About the job
Take Charge of Your Career:
112Cyber (previously known as SP6 Cyber Risk & Compliance) is on the lookout for a seasoned Compliance Subject Matter Expert (SME) who is ready to elevate their career! In this pivotal role, you will play a crucial part in helping organizations enhance their security protocols while performing assessments for those seeking certification.
As a member of our dynamic Compliance team, you will witness the tangible impact of your work across the organization, taking the lead on various client projects and providing guidance to our platform team about the numerous compliance regulations.
Your primary focus will be supporting companies within the Defense Industrial Base (DiB) to achieve compliance with CMMC and/or NIST 800-171 standards. This will involve delivering pre-audit readiness consultations, conducting GAP assessments, providing plans of action and milestones (POA&M) support, offering Compliance as a Service (CaaS), and executing official C3PAO assessments.
Your Keys to Success:
Advisory Services
- Leading cybersecurity gap assessments in accordance with NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC).
- Engaging in daily activities for external client engagements as a vital contributor to 112Cyber’s customer-facing Cyber Risk & Compliance division.
- Facilitating compliance initiatives for external clients regarding FedRAMP, DFARS 7012, CMMC, and NIST 800-171.
- Utilizing knowledge of cyber compliance and risk management principles to provide actionable insights during engagements.
- Consulting with clients to gather their requirements and understand their primary security challenges, then collaborating with team members to devise cost-effective solutions to mitigate cybersecurity risks.
- Possessing in-depth knowledge of relevant security regulations and translating these into effective business processes and security controls to bolster clients' compliance and audit capabilities.
- Clearly articulating and defending IT controls testing methodologies while assessing design and operational effectiveness.
- Creating and delivering training sessions for both internal teams and clients.
- Building and maintaining strong working relationships with colleagues, existing clients, and prospective clients.
- Offering support to the ASCERA product team by providing insights on NIST continuous monitoring software.
C3PAO Assessments
- Conducting thorough assessments of organizations' cybersecurity practices using the CMMC assessment framework (CAP).
- Collaborating with client organizations to strategize assessments, create schedules, and ensure preparedness.
- Evaluating the efficacy of security practices to ensure alignment with CMMC standards.
- Interviewing key personnel within the organization to gather insights.
