it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

2502 jobs found

Email me jobs like this
Refine Search
Current Search
acc lead
EPIC Application Analyst 3 (EpicCare Ambulatory)
Franciscan Missionaries of Our Lady Health System Baton Rouge, Louisiana
Job Description Job Description The Epic Application System Analyst 3 designs, configures, supports and maintains accurate and efficient Information Services technology, applications and programs to maximize organizational performance. Provides technical, systems and applications support to FMOLHS facilities and users. Provides ongoing analysis and problem-solving to ensure the integration of Epic in effective workflow and process design. Company Description As a leading health care innovator in Louisiana and Mississippi, Franciscan Missionaries of Our Lady Health System brings together outstanding clinicians, the most advanced technology and leading research. With our health system, your career opportunities are endless. From one of Louisiana's largest tertiary medical centers to the most personal and familiar small community hospital, we offer a variety of paths and settings to help your career grow. From clinical to non-clinical, we are a team on a mission to deliver compassionate care to everyone, especially those most in need, by promoting health, wellness and spiritual wholeness. We are committed to serving our community and patients with a dedication to continual improvement, innovation, first-class technology and our award-winning staff.
09/23/2026
Full time
Job Description Job Description The Epic Application System Analyst 3 designs, configures, supports and maintains accurate and efficient Information Services technology, applications and programs to maximize organizational performance. Provides technical, systems and applications support to FMOLHS facilities and users. Provides ongoing analysis and problem-solving to ensure the integration of Epic in effective workflow and process design. Company Description As a leading health care innovator in Louisiana and Mississippi, Franciscan Missionaries of Our Lady Health System brings together outstanding clinicians, the most advanced technology and leading research. With our health system, your career opportunities are endless. From one of Louisiana's largest tertiary medical centers to the most personal and familiar small community hospital, we offer a variety of paths and settings to help your career grow. From clinical to non-clinical, we are a team on a mission to deliver compassionate care to everyone, especially those most in need, by promoting health, wellness and spiritual wholeness. We are committed to serving our community and patients with a dedication to continual improvement, innovation, first-class technology and our award-winning staff.
Senior AI Security Technical Architect
Edward Jones Tempe, Arizona
This job posting is anticipated to remain open for 30 days, from 18-Sep-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns. Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging. People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career. View our Purpose, Inclusion and Citizenship Report . Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Team Overview Edward Jones is seeking a Senior AI Security Technical Architect to continue to build upon a defined enterprise AI security strategy, ensuring artificial intelligence and generative AI capabilities are designed, deployed, and operated in a secure, compliant, and responsible manner. This role is responsible for aligning business objectives, technology strategy, and security architecture to enable AI innovation with clear guardrails. The Senior AI Security Technical Architect will establish standards, patterns, and governance across multiple AI usage models, including third party SaaS AI solutions, internally developed AI/ML platforms, and emerging agentic and autonomous AI systems. By grounding AI security practices in industry frameworks such as NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS, this role ensures AI risks are proactively identified, communicated, and mitigated while supporting the firm's broader digital transformation, cloud adoption, and regulatory obligations. What You'll Do Own and evolve the enterprise AI security architecture and strategy, aligning business goals, technology platforms, and risk management practices. Assist in defining secure by design patterns and standards for AI/ML systems Establish and maintain AI specific security artifacts Ensure consistent adoption of NIST AI RMF, MITRE ATLAS, CIS, ISO 27001 across AI initiatives. Establish architectural governance and enforce adherence to AI security standards across product teams and platforms. Influence AI design decisions early in the lifecycle to reduce downstream risk and rework. Partner with enterprise stakeholders to balance speed of innovation with risk tolerance and regulatory expectations. Evaluate AI frameworks, agents, vector databases, and third party AI platforms for security posture and enterprise readiness. Recommend and rationalize AI security tooling as part of the broader enterprise security strategy. Monitor emerging AI threats, regulatory guidance, and industry best practices to inform security strategy and standards. What Experience You'll Need Bachelor's degree in Computer Science, Engineering, or related field, or equivalent practical experience. 12+ years of experience in cybersecurity engineering or architecture within a complex enterprise environment. 4+ years of hands on experience securing or reviewing AI/ML systems and platforms. Strong understanding of: LLM architectures, embeddings, and Retrieval Augmented Generation (RAG) patterns End to end ML pipelines (training validation deployment inference) AI model supply chain risks (model registries, containers, dependencies, open source components) Zero Trust and identity centric security models Cloud security across Azure, AWS, and GCP Proven ability to influence architecture decisions and lead cross functional initiatives at the enterprise level. Excellent communication skills, with the ability to engage senior technical and business leaders. What Could Set You Apart Security certifications such as CISSP, CISM, CCSP, or SANS certifications. Experience contributing to responsible AI practices, explainability, or bias mitigation initiatives. Experience securing AI platforms in regulated industries, particularly financial services. Demonstrated experience in incident response and enterprise risk management. Understanding of various regulatory requirements and laws, including but not limited to NYDFS Cybersecurity Regulations and FINRA Regulations Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week. At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received. Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law. Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page . Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. Edward Jones is prohibited from hiring individuals with certain specified criminal history as set forth in Section 3(a)(39) and 15(b)(4) and Rule 17a-3(a)(12) of the Securities and Exchange Act of 1934, and conducts background reviews consistent with FINRA Rule 3110(e). A copy of a notice regarding the provisions of the Los Angeles County Fair Chance Ordinance is available at: dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf .
