Kellwick is looking for an experienced CMMC & NIST SP 800-171 Consultant to support organisations subject to US defense supply-chain cybersecurity requirements.
This is a specialist role for someone with practical experience helping organisations protect FCI/CUI, implement NIST SP 800-171 requirements and prepare for CMMC assessments.
Practical CMMC and Defense Industrial Base experience is required.
What You Will Do
Perform CMMC Level 1 and Level 2 readiness assessments
Perform NIST SP 800-171 gap assessments
Determine and validate assessment scope
Support FCI and CUI identification and scoping
Review CUI data flows and system boundaries
Develop and review System Security Plans
Develop and manage Plans of Action and Milestones
Map NIST SP 800-171 requirements to technical and administrative controls
Assess implementation of security requirements
Review objective evidence
Support remediation planning and implementation
Prepare clients for CMMC assessment
Conduct mock readiness reviews
Review policies, procedures and technical evidence
Support client teams with DFARS-related cybersecurity requirements
Work with IT and security teams on identity, access, endpoint, network, logging, incident response and configuration requirements
Produce clear readiness findings and remediation roadmaps
Support ongoing CMMC/NIST governance engagements
Required Experience
5+ years of professional cybersecurity, GRC or security assurance experience
Practical experience with NIST SP 800-171
Practical CMMC readiness or implementation experience
Experience working with organisations handling FCI and/or CUI
Strong understanding of CMMC Level 1 and Level 2 requirements
Experience developing or reviewing System Security Plans
Experience developing and managing POA&Ms
Experience assessing technical and administrative security controls
Understanding of Defense Industrial Base cybersecurity requirements
Experience preparing organisations for external security assessments
Strong client-facing communication and documentation skills
Professional English
Strong Plus
Cyber AB Registered Practitioner
Cyber AB Registered Practitioner Advanced
CCP or CCA credentials
CISSP
CISM
CRISC
NIST cybersecurity consulting experience
DFARS experience
Microsoft GCC / GCC High experience
Microsoft 365 and Azure security experience
Experience with CMMC assessment preparation for small and mid-sized contractors
Previous experience within the Defense Industrial Base
Important
This is a readiness, implementation and advisory role.
Kellwick does not position advisory work as an independent CMMC certification assessment. Consultants must maintain clear separation between implementation support and any assessment activities subject to CMMC ecosystem independence requirements.
Engagement Model
This is a project-based independent contractor position.
Assignments may include CMMC readiness, NIST SP 800-171 implementation, SSP development, remediation, evidence preparation and ongoing security governance.
Apply for this role
Upload your CV (required) and, optionally, a cover letter. We review every application.