CMMC Program Manager
Huntsville, AL
Sentar Inc.
Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the small business team where you can build, innovate, and secure your career.
Sentar is seeking a CMMC Program Manager in Huntsville, AL!
Role Description:
The CMMC Program Manager will work closely with the CISO and his direct reports, members of the C3PAO community, and internal/external stakeholders to advance the market recognition and captured portfolio of C3PAO Assessment and Advisory services to include CMMC and SSDF and similar GRC. The CMMC Program Manager will also serve as a subject matter expert to perform as a Lead Assessor on assessment and advisory services, ensure client satisfaction, mentor team resources, and may support the corporate interest in several other cybersecurity compliance and audit related work efforts.
Responsibilities
· Strategic Alignment
-
- Work closely with the Chief Information Security Officer (CISO) to align the cybersecurity assessment and advisory program delivery with the organization’s broader sales, services, quality and cybersecurity strategies
- Regularly update the CISO on service area performance, risks, opportunities, and needs providing data driven insights to inform decision making
- Participate in strategic planning sessions with the CISO or on behalf of the CISO with other executives to ensure that the cybersecurity assessment and advisory program supports corporate line of business goals
- Become primary point of contact and educator on CMMC, SSDF, and other Cybersecurity GRC for internal stakeholders
· Compliance Engagement Leadership & Oversight
-
- Ensuring all assessment activities comply with the security requirements for CMMC, or other compliance frameworks and relevant guidelines
- Oversee the evaluation and validation of security controls implemented by clients, ensuring that they meet the required standards
- Setting tone and approach for assessment interviews and client engagement while conducting interview, examine, test and feedback
- Providing?subject matter expertise for CMMC?and NIST 800-Series compliance standards and regulations
- Conducting CMMC, and NIST 800-series gap assessments, compliance readiness, compliance monitoring, assessments, etc. activities
- Coordinating?and?leading delivery of audit milestones to ensure audit timelines stay on target by escalating and identifying roadblocks
- Conducting various IT Compliance controls validation and implementation activities
- Collaborating with technology and business stakeholders along with other Compliance team members to facilitate remediation and execution of corrective action plans
- Participating in continuous improvement initiatives
- Implement continuous monitoring and manage practices to maintain security acumen and compliance
- Prepare and present detailed risk reporting, summaries, assessment reports, procedure workbooks for actionable insight and contract compliance
· Business Capture Support
-
- Collaborate with the business development team to identify and pursue opportunities related to CMMC and SSDF assessments
- Provide subject matter expertise and strategic input during the proposal development process to secure new contracts and engagements.
- Develop and maintain relationships with potential and existing clients to understand their needs and tailor assessment services accordingly
- Participating in capture activities with Sales and supporting quote and proposal response toward capture
- Participating in industry conferences other marketing efforts to promote recognition for capability and competence in the field as an individual and by extension for Sentar
· Team Management
-
- Direct and mentor a team of cybersecurity professionals, including assessors, ensuring that they are equipped with the necessary skills and resources to complete engagements
- Oversee the allocation of resources across multiple engagements, balancing workloads, spend, earned value, profit while ensuring timely and quality delivery of services.
- Develop and implement training programs to enhance the team’s knowledge and skill in evolving cybersecurity standards and assessment methodologies.
- Providing coaching and mentorship to more junior team members
- Providing templates and business improvement for the delivery of Cybersecurity Governance Risk and Compliance services
Key Performance Indicators (KPIs)
· Develop, track and report on KPIs related to the efficiency, effectiveness, ROI, Profit/Loss, and impact of the CMMC assessment and advisory line of business
· Implement quality assurance processes to ensure that all assessments meet or exceed industry standards and client expectations
· Monitor client satisfaction levels and implement improvements to enhance the client experience and service delivery
Qualifications:
Clearance Level: No clearance needed at time of hire, but must be eligible for Secret
Certifications:
- CCA (CIACO Certified CMMC Assessor)
- CISM or CISSO or CPTE or CySA+ or FITSP-A or GCSA or CISA or CISSP or CISSP-ISSEP or GSLC or GSNA
Education: Bachelors degree preferred
Experience:
- At least 1 year of experience performing assessments
- Effective program management, project management, and organization management skills to include follow-up, time management, project budget management and people management
- At least 5 years hands-on experience in a Cybersecurity Compliance Audit and Advisory services role
- Strong background and understanding of NIST SP 800-171 and a broad range of knowledge in the fields of NIST Special Publications in the 800 series
- Deep knowledge of client engagement and practice management
- Experience with control assessments, coordination of audit activities, and leading multiple assessment engagement and train junior staff
- Familiarity with Information Security Principles, knowledge of IT Processes (e.g., Change Management, Incident Management, Risk Management, Network and System Administration, Monitoring)
- Strong technical, analytical, interpersonal, written and oral communication skills
- Strong writing ability for business, proposal, information delivery, status, technical and executive
- Ability to work as a remote employee, independently, and collaboratively with a nationally distributed team
- Self-starter, faster learner, and proactive problem-solver skills
- Ability to develop and foster strong relationships in the industry, internally in the company, and with technology, business and government stakeholders
- Fluency in written and spoken English language
Benefits at Sentar:
In addition to a great culture, Sentar not only fosters an inclusive work environment but also offers an extensive benefits package designed to cater to the well-being of its employees and their families.
- Voluntary Medical, Dental, Vision, with Health Savings or Flexible Spending Plan options
- Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
- Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
- Generous 401(k) match
- Competitive PTO plan that graduates quickly with years of service
- Other leave programs; holiday schedule along with bereavement, jury and military duty
- Mental health awareness programs
- Tuition reimbursement
- Professional development reimbursement
- Recognition and Awards programs
If you are not ready to apply for this position, submit your resume here to join our talent community. We'll keep you updated occasionally on new job opportunities.
Sentar is an Affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities
Our culture is one of inclusivity and support. Sentar is proudly an Equal Opportunity and VEVRAA Federal Contractor Employer M/F/Vets/Persons with Disabilities. Follow these links to learn more about your rights: EEO Is the Law Poster; EEO Is Law Supplement; and Pay Transparency.
We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at recruiting@sentar.com. Please indicate the specifics of the assistance needed. Thank you for considering Sentar in your employment search.
Build, Innovate, Secure Your Career at Sentar.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics CISA CISM CISO CISSP Clearance CMMC Compliance Governance GSLC GSNA KPIs Monitoring NIST Risk management
Perks/benefits: 401(k) matching Career development Competitive pay Conferences Flex hours Flex vacation Health care Insurance Medical leave Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.