CMMC Program Manager
Job Location:
Dallas, IA - USA
Yearly Salary:
$ 125000 - 195000
Posted:
28 August 2026 (22 hours ago)
Application Deadline:
25 November 2026
Vacancies:
1 Vacancy
Job Summary
SummaryBalfour Beatty Construction LLC (Company) a member of the Balfour Beatty plc group of companies is searching for a CMMC Program Manager to support its compliance with cyber and physical security requirements for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) associated with the Companys Federal construction contracts as well as equivalent requirements in private contracts. Candidates must have a strong working knowledge of FAR and DFARS requirements for the handling of FCI and CUI excellent analytical project management communication and organizational skills. The selected candidate will ideally work out of our Falls Church VA office but candidates based in Dallas TX will be considered as well. This is a hybrid position that requires working in the office three days per week and working from home two days per CMMC Program Manager is responsible for managing maintaining and continuously improving the organizations Cybersecurity Maturity Model Certification (CMMC) compliance program for the secure enclave supporting Department of Defense (DoD) and other Federal agency CUI as well as the Companys policies and procedures for handling FCI. The CMMC Program Manager will serve as the primary liaison between compliance & ethics IT legal and operations as it relates to governance reporting monitoring assessment and organizational adoption of security requirements necessary to maintain ongoing compliance with NIST SP 800-171 NIST SP 800-137 FAR and DFARS requirements and CMMC Level 1 and Level FunctionsServe as the organizations primary internal authority for CMMC compliance within the secure enclave providing guidance to IT IT Security Operations Human Resources Legal Procurement Communications and executive leadership regarding FCI CUI and equivalent compliance obligations and governance requirements. Own the organizations CMMC compliance program for the secure enclave ensuring governance activities remain aligned with organizational objectives contractual obligations regulatory requirements and evolving cybersecurity maintain and periodically review the Continuous Monitoring Plan (CMP) and support ISCM review maintain and coordinate approval of CMMC-related policies standards procedures and supporting and manage ISCM strategy risk tolerance and reporting cadence in coordination with the CIO CISO CLO and US Compliance initial implementation as well as ongoing assessment of security control effectiveness including vulnerability identification and reporting configuration compliance access reviews and incident annual CMMC self-assessments risk assessments internal audits certification readiness activities and coordination with Certified Third-Party Assessment Organizations (C3PAOs) for external CMMC assessments as compliance status risk posture and strategic recommendations to executive leadership and governance and maintain evidence repositories supporting ongoing internal assessments external certification activities and audit compliance documentationincluding the System Security Plan (SSP) POA&Ms policies procedures system inventories data flow diagrams asset inventories evidence repositories and assessment recordsremains complete accurate and report coordinate and validate remediation of deviations exceptions and findings discovered during monitoring or risk metrics dashboards and executive reports summarizing enclave risk posture and compliance compliance activities involving third-party service providers supporting the enclave including review of agreements security documentation and shared responsibility proposed changes to enclave architecture systems applications and operational processes to evaluate potential impacts to CMMC compliance and update compliance documentation as with IT Operations and IT Security teams to ensure configuration baselines asset inventories and system changes remain aligned with approved security configurations and compliance or participate in periodic incident response tabletop exercises involving IT Legal Human Resources Executive Leadership and applicable business evidence management control documentation and audit post-incident reviews track corrective actions and ensure lessons learned are incorporated into security controls policies procedures training and continuous monitoring activities to improve the organizations overall CMMC compliance with internal stakeholders:Business Stakeholders: program managers project managers and functional owners using enclave resources. Assist with onboarding offboarding and transfers as and secure enclave MSSP and IT Security Teams: administrators network engineers and analysts managing enclave systems and monitoring and Procedure Enforcement: detect and document deviations or non-compliance collaborate with HR and/or Legal to resolve violations and ensure corrective or disciplinary actions are applied and recorded in accordance with organizational policy and audit Training Program Management: review develop and adjust security awareness or role-based training content to ensure alignment with current government DOD and CMMC requirements and to address evolving cyber security and enclave operational Leadership: provide compliance reporting risk briefings POA&M status and recommendations for risk acceptance with export control requirements such as International Traffic in Arms Regulations and Export Administration Regulations. Continuously review and improve ISCM processes automation and reporting frequency to align with organizational risk risk assessments and coordinate risk acceptance activities with executive leadership where and direct security measures necessary for implementing the applicable requirements of the NISPOM and related USG security requirements to ensure the protection of classified and execute an insider threat program to gather integrate and report relevant and available information indicative of potential or actual insider broader Ethics & Compliance initiatives including performing other ethics compliance and special projects as assigned by the Vice President Ethics & Compliance and as workload and business needs QualificationsThis position requires access to export-controlled information. To comply with U.S. government regulations and contract obligations applicable so such information all applicants must be U.S. persons under the U.S. export control degree in Risk Management Compliance and Regulation Information Security Information Systems or a related field. Equivalent experience working within a Department of Defense agency will also be considered.7 years in cybersecurity governance risk management compliance or information security including at least 3 years supporting NIST SP 800-171 related -on experience with NIST SP 800-137 implementation or continuous monitoring with NIST SP 800-171 CMMC Level 1 and 2 and FAR and experience developing or managing System Security Plans (SSP) and POA& analytical documentation and executive-reporting to coordinate cross-functional teams and enforce FSO training within 6 months of hire if not already ITPSO Qualifications / CertificationsExperience supporting Department of Defense Federal Government or other regulated markets with significant information security : Certified CMMC Professional (CCP) or Certified CMMC Assessor (CCA) or CMMC Registered Practitioner Advanced (RPA)Cyber security: Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certified in Risk and Information Systems Control (CRISC) Security or CySAExperience operating in secure enclave or DoD contractor IndicatorsTimeliness and completeness of annual ISCM assessmentsPercentage of controls with continuous monitoring coverageNumber of open POA&M items vs. remediation rateAccuracy and quality of compliance metrics / dashboardsPolicy and Procedure enforcementSuccessful CMMC C3PAO recertification every 3 yearsPay Rate: $00/year *This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range and the range may be modified in the future. An employees pay position within the salary range will be based on several factors including but not limited to relevant education qualifications certifications experience skills seniority geographic location performance shift travel requirements any collective bargaining agreements and business or organizational needs. No amount of pay is considered to be wages or compensation until such amount is earned vested and determinable. The amount and availability of any bonus incentive or any other form of compensation that are allocable to a particular employee remains in the Companys sole discretion unless and until paid and may be modified at the Companys sole discretion consistent with the law and any applicable plan documents.
Required Experience:
IC