Skip to content
Aramis:Insight

Roles

CMMC Readiness Practitioner

You take a defense supplier from a DFARS clause to an honest self-assessment, a signed affirmation, and assessment readiness.

Competency areas

  • Cyber Resiliency (55)
  • Cryptography (39)
  • DevSecOps (37)
  • Artificial Intelligence (AI) Security (31)
Measure yourself against this role

Job description templates

Three ready-to-edit drafts for hiring managers and recruiters: copy one, replace the bracketed lines, and post it. Responsibilities and requirements are drawn from the same NICE statements this role is measured against.

Statements are shown in their official NICE Framework wording, which is maintained in English.

CMMC Readiness Practitioner: Junior

We are hiring a junior CMMC Readiness Practitioner. You will work under the guidance of senior colleagues, take ownership of well-scoped tasks, and grow into the full shape of the role. You take a defense supplier from a DFARS clause to an honest self-assessment, a signed affirmation, and assessment readiness.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Collect and maintain system cybersecurity report data
  • Create system cybersecurity reports
  • Determine impact of noncompliance on organizational risk levels
  • Develop computer environment cybersecurity plans and requirements
  • Recommend risk mitigation strategies
  • Report cybersecurity incidents
  • Develop cybersecurity policy recommendations
  • Update security documentation to reflect current application and system security design features
  • Pair with senior colleagues and grow through structured feedback.
  • Document what you do so the team learns with you.

Required knowledge

  • Cybersecurity laws and regulations
  • Authentication and authorization tools and techniques
  • Risk Management Framework (RMF) requirements
  • Risk tolerance principles and practices
  • Industry cybersecurity models and frameworks
  • Organizational policy and procedures
  • Risk mitigation principles and practices
  • The Registered Practitioner's and Registered Provider Organization's obligations under the Cyber AB's programs, including the Code of Professional Conduct

Skills

  • Applying security controls
  • Developing policy plans
  • Verifying contractor compliance with contracts
  • Creating policies that reflect legal, regulatory, and organizational requirements
  • Maintaining planning documents

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

CMMC Readiness Practitioner: Mid-level

We are hiring a CMMC Readiness Practitioner. You will own this work day to day, collaborate across the security function, and raise the bar on how it is done. You take a defense supplier from a DFARS clause to an honest self-assessment, a signed affirmation, and assessment readiness.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Collect and maintain system cybersecurity report data
  • Create system cybersecurity reports
  • Determine impact of noncompliance on organizational risk levels
  • Develop computer environment cybersecurity plans and requirements
  • Recommend risk mitigation strategies
  • Report cybersecurity incidents
  • Develop cybersecurity policy recommendations
  • Update security documentation to reflect current application and system security design features
  • Document software, network, and system deviations from implemented security postures
  • Develop cybersecurity compliance processes for external services
  • Develop cybersecurity audit processes for external services
  • Determine if procurement activities sufficiently address supply chain risks

Required knowledge

  • Cybersecurity laws and regulations
  • Authentication and authorization tools and techniques
  • Risk Management Framework (RMF) requirements
  • Risk tolerance principles and practices
  • Industry cybersecurity models and frameworks
  • Organizational policy and procedures
  • Risk mitigation principles and practices
  • The Registered Practitioner's and Registered Provider Organization's obligations under the Cyber AB's programs, including the Code of Professional Conduct
  • SPRS: what is posted, by whom, when a score must be current for award, and how an affirmation is recorded
  • The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
  • The DFARS clauses that carry CMMC and NIST SP 800-171 obligations (252.204-7012, -7019, -7020, -7021) and what each requires of a contractor
  • The annual affirmation: who may sign it, when it is due, what the affirming official attests to, and what follows a lapsed or false affirmation

Skills

  • Applying security controls
  • Developing policy plans
  • Verifying contractor compliance with contracts
  • Creating policies that reflect legal, regulatory, and organizational requirements
  • Maintaining planning documents
  • Conducting test events
  • Interfacing with customers
  • Network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

CMMC Readiness Practitioner: Senior

We are hiring a senior CMMC Readiness Practitioner. You will set the direction for this work, mentor others in it, and be accountable for its outcomes at the organizational level. You take a defense supplier from a DFARS clause to an honest self-assessment, a signed affirmation, and assessment readiness.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Collect and maintain system cybersecurity report data
  • Create system cybersecurity reports
  • Determine impact of noncompliance on organizational risk levels
  • Develop computer environment cybersecurity plans and requirements
  • Recommend risk mitigation strategies
  • Report cybersecurity incidents
  • Develop cybersecurity policy recommendations
  • Update security documentation to reflect current application and system security design features
  • Document software, network, and system deviations from implemented security postures
  • Develop cybersecurity compliance processes for external services
  • Develop cybersecurity audit processes for external services
  • Determine if procurement activities sufficiently address supply chain risks
  • Determine if vulnerability remediation plans are in place
  • Develop vulnerability remediation plans
  • Support cybersecurity compliance activities
  • Determine organizational compliance
  • Mentor junior team members and review their work.
  • Represent this function to leadership and to auditors or clients.
  • Set standards, select tooling, and own the roadmap for this area.

Required knowledge

  • Cybersecurity laws and regulations
  • Authentication and authorization tools and techniques
  • Risk Management Framework (RMF) requirements
  • Risk tolerance principles and practices
  • Industry cybersecurity models and frameworks
  • Organizational policy and procedures
  • Risk mitigation principles and practices
  • The Registered Practitioner's and Registered Provider Organization's obligations under the Cyber AB's programs, including the Code of Professional Conduct
  • SPRS: what is posted, by whom, when a score must be current for award, and how an affirmation is recorded
  • The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
  • The DFARS clauses that carry CMMC and NIST SP 800-171 obligations (252.204-7012, -7019, -7020, -7021) and what each requires of a contractor
  • The annual affirmation: who may sign it, when it is due, what the affirming official attests to, and what follows a lapsed or false affirmation
  • The CMMC ecosystem's organizations and individual credentials, their authorities, and their limits (Cyber AB, CAICO, C3PAO, RPO, DIBCAC; RP, CCP, CCA, Lead CCA, CCI)
  • The difference between NIST SP 800-171 Rev 2 as pinned by the DoD class deviation and Rev 3 as published, and why an assessment is conducted against the pinned revision

Skills

  • Applying security controls
  • Developing policy plans
  • Verifying contractor compliance with contracts
  • Creating policies that reflect legal, regulatory, and organizational requirements
  • Maintaining planning documents
  • Conducting test events
  • Interfacing with customers
  • Network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools
  • Assessing security systems designs
  • Applying secure coding techniques

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Related roles

Roles that share this one’s work or career stage. Each links to its own statements, sample questions, and job description templates.