09/23/2026
Full time
This job posting is anticipated to remain open for 30 days, from 18-Sep-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns. Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging. People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career. View our Purpose, Inclusion and Citizenship Report . Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Team Overview Edward Jones is seeking a Senior AI Security Technical Architect to continue to build upon a defined enterprise AI security strategy, ensuring artificial intelligence and generative AI capabilities are designed, deployed, and operated in a secure, compliant, and responsible manner. This role is responsible for aligning business objectives, technology strategy, and security architecture to enable AI innovation with clear guardrails. The Senior AI Security Technical Architect will establish standards, patterns, and governance across multiple AI usage models, including third party SaaS AI solutions, internally developed AI/ML platforms, and emerging agentic and autonomous AI systems. By grounding AI security practices in industry frameworks such as NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS, this role ensures AI risks are proactively identified, communicated, and mitigated while supporting the firm's broader digital transformation, cloud adoption, and regulatory obligations. What You'll Do Own and evolve the enterprise AI security architecture and strategy, aligning business goals, technology platforms, and risk management practices. Assist in defining secure by design patterns and standards for AI/ML systems Establish and maintain AI specific security artifacts Ensure consistent adoption of NIST AI RMF, MITRE ATLAS, CIS, ISO 27001 across AI initiatives. Establish architectural governance and enforce adherence to AI security standards across product teams and platforms. Influence AI design decisions early in the lifecycle to reduce downstream risk and rework. Partner with enterprise stakeholders to balance speed of innovation with risk tolerance and regulatory expectations. Evaluate AI frameworks, agents, vector databases, and third party AI platforms for security posture and enterprise readiness. Recommend and rationalize AI security tooling as part of the broader enterprise security strategy. Monitor emerging AI threats, regulatory guidance, and industry best practices to inform security strategy and standards. What Experience You'll Need Bachelor's degree in Computer Science, Engineering, or related field, or equivalent practical experience. 12+ years of experience in cybersecurity engineering or architecture within a complex enterprise environment. 4+ years of hands on experience securing or reviewing AI/ML systems and platforms. Strong understanding of: LLM architectures, embeddings, and Retrieval Augmented Generation (RAG) patterns End to end ML pipelines (training validation deployment inference) AI model supply chain risks (model registries, containers, dependencies, open source components) Zero Trust and identity centric security models Cloud security across Azure, AWS, and GCP Proven ability to influence architecture decisions and lead cross functional initiatives at the enterprise level. Excellent communication skills, with the ability to engage senior technical and business leaders. What Could Set You Apart Security certifications such as CISSP, CISM, CCSP, or SANS certifications. Experience contributing to responsible AI practices, explainability, or bias mitigation initiatives. Experience securing AI platforms in regulated industries, particularly financial services. Demonstrated experience in incident response and enterprise risk management. Understanding of various regulatory requirements and laws, including but not limited to NYDFS Cybersecurity Regulations and FINRA Regulations Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week. At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received. Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law. Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page . Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. Edward Jones is prohibited from hiring individuals with certain specified criminal history as set forth in Section 3(a)(39) and 15(b)(4) and Rule 17a-3(a)(12) of the Securities and Exchange Act of 1934, and conducts background reviews consistent with FINRA Rule 3110(e). A copy of a notice regarding the provisions of the Los Angeles County Fair Chance Ordinance is available at: dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf .
