CMMC Advisory Consultant
Listed on 2026-03-12
-
IT/Tech
Cybersecurity, IT Consultant
Fortreum is a trusted leader in cloud and cybersecurity services, ranked in the Top 5 FedRAMP Third Party Assessment Organizations (3
PAO). We provide independent, third‑party and vendor‑agnostic regulatory assessment and advisory services, coupled with advanced cybersecurity offensive and compliance technical services to our clients. Our comprehensive service portfolio includes regulatory compliance (FedRAMP, FISMA, SOC, ISO, HIPAA, CMMC, PCI) and technical security services (Penetration Testing, Red Teaming, Social Engineering, Attack Surface Analysis and others).
Working with Fortune 500 companies and leading cloud service providers, we've built our reputation on our service‑delivery excellence and unwavering commitment to client success. Our rapid growth creates exceptional opportunities for driven professionals to make their mark in the cybersecurity industry with a focus on our core values:
- Quality matters most
- Customer‑driven mindset
- Autonomy to do your job
- Personal accountability/stewardship
On our team, you will have the opportunity to work with the best and brightest in the field. Fortreum team members have supported the biggest cloud providers in the world, and you will have the opportunity to work with the best.
We are growing rapidly and are looking for candidates with a background in preparing organizations for security assessments in support of CMMC, FedRAMP and NIST‑based frameworks to support our growing customer base.
Key Responsibilities- Conducting interviews of key stakeholders and technical personnel.
- Perform scoping exercises to determine client enterprise or enclave boundaries.
- Develop documentation for client use, such as System Security Plan (SSP), NIST 800‑171 policies, and other associated plans.
- Collaborate with delivery team members to drive customer satisfaction and meet project deliverables.
- Ensure quality products and services are delivered on time and within allotted hours.
- Establish and maintain positive collaborative relationships with clients and stakeholders.
- Continuous professional development in pursuing industry‑specific certifications.
- Prepare deliverables and conduct peer review of team member’s deliverables.
- Perform project out‑briefs with clients to notify them of the outcome of their compliance activities.
- Manage priorities, tasks, and assigned hours on projects to achieve delivery utilization targets.
This is a customer facing role. Travel is expected to be limited in nature; however, you may be required to travel to client locations and deliver professional services.
Basic Qualifications- Bachelor’s Degree or equivalent job experience
- 3+ years of professional services experience
- 2+ years of experience leveraging NIST SP 800‑171
- Proficient in Microsoft 365 product suite
- CMMC Registered Practitioner (RP)
- Ability to quickly take on new technologies and concepts
- Ability to manage multiple priorities simultaneously
- Proven analytical and problem‑solving skills
- Ability to develop and maintain strong relationships with team members and clients
- Comfortable supporting fast‑paced team environments
- Advanced technical certifications, such as: AWS solutions architect, Google Cloud Engineer, Microsoft solutions architect
- Preferred certifications:
- CMMC CCA
- Certified Information Security Manager (CISM)
- Federal IT Security Professional Auditor (FITSP‑A)
- GIAC Cloud Security Automation (GCSA)
- Cybersecurity Analyst (CySA+)
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Security Officer (CISSO)
Posted Salary Range: $120,000 - $150,000 annual salary
What Fortreum OffersWe offer a competitive compensation package, where you will be rewarded based on your performance/outcomes and recognized for the value you bring to our business. You will be a part of something special as we continue to grow. The founders have a proven track record of successful company acquisitions/exit of both small and mid‑market cybersecurity organizations. Our benefits package includes medical insurance, dental insurance, vision insurance, company‑paid short‑term disability, company‑paid long‑term disability, company‑paid AD&D and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).