GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsCMMC

CMMC Compliance Jobs

CMMC is the US Department of Defense's certification program that verifies a contractor protects federal contract information and controlled unclassified information before it can be awarded work.

New CMMC GRC jobs, the moment they post.

One click unsubscribe.

The Cybersecurity Maturity Model Certification is how the US Department of Defense verifies that the companies in its supply chain actually protect the information they are given. It matters more than most frameworks for one reason: it is a condition of award. A contractor that cannot meet the required level for a solicitation cannot win the contract.

CMMC has three levels, keyed to the sensitivity of the information involved. Level 1 covers Federal Contract Information and is 17 basic practices verified by annual self-assessment. Level 2 covers Controlled Unclassified Information and is the full set of 110 security requirements from NIST SP 800-171 Revision 2; most Level 2 contracts require assessment by a CMMC Third-Party Assessment Organization, a C3PAO, rather than a self-assessment. Level 3 adds a selected set of enhanced requirements from NIST SP 800-172 for the highest-value CUI and is assessed by the Defense Industrial Base Cybersecurity Assessment Center.

The acquisition rule that puts CMMC into DoD contracts took effect on 10 November 2025 and phases in over three years, so requirements appear in more solicitations each year through 2028. That timetable is what makes this a hiring market rather than a compliance topic. The defense industrial base is tens of thousands of companies, most of them small or mid-size manufacturers and service firms with no security staff of their own, and every one of them needs a System Security Plan, a POA&M, evidence that survives an assessor, and someone who can run the program. Roles that ask for CMMC want people who can map 800-171 controls to what a business actually does, gather evidence that holds up, and get an organization through an assessment. Much of that work is bought as a scoped engagement rather than a permanent seat.

CMMC: Frequently Asked Questions

What are the three CMMC levels?

Level 1 covers Federal Contract Information and is 17 practices confirmed by annual self-assessment. Level 2 covers Controlled Unclassified Information and is the 110 requirements of NIST SP 800-171 Revision 2, in most cases assessed by a certified third party. Level 3 adds selected enhanced requirements from NIST SP 800-172 for the most sensitive CUI and is assessed by the government's own DIBCAC.

Do I need a certification to work in CMMC?

No. Employers hiring for CMMC work most often want practical NIST SP 800-171 experience: writing a System Security Plan, running a gap assessment, building and closing a POA&M, and assembling assessment evidence. The Cyber AB credentials matter if you intend to assess rather than implement, and CISSP, CISA and CISM all read well alongside the hands-on record.

Is CMMC the same as NIST SP 800-171?

They are closely related but not the same thing. NIST SP 800-171 is the control set. CMMC is the DoD program that verifies a contractor has actually implemented it, and it adds the assessment and certification layer that self-attestation under DFARS 252.204-7012 did not provide.

When does CMMC apply to a contract?

The acquisition rule took effect on 10 November 2025 and phases in over roughly three years, so the required level appears in a growing share of DoD solicitations through 2028. Whether it applies to a specific contract depends on the solicitation and on whether the work involves Federal Contract Information or Controlled Unclassified Information.

Is CMMC work usually full-time or consulting?

Both, and the split is unusual. Large primes and defense-focused integrators hire full-time. Smaller suppliers in the defense industrial base typically cannot justify a permanent hire and buy readiness, remediation and assessment support as scoped engagements instead, which is why a large share of CMMC work is fractional or project-based.

Open CMMC GRC jobs (14)

Information Technology Specialist (Information Security)

U.S. Army Communications Electronics Command
On-site · Tobyhanna, Pennsylvania · Full-time
$88k to $114k Cybersecurity Aug 25, 2026

Information Security Specialist

Offices, Boards and Divisions
On-site · Washington, District of Columbia · Full-time
$102k to $158k Featured Cybersecurity TS/SCI Aug 23, 2026

Virtual CISO & Cybersecurity Practice Lead

Interdependence
Remote · Remote · Full-time
Featured Governance Aug 20, 2026

Senior Cybersecurity Engineer Specialist

Concurrent Technologies Corporation
On-site · Johnstown, PA · Full-time
Featured Cybersecurity Compliance Clearable Aug 19, 2026

Security Assurance Lead

Scale AI
On-site · Washington, DC · Full-time
Featured Governance Top Secret CISA CISM CISSP Aug 11, 2026

GRC Program Manager

Palantir Technologies
On-site · New York, NY · Full-time
$90k to $160k Featured Governance Clearance required Aug 11, 2026

Governance, Risk & Compliance (GRC) Manager

Northwood Space
On-site · El Segundo, CA · Full-time
Featured Compliance Aug 10, 2026

IT Enterprise Risk Analyst

Holland & Knight
Hybrid · Miami, FL · Full-time
Featured Risk Jul 31, 2026

Compliance Analyst, Texas Institute for Electronics

UT Austin
On-site · 2 Locations · Full-time
Featured Compliance CISA CISM CISSP Jun 28, 2026

Staff Security Assurance Engineer

Databricks
Remote · Washington D.C. · Remote · Full-time
Featured Governance Top Secret Jun 20, 2026

Senior Compliance Engineer, AI Governance

True Anomaly
On-site · Denver, CO · Full-time
Featured Governance Jun 13, 2026

Principal Compliance Engineer

True Anomaly
On-site · Denver, CO, CA or SF Bay Area or Washington D.C. · Full-time
$185k to $270k Featured Compliance TS/SCI CISSP Jun 13, 2026

Senior Compliance Automation Engineer

True Anomaly
On-site · Denver, CO, CA or SF Bay area · Full-time
$140k to $195k Featured Compliance TS/SCI CISA CRISC CISSP Jun 13, 2026

Senior Compliance Engineer

Anduril Industries
On-site · Costa Mesa, California · Full-time
$146k Featured Compliance Secret CISM CISSP Jun 13, 2026

CMMC jobs: what the market looks like right now

A snapshot built from the 14 CMMC roles currently on this page.

What these roles pay

Of the 14 open CMMC roles on this page, 6 publish a salary range. Across those:

  • Median advertised midpoint: $146k
  • Middle half of the market: $125k to $168k
  • Full advertised range: $88k to $270k

Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.

Where the work is

  • Work mode: 2 remote, 1 hybrid, 11 on-site or unstated.
  • Seniority mix: senior (8), mid (5), executive (1)
  • Employers hiring more than one: True Anomaly (3)

Skills these postings ask for

  • board and committee reporting
  • policy lifecycle ownership
  • risk appetite and tolerance setting
  • three-lines-of-defence operating models
  • ISO/IEC 42001 and NIST AI RMF fluency

How to get a governance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.

Certifications that come up most

None of these are universally required, but they appear often enough in CMMC postings to be worth knowing: CGEIT, CRISC, AIGP, CISA. The certification academy covers what each one actually tests and who it is for.

Hiring for CMMC?

We have 14 open CMMC roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

New CMMC GRC jobs, the moment they post.

One click unsubscribe.