This role requires regular face-to-face collaboration in Juneau, Anchorage, and other Alaska communities. This is NOT a fully remote position What's In It For You Full-time role Salary: $100,000-$125,000 a year, depending on experience Health insurance (with vision coverage) Retirement plans Work in Juneau or Anchorage with relocation assistance Why You'll Want to Work with Us Employee satisfaction and growth are important to us! We are committed to helping employees dedicate part of their paid time to personal growth through courses and certifications relevant to their specific interests, research and development, and team-building opportunities. See what else our current employees have to say. Hansen Gress is committed to equal treatment and opportunities for all employees and job applicants. We are dedicated to building an inclusive and diverse company and have no tolerance for discrimination or harassment. We strive to provide meaningful opportunities for all, particularly those who have been traditionally marginalized in tech fields.
09/24/2026
Full time
Job Description Job Description Hansen Gress is a fast-growing, Alaska-based Managed Services Provider with deep roots in Juneau and active expansion into Anchorage. We're 30 people today, scaling quickly, and investing in the people and systems needed to serve our clients with consistency and excellence. We run lean, trust our team, and believe in leadership that works alongside people-not above them. We're relationship-first, execution-focused, and allergic to bureaucracy. If you want to own your work, improve how things get done, and grow into something bigger, this is the right place. The Role The MSP Technical Lead (L3) is our highest individual-contributor technical role and one of the most important seats in the company. You will operate across our three core technical functions-Help Desk, Projects, and Centralized Services-but will typically be hired into one or two concentrated areas. In this role, you'll be the person we trust with our hardest problems, most complex client environments, and most critical escalations. You're the person who holds the line when things get hard and makes things better when they're not. This isn't just a "senior tech" role. You're expected to identify patterns across clients, build and improve processes, reduce key-person risk through documentation and training, and proactively raise the technical bar across the team. You bring structure and repeatability to everything you touch. Successful and consistent performance at this level will position you for future leadership and specialization opportunities, including roles like Onboarding Manager, Help Desk Manager, Centralized Services Manager, and others as the company grows. What You'll Do Technical Execution Take ownership of complex, high-priority escalations from L1 and L2 technicians across Help Desk, Project, and Centralized Services functions. Resolve advanced issues involving Windows Server environments, Microsoft 365, Active Directory, Group Policy, DNS, and enterprise security configurations. Configure, maintain, and support virtualization platforms including Hyper-V-VM builds, migrations, and ongoing maintenance. Administer and troubleshoot Azure Virtual Desktop (AVD) environments and related Microsoft cloud technologies. Configure and troubleshoot firewalls, switches, VLANs, VPN connectivity, and LAN/WAN infrastructure across platforms including SonicWall and Ubiquiti. Utilize PowerShell and CMD scripting for automation, troubleshooting, and system administration tasks. Leverage AI tools actively and fluently to force-multiply your output-whether that's accelerating documentation, automating repetitive work, diagnosing complex issues faster, or building better client-facing materials. At L3, AI proficiency is a professional expectation, not a nice-to-have. Anticipate technical risks before they become client problems-evaluate business impact, flag issues proactively, and maintain clear records of outcomes and contributions. Process, Documentation & Knowledge Create and improve processes-not just follow them. At L3, you're expected to lead documentation standards and build repeatable systems that reduce key-man risk. Actively train and teach teammates. You're responsible for helping others grow, not just solving problems yourself. Build playbooks, standardize delivery, and identify opportunities for automation that improve consistency and scale across the team. Document client environments, recurring issues, and resolutions so that institutional knowledge lives in the system, not just in your head. Communication & Client Experience Communicate clearly and proactively with clients and internal staff-especially in high-pressure situations where confidence and clarity matter most. Set and manage client expectations accurately, keeping relevant stakeholders informed on timelines, risks, and progress. Communicate trends, risks, and service improvements upward to leadership with context and clarity. Understand your clients' businesses, not just their technology. L3 technicians are expected to know how a client operates, what matters to their leadership, and how a technical issue or recommendation translates into real business impact. Represent Hansen Gress professionally in every client interaction-this role carries real weight in how clients experience us. Ownership & Accountability Own your outcomes-not just your tasks. You're accountable for the quality, completeness, and follow-through on everything you touch. Prioritize effectively across competing demands. Help Desk volume, project timelines, and centralized service delivery all require judgment about what matters most. Proactively identify what's not working-across your own work, team processes, and client environments-and do something about it. Mentor junior technicians and invest in their development as a direct expression of your own leadership potential. Who You Are You have substantial IT support experience-typically 5-10+ years-with meaningful time in an MSP or IT services environment. We care more about the depth of what you've built and solved than the number of years on your resume. You've earned the L3 designation through demonstrated capability-not just tenure. You operate at this level consistently, not occasionally. You identify patterns across tickets and client environments and use them to prevent problems, not just react to them. You're a strong communicator in both directions-clear with clients, and clear with leadership. You don't let things fall through the cracks silently. You take documentation seriously. You understand that knowledge trapped in one person's head is a liability, and you build systems that outlast any individual. You mentor others naturally. Sharing what you know isn't a burden-it's part of how you define doing a good job. You're organized, detail-oriented, and process-driven-but you can also move fast when the situation calls for it. You're adaptable. In an MSP environment, no two days are the same, and you're energized rather than frustrated by that reality. You are a recognized subject matter expert across the full Hansen Gress technology stack-not a generalist who knows a little about everything, but someone the team and our clients can point to and say "ask them." You hold deep, current, hands-on expertise across the platforms and disciplines we deliver. You are technically reliable-the kind of person who doesn't speculate out loud, doesn't guess under pressure, and doesn't put wrong information into the world. At L3, the team and our clients defer to you. That trust is earned and protected by a consistent commitment to getting it right. Living in Alaska is either a passion of yours or a dream you want to fulfill. We are looking for someone who is "all in" on Alaska and fits our team and culture. Technical Qualifications Deep, hands-on expertise in Microsoft 365/O365 administration-including Exchange Online, Teams, SharePoint, Intune, Entra ID (Azure AD), licensing management, and tenant-level configuration and troubleshooting. Hands-on experience managing Hyper-V environments, including VM builds, migrations, and maintenance. Strong understanding of LAN/WAN networking with experience configuring and troubleshooting VLANs, managed switches, and connectivity issues across platforms such as Ubiquiti and SonicWall. Advanced experience configuring and troubleshooting firewalls, including routing, VPN, access policies, and network segmentation. Experience administering Azure Virtual Desktop (AVD) and Microsoft 365 cloud technologies. Basic to intermediate scripting and automation experience using PowerShell and CMD. What You'll Need Ability to pass a basic background check for airport security badging Valid driver's license (or willingness to get one) and the ability to drive. Driver policies apply. Where You'll Work Must be based in Juneau or Anchorage, Alaska This role requires regular face-to-face collaboration in Juneau, Anchorage, and other Alaska communities. This is NOT a fully remote position What's In It For You Full-time role Salary: $100,000-$125,000 a year, depending on experience Health insurance (with vision coverage) Retirement plans Work in Juneau or Anchorage with relocation assistance Why You'll Want to Work with Us Employee satisfaction and growth are important to us! We are committed to helping employees dedicate part of their paid time to personal growth through courses and certifications relevant to their specific interests, research and development, and team-building opportunities. See what else our current employees have to say. Hansen Gress is committed to equal treatment and opportunities for all employees and job applicants. We are dedicated to building an inclusive and diverse company and have no tolerance for discrimination or harassment. We strive to provide meaningful opportunities for all, particularly those who have been traditionally marginalized in tech fields.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.