CMMC Program Manager

Balfour Beatty CommunitiesDallas, TX
Hybrid

About The Position

Balfour Beatty Construction, LLC is seeking a CMMC Program Manager to ensure compliance with cybersecurity and physical security requirements for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on federal contracts, as well as similar requirements in private contracts. The role requires a strong understanding of FAR and DFARS, excellent project management, analytical, communication, and organizational skills. This is a hybrid position, ideally based in Falls Church, VA, though Dallas, TX candidates will be considered. The CMMC Program Manager will oversee the organization's Cybersecurity Maturity Model Certification (CMMC) compliance program for the secure enclave supporting Department of Defense (DoD) and other Federal agency CUI, and the company's policies for handling FCI. This role serves as the main point of contact for compliance & ethics, IT, legal, and operations regarding governance, reporting, monitoring, assessment, and adoption of security requirements necessary for NIST SP 800-171, NIST SP 800-137, FAR and DFARS, and CMMC Level 1 and Level 2 compliance.

Requirements

  • This position requires access to export-controlled information. To comply with U.S. government regulations and contract obligations applicable so such information, all applicants must be U.S. persons under the U.S. export control regulations.
  • Bachelor’s degree in Risk Management, Compliance and Regulation, Information Security, Information Systems, or a related field. Equivalent experience working within a Department of Defense agency will also be considered.
  • 7+ years in cybersecurity, governance, risk management, compliance, or information security, including at least 3 years supporting NIST SP 800-171 related programs.
  • Hands-on experience with NIST SP 800-137 implementation or continuous monitoring frameworks.
  • Familiarity with NIST SP 800-171, CMMC Level 1 and 2, and FAR and DFARS.
  • Demonstrated experience developing or managing System Security Plans (SSP) and POA&Ms.
  • Strong analytical, documentation, and executive-reporting skills.
  • Ability to coordinate cross-functional teams and enforce accountability.
  • Complete FSO training within 6 months of hire if not already completed.
  • Complete ITPSO training.

Nice To Haves

  • Experience supporting Department of Defense, Federal Government, or other regulated markets with significant information security requirements.
  • CMMC: Certified CMMC Professional (CCP) or Certified CMMC Assessor (CCA) or CMMC Registered Practitioner Advanced (RPA)
  • Cyber security: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Security+ or CySA+
  • Experience operating in secure enclave or DoD contractor environments.

Responsibilities

  • Serve as the organization's primary internal authority for CMMC compliance within the secure enclave, providing guidance to IT, IT Security, Operations, Human Resources, Legal, Procurement, Communications and executive leadership regarding FCI, CUI and equivalent compliance obligations and governance requirements.
  • Own the organization's CMMC compliance program for the secure enclave, ensuring governance activities remain aligned with organizational objectives, contractual obligations, regulatory requirements, and evolving cybersecurity risks.
  • Develop, maintain, and periodically review the Continuous Monitoring Plan (CMP) and support ISCM procedures.
  • Develop, review, maintain, and coordinate approval of CMMC-related policies, standards, procedures, and supporting documentation.
  • Define and manage ISCM strategy, risk tolerance, and reporting cadence in coordination with the CIO, CISO, CLO, and US Compliance Team.
  • Lead initial implementation, as well as ongoing assessment of security control effectiveness, including vulnerability identification and reporting, configuration compliance, access reviews, and incident monitoring.
  • Lead annual CMMC self-assessments, risk assessments, internal audits, certification readiness activities, and coordination with Certified Third-Party Assessment Organizations (C3PAOs) for external CMMC assessments, as applicable.
  • Present compliance status, risk posture, and strategic recommendations to executive leadership and governance committees.
  • Develop and maintain evidence repositories supporting ongoing internal assessments, external certification activities, and audit readiness.
  • Ensure compliance documentation—including the System Security Plan (SSP), POA&Ms, policies, procedures, system inventories, data flow diagrams, asset inventories, evidence repositories, and assessment records—remains complete, accurate, and current.
  • Track, report, coordinate, and validate remediation of deviations, exceptions, and findings discovered during monitoring or risk assessments.
  • Prepare metrics dashboards and executive reports summarizing enclave risk posture and compliance trends.
  • Coordinate compliance activities involving third-party service providers supporting the enclave, including review of agreements, security documentation, and shared responsibility requirements.
  • Review proposed changes to enclave architecture, systems, applications, and operational processes to evaluate potential impacts to CMMC compliance and update compliance documentation as necessary.
  • Coordinate with IT Operations and IT Security teams to ensure configuration baselines, asset inventories, and system changes remain aligned with approved security configurations and compliance requirements.
  • Coordinate or participate in periodic incident response tabletop exercises involving IT, Legal, Human Resources, Executive Leadership, and applicable business stakeholders.
  • Collect evidence management, control documentation, and audit preparation.
  • Coordinate post-incident reviews, track corrective actions, and ensure lessons learned are incorporated into security controls, policies, procedures, training, and continuous monitoring activities to improve the organization's overall CMMC compliance posture.
  • Collaborate with internal stakeholders: Business Stakeholders: program managers, project managers, and functional owners using enclave resources. Assist with onboarding, offboarding and transfers as needed.
  • Internal and secure enclave MSSP and IT Security Teams: administrators, network engineers, and analysts managing enclave systems and monitoring tools.
  • Policy and Procedure Enforcement: detect and document deviations or non-compliance, collaborate with HR and/or Legal to resolve violations, and ensure corrective or disciplinary actions are applied and recorded in accordance with organizational policy and audit requirements.
  • CMMC Training Program Management: review, develop, and adjust security awareness or role-based training content to ensure alignment with current government, DOD, and CMMC requirements and to address evolving cyber security and enclave operational risks.
  • Executive Leadership: provide compliance reporting, risk briefings, POA&M status, and recommendations for risk acceptance decisions.
  • Familiarity with export control requirements such as International Traffic in Arms Regulations and Export Administration Regulations.
  • Continuously review and improve ISCM processes, automation, and reporting frequency to align with organizational risk tolerance.
  • Facilitate risk assessments and coordinate risk acceptance activities with executive leadership where appropriate.
  • Supervise and direct security measures necessary for implementing the applicable requirements of the NISPOM and related USG security requirements to ensure the protection of classified information.
  • Establish and execute an insider threat program to gather, integrate, and report relevant and available information indicative of potential or actual insider threat.
  • Support broader Ethics & Compliance initiatives, including performing other ethics, compliance, and special projects as assigned by the Vice President, Ethics & Compliance and as workload and business needs permit.

Benefits

  • Health insurance
  • Dental insurance
  • Vision insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service