CMMC Program Manager

Program ManagerProgram ManagerFull TimeRemote

Location

United States

Posted

11 days ago

Salary

$132K - $162K / year

Program ManagementCybersecurityCMMCNIST 800 171NIST Cybersecurity FrameworkISO 27001Risk ManagementGovernanceDFARSCISSPPolicy DevelopmentAuditIncident ResponseVulnerability ManagementThird Party Risk

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

The CMMC Program Manager is responsible for leading clients through NeoSystems Security Program Management solution and driving the overall maturity of our security program. This role oversees the development, implementation, and continuous improvement of cybersecurity compliance activities, ensuring alignment with regulatory requirements and industry best practices. The ideal candidate brings strong program management capabilities paired with hands‑on expertise in security controls, risk management, and governance frameworks. This leader partners closely with IT, engineering, legal, procurement, and executive stakeholders to maintain a robust, audit‑ready security posture that supports organizational objectives.

Qualifications

  • Bachelor’s degree in information systems or related field
  • 5-10 years of experience in consulting, compliance, and cybersecurity or security program experience
  • CISSP or equivalent certification required or equivalent work experience
  • Strong understanding of security governance, risk management, and control frameworks
  • Strong understanding of CMMC framework and its requirements
  • Excellent communication and people skills to effectively interact with various stakeholders
  • Ability to lead and influence cross-functional teams towards a common goal
  • Detail-oriented with strong analytical and problem-solving skills
  • Ability to manage complex, cross-functional programs to drive results
  • CMMC-RPA certification required within first 90 days of employment

Requirements

  • Lead the clients CMMC readiness, certification, and sustainment efforts across all required domains
  • Conduct gap assessments against CMMC practices and processes; develop and manage remediation roadmaps
  • Oversee creation and maintenance of required documentation, policies, SSPs, POA&Ms, and evidence repositories
  • Coordinate with external assessors, RPOs, and C3PAOs during audits and assessments
  • Ensure continuous compliance and maturity progression as CMMC requirements evolve
  • Develop, implement, and maintain the enterprise security program aligned with NIST 800‑171, NIST CSF, ISO 27001, and other relevant frameworks
  • Manage cross‑functional security initiatives, including risk assessments, vulnerability management, incident response planning, and third‑party risk
  • Establish KPIs, metrics, and reporting mechanisms to track program performance and communicate status to leadership
  • Drive policy development, lifecycle management, and organizational adoption of security standards
  • Partner with IT and engineering teams to ensure security controls are implemented effectively and sustainably
  • Lead internal audits, control testing, and continuous monitoring activities
  • Maintain a strong understanding of federal contracting requirements, DFARS 252.204‑7012, and related compliance obligations
  • Support contract reviews, security clauses, and customer assurance activities
  • Identify risks, propose mitigation strategies, and ensure timely remediation
  • Serve as a trusted advisor to senior leadership on cybersecurity maturity and compliance posture
  • Provide guidance and training to internal teams on CMMC practices and security best practices
  • Foster a culture of security awareness and accountability across the organization
  • Manage vendor relationships related to cybersecurity tools, assessments, and advisory services
  • Responsible for initial delivery of CMMC Program with program & deliverable oversight for CMMC clients
  • Lead the implementation of documented strategies to achieve and maintain compliance with CMMC requirements across designated products
  • Collaborate with other relevant departments to ensure a comprehensive approach to CMMC compliance
  • Participate in client information security risk and compliance assessments and audits
  • Lead client gap analysis and remediation plans
  • Lead Incident Response Tabletop exercises and supporting efforts
  • Deliver external processes to support the overall maturity of the Federal practice within client organizations

Benefits

  • Ability to travel
  • Location: Remote but must be within the continental United States

