Description
The Certified CMMC Professional supports CMMC readiness engagements and formal assessments by evaluating cybersecurity practices against CMMC requirements, NIST SP 800-171 controls, and the CMMC Assessment Process. The role includes gap assessments, System Security Plan and POA&M development, control-implementation validation, evidence analysis, remediation guidance, and advisory support for CMMC Level 1 and Level 2 certification. Candidates need 3–5 years of experience in cybersecurity, IT audit or compliance, GRC, or information systems or IT operations, along with knowledge of CMMC, NIST SP 800-171, FedRAMP, and SOC 2, and familiarity with DoD contractor environments and CUI.
