Information Security Compliance Manager
Core
Primary technical authority on the Cybersecurity Maturity Model Certification (CMMC) framework, leading cross-functional compliance efforts to sustain and expand certification across the enterprise.
Role type
Information Security Compliance Manager
Builds
CMMC Level 2 and future Level 3 certification posture for industrial and engineering businesses
Domain
Defense contracting, cybersecurity compliance, NIST SP 800-171/800-172, ITAR/EAR
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
CMMC framework expertise, NIST SP 800-171 implementation, ITAR/EAR regulatory knowledge, gap analysis, control validation, policy development, risk assessment, audit readiness, stakeholder coordination
Preferred skills
CCA or CCP training, GRC platform proficiency, project management
Technologies
GRC platforms, compliance tracking tools, project management tools
Responsibilities
Lead detailed gap analyses across technical, administrative, and physical controls; Translate CMMC practices into actionable technical requirements for IT, Engineering, Manufacturing, Security, HR, and other teams; Guide and validate implementation of required controls; Support CUI scoping activities including asset inventory validation, boundary definition, and data flow mapping; Develop and implement compliance policies, procedures, and standards; Coordinate with IT, Legal, HR, and business units to ensure compliance requirements are understood and completed; Lead the creation, refinement, and maintenance of compliance documentation including SSPs, POA&Ms, ConMon materials, policies, procedures, and evidence artifacts; Establish and implement structured evidence collection and artifact management processes; Perform internal readiness assessments, mock audits, and control testing; Collaborate with assessors to support readiness and certification activities; Conduct risk assessments and provide recommendations to mitigate cybersecurity and compliance risks; Assess and report progress toward compliance objectives; Advise leadership on compliance risks, technical challenges, and factors impacting certification timelines; Generate reports for cybersecurity leadership and contribute to executive level updates; Provide formal and ad-hoc guidance and training to employees on cybersecurity compliance matters; Represent the security function in meetings, planning sessions, and cross-functional initiatives
Seniority
Senior, hands-on IC