Job Requirements

  • Bachelor’s degree in information systems or related field
  • 5-10 years of experience in consulting, compliance, and cybersecurity or security program experience
  • CISSP or equivalent certification required or equivalent work experience
  • Strong understanding of security governance, risk management, and control frameworks
  • Strong understanding of CMMC framework and its requirements
  • Excellent communication and people skills to effectively interact with various stakeholders
  • Ability to lead and influence cross-functional teams towards a common goal
  • Detail-oriented with strong analytical and problem-solving skills
  • Ability to manage complex, cross-functional programs to drive results
  • CMMC-RPA certification required within first 90 days of employment
  • Lead the clients CMMC readiness, certification, and sustainment efforts across all required domains
  • Conduct gap assessments against CMMC practices and processes; develop and manage remediation roadmaps
  • Oversee creation and maintenance of required documentation, policies, SSPs, POA&Ms, and evidence repositories
  • Coordinate with external assessors, RPOs, and C3PAOs during audits and assessments
  • Ensure continuous compliance and maturity progression as CMMC requirements evolve
  • Develop, implement, and maintain the enterprise security program aligned with NIST 800‑171, NIST CSF, ISO 27001, and other relevant frameworks
  • Manage cross‑functional security initiatives, including risk assessments, vulnerability management, incident response planning, and third‑party risk
  • Establish KPIs, metrics, and reporting mechanisms to track program performance and communicate status to leadership
  • Drive policy development, lifecycle management, and organizational adoption of security standards
  • Partner with IT and engineering teams to ensure security controls are implemented effectively and sustainably
  • Lead internal audits, control testing, and continuous monitoring activities
  • Maintain a strong understanding of federal contracting requirements, DFARS 252.204‑7012, and related compliance obligations
  • Support contract reviews, security clauses, and customer assurance activities
  • Identify risks, propose mitigation strategies, and ensure timely remediation
  • Serve as a trusted advisor to senior leadership on cybersecurity maturity and compliance posture
  • Provide guidance and training to internal teams on CMMC practices and security best practices
  • Foster a culture of security awareness and accountability across the organization
  • Manage vendor relationships related to cybersecurity tools, assessments, and advisory services
  • Responsible for initial delivery of CMMC Program with program & deliverable oversight for CMMC clients
  • Lead the implementation of documented strategies to achieve and maintain compliance with CMMC requirements across designated products
  • Collaborate with other relevant departments to ensure a comprehensive approach to CMMC compliance
  • Participate in client information security risk and compliance assessments and audits
  • Lead client gap analysis and remediation plans
  • Lead Incident Response Tabletop exercises and supporting efforts
  • Deliver external processes to support the overall maturity of the Federal practice within client organizations

Benefits

  • Ability to travel
  • Location: Remote but must be within the continental United States

Related Categories

Related Job Pages

More Program Manager Jobs

Program Manager11 days ago
Full TimeRemoteTeam 1,001-5,000

We are seeking a Senior Building Consultant to join our Building Consulting team in Western Pennsylvania. This is a unique opportunity for an entrepreneurial, highly driven person with a well-rounded skill set whose responsibilities extend beyond those of traditional project mana...

United States

Senior Program Analyst

The State Bar of California

The State Bar of California’s mission is to protect the public and includes the primary functions of licensing, regulation, and discipline of attorneys; the advancement of the ethical and competent practice of law; and support of efforts for greater access to, and inclusion in, the legal system. Clarity Investing in Our People Excellence Respect Growth Mindset

Program Manager11 days ago
Full TimeRemote

The State Bar of California seeks two full-time Senior Program Analysts to join its access to justice and diversity and inclusion team. The hiring team may consider applications for one or both positions. Candidates are welcome to describe their interest in either or both roles i...

United States

Program Analyst

Office of Suicide Prevention, Veterans Crisis Line

VA offers a comprehensive total rewards package for its employees.

Program Manager11 days ago
Full TimeRemote

Major duties include but are not limited to: Provides analytical advice on matters relating to people, process, and technology, analyzing, assessing, and providing recommendations for improving or simplifying office-wide knowledge and business processes. Advises management offici...

United States

Benefits Manager

CentraCare

CentraCare, a leading not-for-profit health system and one of the largest providers of rural care, serves patients across Central, West Central, and Southwestern Minnesota. It delivers nationally recognized care through 40+ medical and surgical specialties, innovative population health programs, and a collaborative physician–administration leadership model. St. Cloud Hospital, a 489-bed regional referral center and Level II trauma center, delivers comprehensive inpatient and outpatient services with Magnet-designated nursing and expert support staff. Just 60 minutes from Minneapolis-St. Paul, the St. Cloud region is a family-friendly mini-metro featuring excellent schools and four colleges, vibrant arts and theatre, abundant lakes and outdoor recreation, and year-round activities for all seasons. CentraCare has made a commitment to diversity in its workforce. All individuals including, but not limited to, individuals with disabilities, are encouraged to apply. CentraCare is an EEO/AA employer.

Program Manager11 days ago
Full TimeRemoteTeam 10,001

Find your purpose as the Benefits Manager at CentraCare. The Benefits Manager leads the administration and continuous improvement of employee benefits, well-being programs, and absence processes while supporting the overall benefit strategy for a large, complex healthcare workfor...

United States