CMMC Lead Assessor Steelgate
LLC - 5.0
Augusta, GA Job Details Full-time $150,000 - $170,000 a year 22 hours ago Benefits Health savings account Health insurance Dental insurance 401(k) Flexible spending account Paid time off Vision insurance 401(k) matching Life insurance Qualifications Information security audit implementation Team leadership Military CISSP Secret Clearance DoD experience Information & network security team management Information security compliance Cloud security Data collection Information security auditing Full Job Description SteelGate LLC is seeking an experienced, highly qualified Lead CMMC Certified Assessor (LCCA) to lead formal Department of Defense (DoD) CMMC Level 2 certification assessments. Operating out of Augusta, GA in close proximity to the Cyber Center of Excellence you will serve as the primary assessment lead and senior subject matter expert across SteelGate's C3PAO assessment lifecycle and External Service Provider (ESP) advisory initiatives. In this role, you will lead assessment teams, evaluate defense contractor systems against
NIST SP 800-171 / 800-171A
controls, manage client engagements through the CMMC Assessment Process (CAP), validate evidence sufficiency, and issue defensible, final compliance determinations. Key Responsibilities
Assessments:
Serve as the Lead Assessor for C3PAO certification engagements, directing assessment planning, execution, evidence collection, and final reporting in accordance with 32 CFR Part 170/171 and Cyber AB CAP guidelines.
Scope Validation:
Review and validate Organization Seeking Assessment (OSA) scoping boundaries across CUI Assets, Security Protection Assets (SPAs), Out-of-Scope Assets, and specialized assets.
Evidence Analysis & Testing:
Execute and supervise the Examine, Interview, and Test assessment methods mapped to
NIST SP 800-171A
requirements.
Defensible Reporting:
Document findings, generate Assessment Findings Reports, verify artifact hash lists, and oversee submissions into CMMC eMASS.
Team Management & Quality Assurance:
Supervise team CCAs and CCPs, resolve technical discrepancies during evaluations, and ensure independence and strict adherence to ethics and conflict-of-interest standards.
- Collaborate with SteelGate engineering and compliance leadership to ensure SteelGate's ESP hosting environment maintains alignment with Level 2 security baseline requirements.
- Maintain complete independence between advisory/consulting engagements and formal C3PAO certification audits. Required Qualifications
- Active Lead CMMC Certified Assessor (LCCA™) credential in good standing with The Cyber AB / CAICO or active CCA™ credential meeting all LCCA criteria.
- Active DoD 8140.03 / 8570.01-M Baseline Certification Advanced Proficiency Level for Work Role 612 (Security Control Assessor) e.g., CISSP, CISM, CISA, GSLC, or GSNA.
- Minimum 5+ years of progressive cybersecurity experience.
- Minimum 3+ years directly conducting IT/cybersecurity audits or control evaluations (NIST
SP 800-53, NIST SP
800-171, Fed
RAMP, ISO
27001, or SOC 2).
- Minimum 5+ years in a technical leadership, management, or audit lead role.
- U.
S. Citizenship (Mandatory per
CMMC C3PAO
program guidelines).
- Active DoD Secret Clearance (or favorable Tier 3 / NAC background investigation determination). Preferred Qualifications
- Hands-on experience working with Defense Industrial Base (DIB) contractors handling CUI/FCI data.
- Background in federal government contracting, DFARS 252.204-7012 / 7019 / 7020 compliance, and SPRS score submissions.
- Experience with cloud security architectures (AWS GovCloud, Microsoft 365 GCC High) and enclave/ESP boundaries.
- Prior military or DoD civilian experience in Cyber Operations or Information Assurance (e.g., USCC, NETCOM, CCoE). Travel Requirements
Primary:
Georgia Cyber Center, Augusta, GA. Hybrid scheduling available for non-assessment delivery periods.
Travel:
Up to 25%-35% regional travel for on-site client assessments and site reviews.
Pay:
$150,000.00 - $170,000.00 per year
Benefits:
401(k) 401(k) matching Dental insurance Flexible spending account Health insurance Health savings account Life insurance Paid time off Vision insurance
Experience:
Conducting Cybersecurity Audits or control evaluation: 3 years (Preferred)
Cybersecurity:
5 years (Preferred)
CMMC:
3 years (Preferred) Azure Cloud platform: 1 year (Preferred)
License/Certification:
LCCA (Required) Security clearance: Secret (Required)
Work Location:
Hybrid remote in Augusta, GA 30901