About the Role
OCT Consulting is seeking a highly skilled and detail-oriented Certified CMMC Assessor (CCA) to join our growing team. As a vital member of our CMMC Certified Third-Party Assessment Organization (C3PAO) practice, you will work under the guidance of a Lead Assessor to conduct rigorous Level 2 certification assessments for organizations within the Defense Industrial Base. This is a unique opportunity to apply your technical expertise in cybersecurity and regulatory compliance to ensure the security of sensitive federal information and support the build-out of a high-impact consulting service.
Key ResponsibilitiesYour primary objective will be to execute the CMMC Level 2 certification assessment process with precision and integrity. You will play a hands-on role in evaluating client environments to ensure they meet the stringent requirements necessary for federal contracting eligibility.
- Conduct formal CMMC Level 2 certification assessment activities as a core member of the assessment team, following the direction of the Lead Certified CMMC Assessor (LCCA).
- Perform comprehensive examinations of security documentation and technical artifacts to verify compliance with the 110 NIST SP 800-171 Rev 2 requirements.
- Engage with client personnel through professional interviews and technical testing of security controls using NIST SP 800-171A assessment methods.
- Thoroughly document all findings and provide expert recommendations for MET, NOT MET, or NOT APPLICABLE determinations, ensuring all conclusions are backed by objective evidence.
- Contribute to the strategic development of assessment plans, including scope validation and conducting pre-assessment readiness reviews for clients.
- Assist in the generation of official assessment reports and monitor the progress of Plan of Action and Milestones (POA&M) closeout activities.
- Maintain meticulous records of assessment evidence and working papers in strict adherence to C3PAO internal procedures and ISO/IEC 17020:2012 standards.
- Uphold the highest standards of professional ethics by adhering to the Cyber AB Code of Professional Conduct, maintaining impartiality, and avoiding conflicts of interest at all times.
To be successful in this role, candidates must possess a deep understanding of cybersecurity frameworks and the ability to operate within a highly regulated environment. We require professionals who are analytical, communicative, and technically proficient.
- U.S. Citizenship: Mandatory requirement for all personnel participating in the CMMC Level 2 certification process due to background investigation requirements.
- Certification: Must hold an active Certified CMMC Assessor (CCA) certification in good standing with the Cyber AB.
- Background Investigation: Ability to obtain and maintain a favorable Tier 3 background investigation resulting in national security eligibility determination (includes credit, fingerprint, and law enforcement checks).
- Education: Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field, or equivalent professional experience.
- Experience: Typically 4+ years of professional experience in cybersecurity or information assurance, specifically involving NIST SP 800-171 or CMMC frameworks.
- Technical Knowledge: Advanced working knowledge of NIST SP 800-171 Rev 2, NIST SP 800-171A, 32 CFR Part 170, and DFARS 252.204-7012.
- Preferred Credentials: Additional industry certifications such as CISSP, CISA, CompTIA Security+, or CMMC Certified Professional (CCP) are highly desirable.
- Skills: Exceptional analytical capabilities, strong technical writing skills for documentation, and the ability to communicate complex compliance requirements to various stakeholders.
OCT Consulting is dedicated to fostering a work environment where individual merit is recognized and rewarded. We offer a competitive package designed to support the professional growth and well-being of our team members.
- Competitive hourly compensation ranging from $35.00 to $50.00, commensurate with your level of experience and education.
- Flexible work arrangements, offering this role as either a part-time or full-time opportunity based on candidate preference and business needs.
- The agility of a small business culture combined with the stability of a management team that has a proven track record with major federal agencies.
- Opportunities for career advancement and professional development within our expanding C3PAO practice.
- A remote-eligible work environment with travel support provided for required on-site client assessment activities.
- An inclusive workplace culture that values diversity, integrity, and proactive problem-solving.