About SecureITSMSecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements.The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities.Location and Travel: This is a remote position with occasional travel required to support customer assessments.Position SummaryThe CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership.This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible.Key ResponsibilitiesPlan and Coordinate Assessments (Primary)Maintain the master CMMC customer assessment scheduleCoordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teamsConduct readiness reviews and pre-assessment planning meetingsTrack customer assessment milestones, dependencies, and remediation activitiesManage customer communications related to assessment preparation and schedulingCoordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processesMonitor assessment status and provide executive-level reporting on customer readinessAssist customers in understanding assessment scope, boundary definitions, and enclave considerationsPrepare Assessment Packages (Primary)Update implementation statements as neededGather and organize evidentiary artifactsCoordinate customer evidence collection activitiesReview SSPs, policies, procedures, and supporting documentation for assessment readinessValidate evidence traceability to NIST SP 800-171 requirements and assessment objectivesPrepare assessor-ready evidence packages and artifact repositoriesConduct internal quality assurance reviews of documentation and evidenceIdentify documentation gaps and coordinate remediation activitiesSupport development and maintenance of Plans of Action & Milestones (POA&Ms)Ensure documentation aligns with evolving CMMC and NIST guidanceSupport Customer Assessments (Primary)Attend and actively support customer assessmentsActively defend implementations and evidence presented to assessorsCoordinate assessment interviews and technical demonstrationsSupport mock assessments and readiness exercises for customersAssist customers in responding to assessor requests and follow-up questionsDocument assessment observations, findings, and remediation actionsCoordinate post-assessment remediation activities and evidence resubmissions when requiredServe as a trusted advisor throughout the certification lifecycleMaintain SecureITSM’s Authorization and Compliance (Secondary)Conduct SecureITSM’s annual self-assessment activitiesMaintain internal compliance documentation and evidentiary artifactsCoordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)Assist with internal policy and procedure updatesSupport ongoing continuous monitoring and compliance validation activitiesTrack changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture Implementation Statement Management (Secondary)Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidanceDevelop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)Standardize implementation language and evidence expectations across customer environmentsCoordinate updates to implementation statements based on assessment findings, regulatory changes, and best practicesValidate implementation statements for technical accuracy, completeness, and assessor defensibilitySupport continuous improvement of SecureITSM’s proprietary documentation platform and implementation content libraryMaintain and Improve Standard Operating Procedures (Secondary)Develop and maintain assessment preparation Standard Operating Procedures (SOPs)Continuously improve evidence collection and assessment support workflowsCreate standardized templates, checklists, and assessment playbooksDocument lessons learned and incorporate process improvementsMaintain internal knowledge base articles and operational documentationAssist in refining SecureITSM’s proprietary CMMC documentation platform workflows and processesRequired QualificationsU.S. Citizenship requiredDetailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171Experience supporting compliance assessments, audits, or certification activitiesStrong understanding of CMMC assessment methodology and evidence requirementsExcellent technical writing and communication skillsStrong project management and organizational abilitiesExceptional attention to detailAbility to manage multiple customer engagements simultaneouslyExperience working directly with external assessors, auditors, or regulatory bodiesFamiliarity with secure project management and compliance collaboration platformsPreferred QualificationsPMP certification preferredCMMC Certified Professional (CCP) or Certified Assessor (CCA) preferredCISSP, CISM, or equivalent cybersecurity certification preferredExperience supporting DoD contractors or working within the Defense Industrial Base (DIB)Familiarity with FedRAMP and DFARS 252.204-7012Experience with SIEM, vulnerability management, and endpoint protection technologiesKey AttributesStrong leadership and customer engagement skillsAbility to remain composed and professional during high-pressure assessment activitiesAnalytical thinker with strong problem-solving capabilitiesSelf-motivated with ability to work independentlyCollaborative team player with strong interpersonal skillsHigh level of integrity and professionalism