Skip to content
Aramis:Insight

Roles

CMMC Compliance Professional

You run CMMC compliance to the standard an assessor will hold it to: objectives, evidence, inherited controls, and closeout.

Competency areas

  • Cyber Resiliency (57)
  • Cryptography (39)
  • DevSecOps (38)
  • Artificial Intelligence (AI) Security (31)
Measure yourself against this role

Job description templates

Three ready-to-edit drafts for hiring managers and recruiters: copy one, replace the bracketed lines, and post it. Responsibilities and requirements are drawn from the same NICE statements this role is measured against.

Statements are shown in their official NICE Framework wording, which is maintained in English.

CMMC Compliance Professional: Junior

We are hiring a junior CMMC Compliance Professional. You will work under the guidance of senior colleagues, take ownership of well-scoped tasks, and grow into the full shape of the role. You run CMMC compliance to the standard an assessor will hold it to: objectives, evidence, inherited controls, and closeout.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Assess the effectiveness of security controls
  • Advise senior management on risk levels and security posture
  • Advise senior leadership and authorizing official of changes affecting the organization's cybersecurity posture
  • Recommend vulnerability remediation strategies
  • Determine if cybersecurity inspections, tests, and reviews are coordinated for the network environment
  • Determine impact of noncompliance on organizational risk levels
  • Determine impact of noncompliance on effectiveness of the enterprise's cybersecurity program
  • Establish Security Assessment and Authorization processes
  • Pair with senior colleagues and grow through structured feedback.
  • Document what you do so the team learns with you.

Required knowledge

  • Security Assessment and Authorization (SA&A) processes
  • Cybersecurity laws and regulations
  • Risk Management Framework (RMF) requirements
  • Supply chain risk management principles and practices
  • Risk scoring principles and practices
  • The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
  • Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
  • The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped

Skills

  • Creating technical documentation
  • Developing security assessments
  • Developing policy plans
  • Evaluating regulations
  • Verifying contractor compliance with contracts

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

CMMC Compliance Professional: Mid-level

We are hiring a CMMC Compliance Professional. You will own this work day to day, collaborate across the security function, and raise the bar on how it is done. You run CMMC compliance to the standard an assessor will hold it to: objectives, evidence, inherited controls, and closeout.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Assess the effectiveness of security controls
  • Advise senior management on risk levels and security posture
  • Advise senior leadership and authorizing official of changes affecting the organization's cybersecurity posture
  • Recommend vulnerability remediation strategies
  • Determine if cybersecurity inspections, tests, and reviews are coordinated for the network environment
  • Determine impact of noncompliance on organizational risk levels
  • Determine impact of noncompliance on effectiveness of the enterprise's cybersecurity program
  • Establish Security Assessment and Authorization processes
  • Develop computer environment cybersecurity plans and requirements
  • Perform security reviews
  • Develop a cybersecurity risk management plan
  • Recommend risk mitigation strategies

Required knowledge

  • Security Assessment and Authorization (SA&A) processes
  • Cybersecurity laws and regulations
  • Risk Management Framework (RMF) requirements
  • Supply chain risk management principles and practices
  • Risk scoring principles and practices
  • The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
  • Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
  • The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
  • SPRS: what is posted, by whom, when a score must be current for award, and how an affirmation is recorded
  • Conditional CMMC status, the 180-day closeout window, the closeout assessment, and the consequence of missing it
  • The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
  • The DFARS clauses that carry CMMC and NIST SP 800-171 obligations (252.204-7012, -7019, -7020, -7021) and what each requires of a contractor

Skills

  • Creating technical documentation
  • Developing security assessments
  • Developing policy plans
  • Evaluating regulations
  • Verifying contractor compliance with contracts
  • Conducting system reviews
  • Assessing security controls
  • Performing risk assessments

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

CMMC Compliance Professional: Senior

We are hiring a senior CMMC Compliance Professional. You will set the direction for this work, mentor others in it, and be accountable for its outcomes at the organizational level. You run CMMC compliance to the standard an assessor will hold it to: objectives, evidence, inherited controls, and closeout.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Assess the effectiveness of security controls
  • Advise senior management on risk levels and security posture
  • Advise senior leadership and authorizing official of changes affecting the organization's cybersecurity posture
  • Recommend vulnerability remediation strategies
  • Determine if cybersecurity inspections, tests, and reviews are coordinated for the network environment
  • Determine impact of noncompliance on organizational risk levels
  • Determine impact of noncompliance on effectiveness of the enterprise's cybersecurity program
  • Establish Security Assessment and Authorization processes
  • Develop computer environment cybersecurity plans and requirements
  • Perform security reviews
  • Develop a cybersecurity risk management plan
  • Recommend risk mitigation strategies
  • Advise on Risk Management Framework process activities and documentation
  • Report cybersecurity incidents
  • Implement protective or corrective measures when a cybersecurity incident or vulnerability is discovered
  • Update security documentation to reflect current application and system security design features
  • Mentor junior team members and review their work.
  • Represent this function to leadership and to auditors or clients.
  • Set standards, select tooling, and own the roadmap for this area.

Required knowledge

  • Security Assessment and Authorization (SA&A) processes
  • Cybersecurity laws and regulations
  • Risk Management Framework (RMF) requirements
  • Supply chain risk management principles and practices
  • Risk scoring principles and practices
  • The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
  • Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
  • The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
  • SPRS: what is posted, by whom, when a score must be current for award, and how an affirmation is recorded
  • Conditional CMMC status, the 180-day closeout window, the closeout assessment, and the consequence of missing it
  • The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
  • The DFARS clauses that carry CMMC and NIST SP 800-171 obligations (252.204-7012, -7019, -7020, -7021) and what each requires of a contractor
  • The annual affirmation: who may sign it, when it is due, what the affirming official attests to, and what follows a lapsed or false affirmation
  • The CMMC ecosystem's organizations and individual credentials, their authorities, and their limits (Cyber AB, CAICO, C3PAO, RPO, DIBCAC; RP, CCP, CCA, Lead CCA, CCI)

Skills

  • Creating technical documentation
  • Developing security assessments
  • Developing policy plans
  • Evaluating regulations
  • Verifying contractor compliance with contracts
  • Conducting system reviews
  • Assessing security controls
  • Performing risk assessments
  • Conducting test events
  • Applying security controls

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Related roles

Roles that share this one’s work or career stage. Each links to its own statements, sample questions, and job description templates.