CMMC Assessor
You decide, on evidence, whether an organization meets CMMC, and say so in a form the Department can rely on.
Competency areas
- Cyber Resiliency (43)
- Cryptography (36)
- DevSecOps (32)
- Artificial Intelligence (AI) Security (24)
Job description templates
Three ready-to-edit drafts for hiring managers and recruiters: copy one, replace the bracketed lines, and post it. Responsibilities and requirements are drawn from the same NICE statements this role is measured against.
Statements are shown in their official NICE Framework wording, which is maintained in English.
CMMC Assessor: Junior
We are hiring a junior CMMC Assessor. You will work under the guidance of senior colleagues, take ownership of well-scoped tasks, and grow into the full shape of the role. You decide, on evidence, whether an organization meets CMMC, and say so in a form the Department can rely on.
[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.
Responsibilities
- Assess the effectiveness of security controls
- Scope analysis reports to various audiences that accounts for data sharing classification restrictions
- Perform security reviews
- Plan security authorization reviews for system and network installations
- Conduct security authorization reviews for system and network installations
- Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
- Conduct technology program and project audits
- Document software, network, and system deviations from implemented security postures
- Pair with senior colleagues and grow through structured feedback.
- Document what you do so the team learns with you.
Required knowledge
- Security Assessment and Authorization (SA&A) processes
- Risk Management Framework (RMF) requirements
- Supply chain risk management principles and practices
- Process maturity models and frameworks
- The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
- Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
- The C3PAO's quality assurance review, results submission to the CMMC instantiation of eMASS, and the organization's appeal path
- The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
Skills
- Evaluating regulations
- Creating technical documentation
- Preparing reports
- Auditing technical systems
- Reviewing logs
How to use this template
Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.
CMMC Assessor: Mid-level
We are hiring a CMMC Assessor. You will own this work day to day, collaborate across the security function, and raise the bar on how it is done. You decide, on evidence, whether an organization meets CMMC, and say so in a form the Department can rely on.
[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.
Responsibilities
- Assess the effectiveness of security controls
- Scope analysis reports to various audiences that accounts for data sharing classification restrictions
- Perform security reviews
- Plan security authorization reviews for system and network installations
- Conduct security authorization reviews for system and network installations
- Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
- Conduct technology program and project audits
- Document software, network, and system deviations from implemented security postures
- Determine if procurement activities sufficiently address supply chain risks
- Determine if vulnerability remediation plans are in place
- Develop independent cybersecurity audit processes for application software, networks, and systems
- Implement independent cybersecurity audit processes for application software, networks, and systems
Required knowledge
- Security Assessment and Authorization (SA&A) processes
- Risk Management Framework (RMF) requirements
- Supply chain risk management principles and practices
- Process maturity models and frameworks
- The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
- Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
- The C3PAO's quality assurance review, results submission to the CMMC instantiation of eMASS, and the organization's appeal path
- The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
- Conditional CMMC status, the 180-day closeout window, the closeout assessment, and the consequence of missing it
- The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
- The CMMC ecosystem's organizations and individual credentials, their authorities, and their limits (Cyber AB, CAICO, C3PAO, RPO, DIBCAC; RP, CCP, CCA, Lead CCA, CCI)
- The difference between NIST SP 800-171 Rev 2 as pinned by the DoD class deviation and Rev 3 as published, and why an assessment is conducted against the pinned revision
Skills
- Evaluating regulations
- Creating technical documentation
- Preparing reports
- Auditing technical systems
- Reviewing logs
- Conducting system reviews
- Assessing security controls
- Performing risk assessments
How to use this template
Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.
CMMC Assessor: Senior
We are hiring a senior CMMC Assessor. You will set the direction for this work, mentor others in it, and be accountable for its outcomes at the organizational level. You decide, on evidence, whether an organization meets CMMC, and say so in a form the Department can rely on.
[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.
Responsibilities
- Assess the effectiveness of security controls
- Scope analysis reports to various audiences that accounts for data sharing classification restrictions
- Perform security reviews
- Plan security authorization reviews for system and network installations
- Conduct security authorization reviews for system and network installations
- Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
- Conduct technology program and project audits
- Document software, network, and system deviations from implemented security postures
- Determine if procurement activities sufficiently address supply chain risks
- Determine if vulnerability remediation plans are in place
- Develop independent cybersecurity audit processes for application software, networks, and systems
- Implement independent cybersecurity audit processes for application software, networks, and systems
- Determine if cybersecurity requirements included in contracts are delivered
- Design and execute a control test that distinguishes a design deficiency from an operating-effectiveness deficiency
- Construct an audit workpaper documenting population, sample selection, test steps performed, and results
- Write an audit finding that states condition, criteria, cause, and effect with an actionable recommendation
- Mentor junior team members and review their work.
- Represent this function to leadership and to auditors or clients.
- Set standards, select tooling, and own the roadmap for this area.
Required knowledge
- Security Assessment and Authorization (SA&A) processes
- Risk Management Framework (RMF) requirements
- Supply chain risk management principles and practices
- Process maturity models and frameworks
- The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
- Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
- The C3PAO's quality assurance review, results submission to the CMMC instantiation of eMASS, and the organization's appeal path
- The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
- Conditional CMMC status, the 180-day closeout window, the closeout assessment, and the consequence of missing it
- The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
- The CMMC ecosystem's organizations and individual credentials, their authorities, and their limits (Cyber AB, CAICO, C3PAO, RPO, DIBCAC; RP, CCP, CCA, Lead CCA, CCI)
- The difference between NIST SP 800-171 Rev 2 as pinned by the DoD class deviation and Rev 3 as published, and why an assessment is conducted against the pinned revision
- The assessment objectives of NIST SP 800-171A and how each decomposes its requirement
- The examine, interview, and test assessment methods, and the depth and coverage each provides
Skills
- Evaluating regulations
- Creating technical documentation
- Preparing reports
- Auditing technical systems
- Reviewing logs
- Conducting system reviews
- Assessing security controls
- Performing risk assessments
- Producing after-action reports
- Conducting test events
How to use this template
Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.
Related roles
Roles that share this one’s work or career stage. Each links to its own statements, sample questions, and job description templates.