CMMC Assessment Lead
Paragone Solutions, Inc. Chattanooga, Tennessee
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Rockford, Illinois
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Akron, Ohio
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Jackson, Mississippi
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Fort Lauderdale, Florida
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Lincoln, Nebraska
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Santa Clara, California
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Saint Paul, Minnesota
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Jersey City, New Jersey
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Albany, Georgia
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Buffalo, New York
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Providence, Rhode Island
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Worcester, Massachusetts
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Everett, Washington
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Bismarck, North Dakota
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Boise, Idaho
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Tallahassee, Florida
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
CMMC Assessment Lead
Paragone Solutions, Inc. Savannah, Georgia
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
09/23/2026
Full time
Job DescriptionJob DescriptionAbout SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID ) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations. We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements. The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities. Location and Travel: This is a remote position with occasional travel required to support customer assessments. Position Summary The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership. This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) Maintain the master CMMC customer assessment schedule Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams Conduct readiness reviews and pre-assessment planning meetings Track customer assessment milestones, dependencies, and remediation activities Manage customer communications related to assessment preparation and scheduling Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes Monitor assessment status and provide executive-level reporting on customer readiness Assist customers in understanding assessment scope, boundary definitions, and enclave considerations Prepare Assessment Packages (Primary) Update implementation statements as needed Gather and organize evidentiary artifacts Coordinate customer evidence collection activities Review SSPs, policies, procedures, and supporting documentation for assessment readiness Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives Prepare assessor-ready evidence packages and artifact repositories Conduct internal quality assurance reviews of documentation and evidence Identify documentation gaps and coordinate remediation activities Support development and maintenance of Plans of Action & Milestones (POA&Ms) Ensure documentation aligns with evolving CMMC and NIST guidance Support Customer Assessments (Primary) Attend and actively support customer assessments Actively defend implementations and evidence presented to assessors Coordinate assessment interviews and technical demonstrations Support mock assessments and readiness exercises for customers Assist customers in responding to assessor requests and follow-up questions Document assessment observations, findings, and remediation actions Coordinate post-assessment remediation activities and evidence resubmissions when required Serve as a trusted advisor throughout the certification lifecycle Maintain SecureITSM's Authorization and Compliance (Secondary) Conduct SecureITSM's annual self-assessment activities Maintain internal compliance documentation and evidentiary artifacts Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans) Assist with internal policy and procedure updates Support ongoing continuous monitoring and compliance validation activities Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary) Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments) Standardize implementation language and evidence expectations across customer environments Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices Validate implementation statements for technical accuracy, completeness, and assessor defensibility Support continuous improvement of SecureITSM's proprietary documentation platform and implementation content library Maintain and Improve Standard Operating Procedures (Secondary) Develop and maintain assessment preparation Standard Operating Procedures (SOPs) Continuously improve evidence collection and assessment support workflows Create standardized templates, checklists, and assessment playbooks Document lessons learned and incorporate process improvements Maintain internal knowledge base articles and operational documentation Assist in refining SecureITSM's proprietary CMMC documentation platform workflows and processes Required Qualifications U.S. Citizenship required Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171 Experience supporting compliance assessments, audits, or certification activities Strong understanding of CMMC assessment methodology and evidence requirements Excellent technical writing and communication skills Strong project management and organizational abilities Exceptional attention to detail Ability to manage multiple customer engagements simultaneously Experience working directly with external assessors, auditors, or regulatory bodies Familiarity with secure project management and compliance collaboration platforms Preferred Qualifications PMP certification preferred CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred CISSP, CISM, or equivalent cybersecurity certification preferred Experience supporting DoD contractors or working within the Defense Industrial Base (DIB) Familiarity with FedRAMP and DFARS Experience with SIEM, vulnerability management, and endpoint protection technologies Key Attributes Strong leadership and customer engagement skills Ability to remain composed and professional during high-pressure assessment activities Analytical thinker with strong problem-solving capabilities Self-motivated with ability to work independently Collaborative team player with strong interpersonal skills High level of integrity and professionalism All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law. Powered by JazzHR 0mriC7k8Mc Company Description Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment. Company DescriptionParagone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board