Cybersecurity Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
BAA Consulting is seeking a skilled and detail-oriented Cyber Security Auditor to join our growing compliance and risk management practice. In this role, you will conduct IT audits and assessments across a range of regulatory frameworks, with a particular emphasis on CMMC compliance support for Department of Defense (DoD) contractors and federal agencies. You will work directly with clients to evaluate security posture, identify gaps, and provide actionable guidance toward audit readiness and ongoing compliance., · Plan, execute, and document IT security audits across frameworks including RMF, NIST SP 800-171, CMMC (Levels 1 and 2), SOC-1, SOC-2 Type II, PCI DSS, FedRAMP, FISMA, and DISA STIGs
· Conduct CMMC readiness assessments and gap analyses for DoD contractors and government clients pursuing Level 1 Self-Assessments and Level 2 Third-Party Assessments (C3PAO)
· Assess the implementation and effectiveness of security controls against applicable frameworks and document findings with clarity and precision
· Develop detailed audit reports, Plans of Action and Milestones (POA&Ms), and remediation roadmaps for client stakeholders
· Guide clients through CMMC Level 1 Self-Assessment preparation, including documentation review, evidence collection, and control validation
· Support client preparation activities for CMMC Level 2 Third-Party Assessments, including pre-assessment mock reviews and evidence packaging
· Collaborate with client IT teams to evaluate system configurations, access controls, incident response procedures, and security documentation
· Communicate audit findings and compliance status to technical and executive-level audiences in clear, concise language
· Stay current with evolving CMMC standards, NIST guidelines, and DoD cybersecurity policy updates
· Contribute to the continuous improvement of BAA Consulting’s audit methodologies, templates, and service delivery practices
Requirements
Do you have experience in Regulatory compliance?, This position requires a professional who brings both technical depth and strong interpersonal skills - someone capable of engaging with government clients, translating complex compliance requirements into practical recommendations, and supporting organizations through the full audit lifecycle., · Demonstrated experience conducting IT security audits using one or more of the following frameworks: RMF, NIST SP 800-53 / SP 800-171, SOC-1, SOC-2 Type II, PCI DSS, CMMC, FedRAMP, or FISMA
· Working knowledge of CMMC (Cybersecurity Maturity Model Certification) practices, including the 110 security requirements of NIST SP 800-171 and the CMMC Assessment Process (CAP)
· Active RP (Registered Practitioner) or RPA (Registered Practitioner Advanced) certification issued by the Cyber AB
· Minimum of one active Level 1 IT certification, such as:
o CompTIA A+
o CompTIA Security+
o CompTIA Network+
o Or an equivalent vendor-neutral foundational certification
· Ability to obtain and maintain a Secret security clearance (active clearance is preferred)
· Strong written and verbal communication skills, including the ability to produce professional audit documentation and present findings to government clients
· Demonstrated ability to work independently, manage competing priorities, and meet deadlines in a client-facing environment
Preferred Qualifications
· Active RP/RPA Certification
· Additional certifications such as CISSP, CASP+, CISM, or CISA
· Experience supporting CMMC Level 2 Third-Party Assessments (C3PAO engagements)
· Familiarity with DISA STIGs and system hardening practices for government IT environments
· Hands-on experience with cloud environments (AWS or Azure) in the context of government compliance programs such as FedRAMP or IL2/IL4/IL5
· Prior experience working with federal government clients, including DoD components, civilian agencies, or state government entities
· Experience using vulnerability management tools, GRC platforms, or POA&M tracking systems
· Background in enterprise IT infrastructure, systems administration, or network engineering
Benefits & conditions
Pulled from the full job description
- Referral program
- Professional development assistance
- Tuition reimbursement
- 401(k)
- Health insurance
- Paid time off
- Vision insurance, * 401(k)
- Flexible schedule
- Health insurance
- Paid time off
- Professional development assistance
- Referral program
- Tuition reimbursement
- Vision insurance
About the company
BAA Consulting is a Richmond, Virginia-based IT consulting firm delivering enterprise-grade cybersecurity and compliance solutions to federal and state government clients. Our portfolio spans the Department of the Army, Office of Inspector General (OIG), Office of Personnel Management (OPM), and the State of Virginia, among others. We hold a GSA Schedule contract vehicle and are certified as a Registered Practitioner Organization (RPO) through the Cyber AB, positioning us as a trusted partner for organizations pursuing Cybersecurity Maturity Model Certification (CMMC).
Our team of certified professionals operates at the intersection of compliance, risk management, and mission-critical IT - implementing frameworks including RMF, NIST, FedRAMP, FISMA, DISA STIGs, CMMC, and PCI across complex government environments., BAA Consulting is at a significant growth inflection. As a Cyber AB-certified RPO, we are actively expanding our CMMC advisory and audit readiness practice to meet rising demand across the Defense Industrial Base (DIB). This role offers the opportunity to work on meaningful, mission-critical engagements alongside a team of seasoned professionals holding certifications including CISSP, CASP+, Security+, and AWS/Azure Architect credentials.
You will be part of an organization that values technical rigor, client trust, and professional growth. With offices in Richmond, Virginia and Miami, FL as well as expansion plans underway in Colorado Springs, CO, BAA Consulting offers a stable, mission-driven environment with the energy and opportunity of a growing firm.
If you are a compliance professional who is passionate about cybersecurity, experienced in government audit frameworks, and ready to make a direct impact on how organizations achieve and maintain their security certifications - we want to hear from you.
BAA Consulting is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or veteran status.
For more information, visit www.baaconsulting.org or submit your resume and a brief cover letter outlining your relevant audit experience and certifications.
Pay: $80,000.00 - $105,000.00 per year
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities