Remote Jobs RockRemote Jobs Rock

CMMC Security Engineer

πŸ•’ 7 days ago
CMMC 2.0 FrameworkNIST SP 800-171DFARS RequirementsVulnerability Management

πŸ“œ Description

  • Design, implement, and monitor security controls aligned with CMMC requirements, including access controls, encryption, endpoint protection, and secure configurations.
  • Lead vulnerability assessments, scan remediation tracking, and continuous risk management across hybrid and cloud environments.
  • Support incident response, threat hunting, and forensic analysis for cybersecurity events.
  • Prepare for and facilitate CMMC assessments (self and third-party), maintain certification documentation (SSP, POA&M), and address audit findings.
  • Collaborate with compliance managers, legal/data protection officers, and operations teams to ensure continuous alignment with NIST SP 800-171/DFARS controls.
  • Oversee CMMC continuous monitoring programs and identify compliance gaps in workflows.

πŸ› οΈ Requirements

  • Deep understanding of CMMC 2.0 framework, NIST SP 800-171, and DFARS requirements.
  • Experience conducting technical assessments, vulnerability management, and implementing FedRAMP Moderate or equivalent systems for CUI.
  • Strong documentation skills for policies, procedures, and audit support.
  • Ability to communicate technical findings to both technical and non-technical stakeholders.
  • Knowledge of cloud (e.g., Azure, Microsoft 365) and on-premise security technologies.
  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • Professional certifications such as CISSP, CISM, GIAC, or CCA/CCP (CMMC-specific certifications preferred).
  • Experience supporting DoD compliance or federal contracts is highly valued.
Full job description

We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and leading cybersecurity efforts to ensure compliance with the Cybersecurity Maturity Model Certification (CMMC) standards, focusing on protecting Controlled Unclassified Information (CUI) for organizations in the Defense Industrial Base (DIB).

Key Responsibilities

  • Design, implement, and monitor security controls aligned with CMMC requirements, including access controls, encryption, endpoint protection, and secure configurations.
  • Lead vulnerability assessments, scan remediation tracking, and continuous risk management across hybrid and cloud environments.
  • Support incident response, threat hunting, and forensic analysis for cybersecurity events.
  • Prepare for and facilitate CMMC assessments (self and third-party), maintain certification documentation (SSP, POA&M), and address audit findings.
  • Collaborate with compliance managers, legal/data protection officers, and operations teams to ensure continuous alignment with NIST SP 800-171/DFARS controls.
  • Oversee CMMC continuous monitoring programs and identify compliance gaps in workflows.
  • Provide security awareness training and promote a culture of cybersecurity vigilance across departments.

Required Skills

  • Deep understanding of CMMC 2.0 framework, NIST SP 800-171, and DFARS requirements.
  • Experience conducting technical assessments, vulnerability management, and implementing FedRAMP Moderate or equivalent systems for CUI.
  • Strong documentation skills for policies, procedures, and audit support.
  • Ability to communicate technical findings to both technical and non-technical stakeholders.
  • Knowledge of cloud (e.g., Azure, Microsoft 365) and on-premise security technologies.

Typical Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • Professional certifications such as CISSP, CISM, GIAC, or CCA/CCP (CMMC-specific certifications preferred).
  • Experience supporting DoD compliance or federal contracts is highly valued.

Job Purpose

The role ensures a secure and compliant enclave for CUI, mitigates cybersecurity risks, leads compliance projects, and prepares for third-party assessments and audits under the evolving CMMC 2.0 regulations.

Social-Discovery-Ventures

Infrastructure Security Engineer

Social-Discovery-VenturesπŸ‘₯ 501 - 1000 employees🏒 Computer Software
πŸ•’ 3 days ago

As an Infrastructure Security Engineer, you will design and maintain security architectures, manage vulnerabilities, and coordinate incident responses to enhance the organization's security posture.

Cloudflare Zero TrustVulnerability ManagementEndpoint ProtectionNetwork Segmentation
Accela

Cybersecurity Engineer

AccelaπŸ‘₯ 201 - 500 employees🏒 Computer Software
πŸ•’ 8 days ago

The Cybersecurity Engineer independently executes security engineering and operational tasks across endpoints, identities, and cloud platforms, enhancing technical safeguards and business continuity.

CybersecurityEndpoint SecurityIdentity And Access ManagementSecurity Operations
Coinbase

Product Security Engineer

CoinbaseπŸ‘₯ 10,000+ employees🏒 Financial Services
πŸ•’ 15 days ago

As an Offensive Security Engineer, you'll leverage AI models to enhance vulnerability discovery, lead red teaming efforts, and automate security workflows at Coinbase.

Application SecurityPenetration TestingOffensive SecurityAI Models
Affinipay1

Information Security Engineer

Affinipay1πŸ‘₯ 501 - 1000 employees
πŸ•’ 15 days ago

The Information Security Engineer is responsible for ensuring the security and integrity of systems, focusing on cloud security operations, detection engineering, incident response, and data protection.

AWS SecurityIncident ResponseDetection EngineeringVulnerability Management

Trusted by Remote Workers