GRC Engineer (CMMC)
New
J
JobgetherCybersecurity Compliance
Based in the United States, 8:00 AM–5:00 PM U.S. Eastern TimeFull-TimeMiddle
SalaryCompetitive base salary with regular performance reviews and bonus opportunities based on performance.
Apply NowOpens the employer's application page
Job Details
- Languages
- English
- Experience
- 2+ years
- Required Skills
- Project Management
Requirements
- 2+ years of direct experience in GRC, cybersecurity compliance, or related roles.
- Hands-on exposure to FedRAMP, NIST SP 800-53, NIST SP 800-171, or federal authorization lifecycles.
- Practical experience authoring and maintaining federal compliance artifacts (SSPs, POA&Ms).
- Foundational knowledge of CMMC 2.0 and NIST SP 800-171 requirements.
- Experience with government cloud environments such as AWS GovCloud, Azure Government, or Microsoft GCC High.
- Strong project management and organizational skills.
- Excellent written and verbal English communication skills.
- Ability to translate complex regulatory and technical requirements into actionable guidance.
- Experience supporting B2B SaaS providers or federal contractors.
Responsibilities
- Analyze and apply NIST SP 800-53 controls and FedRAMP baselines to assess client architectures.
- Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 requirements.
- Author, maintain, and evaluate key compliance artifacts including SSPs, POA&Ms, SAPs, and SARs.
- Conduct detailed readiness assessments and gap analyses for federal ATO and CMMC pathways.
- Define and document technical authorization boundaries, data flows, and shared-responsibility models.
- Execute continuous monitoring activities including vulnerability management and incident response documentation.
- Coordinate external assessment activities between clients, Cloud Service Providers, and 3PAOs.
- Develop structured compliance documentation for CMMC Level 1 and Level 2 engagements.
View Full Description & ApplyYou'll be redirected to the employer's site