CMMC Compliance Specialist
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Position Overview
Horizon Industries is seeking an experienced Part-Time Compliance Specialist to provide executive leadership and operational oversight for the company’s Cybersecurity Maturity Model Certification (CMMC) Level 2 program and Microsoft GCC High environment. The person will serve as the executive owner of the organization's CMMC compliance posture, ensuring that cybersecurity controls, governance processes, technical implementations, risk management activities, and assessment preparation efforts remain compliant, sustainable, and audit-ready. This position is ideal for a technology executive with deep experience in NIST SP 800-171, CMMC, Microsoft GCC High, federal government contracting, and cybersecurity governance.
Key Responsibilities
Executive Leadership & Governance
- Serve as Horizon's designated expert for all CMMC-related activities.
- Act as executive owner of systems that process, store, or transmit Controlled Unclassified Information (CUI).
- Ensure cybersecurity initiatives align with business objectives, contract requirements, and federal regulations.
- Provide strategic technology guidance to executive leadership regarding compliance, security, and risk management.
- Participate in executive compliance reviews and readiness briefings.
- Support annual affirmations and executive attestations relating to CMMC certification readiness.
CMMC Program Oversight
- Provide executive oversight of Horizon's CMMC Level 2 program.
- Review and approve CMMC policies, procedures, plans, and compliance artifacts.
- Ensure alignment among the System Security Plan (SSP), CUI Management Plan, POA&M, Risk Register, and supporting evidence repositories.
- Review compliance metrics, remediation activities, and audit findings.
- Support preparation for self-assessments, mock assessments, and formal C3PAO assessments.
- Participate in assessor interviews and executive-level discussions during audits.
Technical & Security Oversight
- Provide executive oversight of:
- Microsoft GCC High environment
- Entra ID / Identity & Access Management
- Conditional Access and MFA
- Endpoint security and device management
- Security monitoring and incident response
- Vulnerability management activities
- Configuration and change management processes
- Review security architecture and ensure alignment with CMMC control requirements.
- Evaluate impacts of major technology changes on CMMC scope and security posture.
Risk Management
- Lead annual and periodic cybersecurity risk assessments.
- Review risk treatment decisions and approve risk acceptance recommendations.
- Ensure corrective actions and remediation plans are effectively managed.
- Provide governance oversight for POA&M development and closure activities.
- Monitor compliance risks affecting certification status and federal contract eligibility.
Documentation & Audit Readiness
- Review and approve:
- System Security Plan (SSP)
- Policies and Procedures
- Continuous Monitoring Plan
- Incident Response Documentation
- Risk Assessment Reports
- CUI Management Documentation
- Evidence Management Processes
- Ensure documentation accurately reflects implemented controls and operational practices.
- Conduct periodic readiness reviews and executive quality checks on compliance artifacts.
Required Qualifications
- Demonstrated experience supporting CMMC Level 2 or NIST SP 800-171 compliance programs.
- Experience operating within DoD, federal contractor, or defense-industrial-base environments.
- Strong working knowledge of:
- Microsoft 365 GCC High
- Entra ID
- Microsoft Defender
- Microsoft Purview
- Microsoft Sentinel
- Intune
- Identity and Access Management
Preferred Qualifications
- Previous experience serving as CIO, CISO, or equivalent executive role.
- Successfully supported one or more organizations through CMMC certification.
- Experience participating in DoD cybersecurity assessments.
- Familiarity with DFARS 252.204-7012, 7019, 7020, and 7021.
- Experience with SPRS submissions and executive affirmations.
- Certifications such as:
- CISSP
- CISM
- CGRC (formerly CAP)
- CCSP
- CMMC Certified Professional (CCP)
- CMMC Certified Assessor (CCA)
Key Deliverables
The Part-Time Compliance Specialist will be expected to:
- Maintain executive oversight of Horizon's CMMC compliance program.
- Conduct monthly compliance governance reviews.
- Review and approve major compliance documentation.
- Provide quarterly executive risk assessments.
- Participate in internal audit and assessment preparations.
- Support executive readiness for C3PAO assessments.
- Validate SSP accuracy and compliance traceability.
- Advise leadership on cybersecurity investments, risk acceptance, and CMMC sustainment strategies.
This role is intended to provide Horizon with an experienced executive capable of serving as the reliable expert for CMMC compliance while leveraging existing internal resources for day-to-day administration and technical operations.
Horizon is an Equal Employment Opportunity employer, and it is our policy to consider all applicants for employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Horizon Industries
Explore Top Companies in this Space
Capgemini
Information Technology / Management Consulting / IT Services
AmeXio Group
Enterprise Software / Content Management / Digital Transformation / Cloud Solutions
Vix Technology
Intelligent Transportation Systems / Automated Fare Collection / Transit Analytics / IT Services
Panorama Education
EdTech / K-12 Education / SaaS / Data Analytics
Horizon Industries
View Company ProfileHorizon Industries, Limited (operating via hil.us) is a premier IT and Management Consulting firm engineered to deliver modern technological solutions and strategic public impact. Founded in 1996 and headquartered in Vienna, Virginia, the company fundamentally transforms how federal agencies and commercial enterprises operate by bridging the gap between innovative technology and actionable business outcomes. Moving far beyond traditional consulting, Horizon natively unifies Low Code Software Development (leveraging platforms like Appian and ServiceNow), robust Cyber Security lifecycle engineering, and advanced data analytics into a single, cohesive service ecosystem. The firm empowers organizations to accelerate digital transformation, reduce operational complexity, and rigorously secure critical toolsets against modern threats. Under the hood, their deep technical expertise is backed by a relentless focus on results and over 25 years of trusted experience supporting major organizations, including the US Department of the Army, OPM, the Department of Labor, and the GSA. Bolstered by a dynamic, multi-disciplinary team of professionals, Horizon Industries remains a definitive cornerstone of the modern federal and commercial IT consulting landscape, ensuring critical public missions are met with agility and security.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

