Jobs › CMMC
CMMC Compliance Jobs
CMMC is the US Department of Defense's certification program that verifies a contractor protects federal contract information and controlled unclassified information before it can be awarded work.
The Cybersecurity Maturity Model Certification is how the US Department of Defense verifies that the companies in its supply chain actually protect the information they are given. It matters more than most frameworks for one reason: it is a condition of award. A contractor that cannot meet the required level for a solicitation cannot win the contract.
CMMC has three levels, keyed to the sensitivity of the information involved. Level 1 covers Federal Contract Information and is 17 basic practices verified by annual self-assessment. Level 2 covers Controlled Unclassified Information and is the full set of 110 security requirements from NIST SP 800-171 Revision 2; most Level 2 contracts require assessment by a CMMC Third-Party Assessment Organization, a C3PAO, rather than a self-assessment. Level 3 adds a selected set of enhanced requirements from NIST SP 800-172 for the highest-value CUI and is assessed by the Defense Industrial Base Cybersecurity Assessment Center.
The acquisition rule that puts CMMC into DoD contracts took effect on 10 November 2025 and phases in over three years, so requirements appear in more solicitations each year through 2028. That timetable is what makes this a hiring market rather than a compliance topic. The defense industrial base is tens of thousands of companies, most of them small or mid-size manufacturers and service firms with no security staff of their own, and every one of them needs a System Security Plan, a POA&M, evidence that survives an assessor, and someone who can run the program. Roles that ask for CMMC want people who can map 800-171 controls to what a business actually does, gather evidence that holds up, and get an organization through an assessment. Much of that work is bought as a scoped engagement rather than a permanent seat.
CMMC: Frequently Asked Questions
What are the three CMMC levels?
Level 1 covers Federal Contract Information and is 17 practices confirmed by annual self-assessment. Level 2 covers Controlled Unclassified Information and is the 110 requirements of NIST SP 800-171 Revision 2, in most cases assessed by a certified third party. Level 3 adds selected enhanced requirements from NIST SP 800-172 for the most sensitive CUI and is assessed by the government's own DIBCAC.
Do I need a certification to work in CMMC?
No. Employers hiring for CMMC work most often want practical NIST SP 800-171 experience: writing a System Security Plan, running a gap assessment, building and closing a POA&M, and assembling assessment evidence. The Cyber AB credentials matter if you intend to assess rather than implement, and CISSP, CISA and CISM all read well alongside the hands-on record.
Is CMMC the same as NIST SP 800-171?
They are closely related but not the same thing. NIST SP 800-171 is the control set. CMMC is the DoD program that verifies a contractor has actually implemented it, and it adds the assessment and certification layer that self-attestation under DFARS 252.204-7012 did not provide.
When does CMMC apply to a contract?
The acquisition rule took effect on 10 November 2025 and phases in over roughly three years, so the required level appears in a growing share of DoD solicitations through 2028. Whether it applies to a specific contract depends on the solicitation and on whether the work involves Federal Contract Information or Controlled Unclassified Information.
Is CMMC work usually full-time or consulting?
Both, and the split is unusual. Large primes and defense-focused integrators hire full-time. Smaller suppliers in the defense industrial base typically cannot justify a permanent hire and buy readiness, remediation and assessment support as scoped engagements instead, which is why a large share of CMMC work is fractional or project-based.
Open CMMC GRC jobs (14)
Information Technology Specialist (Information Security)
Information Security Specialist
Virtual CISO & Cybersecurity Practice Lead
Senior Cybersecurity Engineer Specialist
Security Assurance Lead
GRC Program Manager
Governance, Risk & Compliance (GRC) Manager
IT Enterprise Risk Analyst
Compliance Analyst, Texas Institute for Electronics
Staff Security Assurance Engineer
Senior Compliance Engineer, AI Governance
Principal Compliance Engineer
Senior Compliance Automation Engineer
Senior Compliance Engineer
CMMC jobs: what the market looks like right now
A snapshot built from the 14 CMMC roles currently on this page.
What these roles pay
Of the 14 open CMMC roles on this page, 6 publish a salary range. Across those:
- Median advertised midpoint: $146k
- Middle half of the market: $125k to $168k
- Full advertised range: $88k to $270k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 2 remote, 1 hybrid, 11 on-site or unstated.
- Seniority mix: senior (8), mid (5), executive (1)
- Employers hiring more than one: True Anomaly (3)
Skills these postings ask for
- board and committee reporting
- policy lifecycle ownership
- risk appetite and tolerance setting
- three-lines-of-defence operating models
- ISO/IEC 42001 and NIST AI RMF fluency
How to get a governance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in CMMC postings to be worth knowing: CGEIT, CRISC, AIGP, CISA. The certification academy covers what each one actually tests and who it is for.
Hiring for CMMC?
We have 14 open CMMC roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts