Principal Analyst- IT Cyber Security; CMMC
Listed on 2026-01-16
-
IT/Tech
Cybersecurity
Are you looking for a unique opportunity to be a part of something great? Want to join a 17,000-member team that works on the technology that powers the world around us? Looking for an atmosphere of trust, empowerment, respect, diversity, and communication? How about an opportunity to own a piece of a multi‑billion dollar (with a B!) global organization? We offer all that and more at Microchip Technology Inc.
People come to work at Microchip because we help design the technology that runs the world. They stay because our culture supports their growth and stability. They are challenged and driven by an incredible array of products and solutions with unlimited career potential. Microchip's nationally‑recognized Leadership Passage Programs support career growth where we proudly enroll over a thousand people annually. We take pride in our commitment to employee development, values‑based decision making, and strong sense of community, driven by our Vision, Mission, and 11 Guiding Values;
we affectionately refer to it as the Aggregate System and it has earned us countless awards for diversity and workplace excellence.
Our company is built by dedicated team players who love to challenge the status quo; we did not achieve record revenue and over 30 years of quarterly profitability without a great team dedicated to empowering innovation. People like you.
Visit our careers page to see what exciting opportunities and company perks await!
Job Description:
We are seeking an experienced, highly skilled Principal CMMC Analyst to join our security team and lead enterprise‑wide compliance initiatives. This role delivers strategic leadership, technical expertise, and authoritative regulatory interpretation to ensure adherence to CMMC requirements, NIST SP 800‑171, DFARS, and other applicable federal cybersecurity standards.
The Principal CMMC Analyst works in close collaboration with management, engineering teams, and internal and external stakeholders to evaluate cybersecurity maturity, identify and mitigate risk, and build scalable, sustainable compliance programs. This position is instrumental in strengthening the organization's cybersecurity posture and ensuring full readiness for formal CMMC assessments in support of mission‑critical programs.
ResponsibilitiesSupport and help guide activities related to CMMC compliance and overall certification strategy
Assist in the management, implementation, and validation of security controls in compliance with CMMC, NIST SP 800‑171, and/or DFARS requirements
Provide expert guidance and authoritative input on CMMC, NIST SP 800‑171, DFARS, and related DoD cybersecurity requirements
Oversee the development and maintenance of System Security Plans (SSPs), POA&Ms, policies, procedures, and security control documentation
Conduct and oversee CMMC readiness assessments, gap analysis, and internal/external audits
Coordinate with internal stakeholders to remediate identified gaps
Partner with IT, Cybersecurity, Legal, and Engineering teams to ensure compliance across systems handling CUI
Advise leadership on risk posture, compliance status, and remediation priorities
Support customer and government inquiries related to cybersecurity compliance
Serve as the primary liaison with external auditors, consultants, and CMMC Third‑Party Assessment Organizations (C3
PAOs)Provide technical leadership and mentorship across the enterprise
Develop internal training and guidance on CUI handling and CMMC requirements
Promote a culture of security awareness aligned with Microchipаре guiding values
Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field
10+ years of cybersecurity, GRC, or compliance experience
5+ years working સુંદર directly with compliance frameworks (NIST SP 800‑171) and DoD compliance programs
Hands‑on experience applying CMMC and NIST frameworks to assess, implement, and govern cybersecurity controls across complex environments.
Experience authoring, reviewing, and governing enterprise‑level compliance documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and other various support…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).