CMMC Cybersecurity Specialist

ACG Inc.
El Paso, TX, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$65,000.0 - $85,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Bash Shell Border Gateway Protocol Cisco PIX Cloud Computing Security Cyber Security Computer Networks Dynamic Host Configuration Protocol Domain Name System (DNS) Enhanced Interior Gateway Routing Protocol Intrusion Detection Systems Python (Programming Language)
+14 more
Network Security Routing Open Shortest Path First (OSPF) Open Source Technology Security Information and Event Management TCP/IP Software Vulnerability Management Data Logging Google Cloud Cloud Platform System Cyber Threat Analysis SolarWinds (Software) Splunk Software Version Control

Job description

The CMMC Cybersecurity Specialist is responsible for implementing, maintaining, and continuously improving ACG’s cybersecurity posture to support CMMC Level 2 compliance, federal contract requirements, and the protection of Controlled Unclassified Information (CUI). This role operates in a structured, high-expectation environment where documentation, accountability, and execution are non-negotiable. The position supports audits, assessments, and secure operations across the organization while ensuring alignment with NIST SP 800-171 and internal QMS policies., * CMMC & Compliance Execution

  • Lead day-to-day implementation and sustainment of CMMC Level 2 controls.
  • Maintain alignment with NIST SP 800-171 requirements and federal cybersecurity expectations.
  • Prepare, organize, and maintain audit-ready compliance evidence.
  • Support assessor interactions following approved communication procedures.

Cybersecurity Operations

  • Implement and monitor technical and administrative security controls.
  • Support secure configuration, access control, logging, monitoring, and incident response.
  • Coordinate vulnerability management, patching, and remediation tracking.
  • Ensure secure handling, storage, and transmission of CUI.

Documentation & QMS

  • Develop, update, and maintain cybersecurity policies, SOPs, standards, and forms.
  • Ensure documentation meets formatting, version control, and annual review requirements.
  • Maintain traceability between controls, evidence, and system implementation.

Training & Cross-Functional Support

  • Support cybersecurity and CMMC awareness training for employees and contractors.
  • Coordinate role-based training and acknowledgment tracking.
  • Work closely with HR on personnel security requirements.
  • Support Operations and Project Teams on secure practices for federal projects.
  • Provide executive-level compliance and risk status updates.

KPIs Impacted

  • CMMC control implementation completion percentage
  • Audit readiness and evidence completeness
  • Policy and SOP review compliance
  • Incident response and remediation timelines
  • Training completion rates

Requirements

Do you have experience in Vulnerability management?, * 3+ years of experience in cybersecurity, compliance, or information security.

  • Hands-on experience with CMMC Level 2 and NIST SP 800-171.
  • Experience supporting audits or formal assessments (CMMC, NIST, ISO, SOC, etc.).
  • Experience in federal contracting or regulated environments preferred., * Proven experience in cybersecurity roles with a focus on system security plans, vulnerability management, or network security.
  • Strong knowledge of computer networking concepts including LAN/WAN architecture, routing protocols such as OSPF/EIGRP/BGP, TCP/IP stack, DNS/ DHCP configuration.
  • Hands-on experience with firewall management (Cisco ASA), IDS/IPS systems, SIEM tools like Splunk or SolarWinds, and open-source scripting languages such as Python or Bash for automation.
  • Familiarity with cloud computing platforms such as AWS or Google Cloud Platform along with cloud infrastructure security best practices including FedRAMP compliance.
  • Understanding of threat intelligence frameworks and attack frameworks for proactive threat detection & response., * cybersecurity: 3 years (Required)

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Profit sharing, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Vision insurance

About the company

ACG is a fast-growing, family-minded small business built on ownership, discipline, and results. We value clear communication, strong documentation, and consistent follow-through. Our roles move quickly and require people who are organized, emotionally mature, and comfortable with direct feedback.

Strong performance and execution translate directly into real financial and professional growth.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all