Senior CMMC Compliance Consultant

Systems Engineering IncPortland, ME
$110,000 - $125,000Hybrid

About The Position

Systems Engineering has immediate availability for a Senior CMMC Compliance Consultant to join our growing Advisory Services team in Portland, Maine. This role leads clients through CMMC readiness, from initial scoping and CUI boundary definition through NIST SP 800-171 gap analysis, remediation planning, evidence development, and assessment preparation. While CMMC is a primary focus, the GRC consulting role supports clients across multiple industries, regulatory requirements, and cybersecurity frameworks. The Senior CMMC Compliance Consultant serves as a trusted advisor to client executives and technical teams, helping them translate compliance requirements into practical security improvements while providing leadership, coaching, and quality oversight to the broader consulting team. This is a hybrid role, which includes a mix of remote & onsite work at our Portland, Maine office as well as onsite client engagements which may require occasional travel.

Requirements

  • BS or similar degree with 8+ years of progressively responsible experience. Applicants without a degree may substitute additional experience, especially in leadership roles (10+ years expected).
  • Demonstrated experience leading CMMC or NIST SP 800-171 readiness engagements, including scope definition, gap assessment, remediation planning, evidence review, and preparation for an external assessment.
  • CMMC Certified Professional, CMMC Certified Assessor, CISSP, CISA, CRISC, or a comparable security or compliance certification is strongly preferred. Candidates without a current credential should demonstrate equivalent CMMC and NIST SP 800-171 experience and be willing to obtain an agreed certification after hire.
  • Strong working knowledge of CMMC, NIST SP 800-171, common CUI environments, identity and access management, endpoint security, network security, logging and monitoring, vulnerability management, incident response, backup and recovery, and cloud security.
  • Experience evaluating Microsoft 365, Azure, and related security configurations is strongly preferred.
  • Consulting experience strongly preferred.
  • Ability to distil complex technical information into broadly comprehensible concepts, and vice versa.
  • Must be an excellent written and oral communicator.
  • Meet hybrid work requirements - ability to work onsite at our Portland, Maine office and travel occasionally for onsite client engagements.
  • Reliable transportation is required.
  • Candidates must be U.S. citizens or lawful permanent residents and be willing to undergo a thorough background check as part of the employment process.

Nice To Haves

  • Experience with HIPAA, GLBA, PCI, GDPR and NIST compliance is a plus.
  • Project management experience preferred.
  • Passion for security, governance, compliance, and risk required!

Responsibilities

  • Lead CMMC scoping, readiness, and NIST SP 800-171 gap assessments by identifying FCI and CUI, evaluating data flows, defining the assessment boundary, and documenting in-scope people, processes, technologies, facilities, and external service providers.
  • Develop and maintain assessment-ready deliverables, including System Security Plans, policies, procedures, control narratives, Plans of Action and Milestones, boundary and data-flow documentation, and supporting evidence, while clearly communicating findings and risk to technical and executive stakeholders.
  • Information security program development and oversight.
  • Utilizing Governance, Risk, and Compliance (GRC) tools to track and communicate compliance program status.
  • Participation or leadership on client security committees.
  • Community and industry thought leadership.
  • Internal organizational leadership.
  • Technology compliance consultants work with clients to ensure technology, compliance, and security are expertly managed through organizational policies, strategic IT planning, and at times taking ownership over roadmap execution.
  • Lead clients through the development of security documentation, policies, and operating practices by facilitating decisions, establishing ownership, and coordinating work across client stakeholders and internal cross-functional teams, from operational staff to C-suite leaders.
  • Direct the NIST 800-171 implementation process by confirming FCI and CUI flows, establishing the system boundary, and ensuring all relevant personnel, processes, technologies, facilities, and external service providers are accurately represented.
  • Translate identified gaps into practical solution options, recommend an appropriate path forward, and coordinate with the technical resources responsible for implementation.
  • Lead GRC consulting engagements across multiple industries and regulatory environments.
  • Develop and maintain information security, business continuity, cybersecurity workforce, and compliance programs; facilitate the creation and maintenance of business continuity plans and risk assessments; and identify gaps against applicable frameworks and client requirements.
  • Provide strategic CISO-level consultation to clients.
  • Work independently with clients to ensure an appropriate technology and security posture is developed and maintained.
  • Assemble, analyze, and deliver comprehensive IT risk assessments documenting “State of the State” for clients and making appropriate recommendations.
  • Provide guidance and context in prioritizing and determining complexity of cultural and technological problems.
  • Oversee remediation planning by defining required security and business continuity outcomes, evaluating proposed solutions, communicating residual risk, and confirming that completed work is supported by appropriate documentation and evidence.
  • Provide internal training and mentorship.

Benefits

  • Competitive medical, dental, & vision benefits
  • employer-paid life, short-term, and long-term disability insurance
  • 24/7 Employee Assistance Program (EAP)
  • onsite fitness facilities
  • wellness programs
  • Employer 401k matching contributions
  • short-term incentive plans (STIP)
  • free financial advising
  • Paid Time Off starting with 17 days PTO
  • nine paid holidays
  • hybrid work arrangements
  • Paid parental leave
  • dependent care FSA programs
  • Career mobility and professional development
  • employer-supported training, learning, and certification opportunities
  • tuition reimbursement benefits
  • Paid community volunteer time
  • employer-charitable match programs
  • corporate golf membership
  • company-provided season tickets to local sports teams
  • employer provided parking
  • regular company gatherings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service