Cybersecurity Consultant

BAA Consulting LLC
Richmond, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Compensation
$80,000.0 - $105,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure CompTIA Network+ CompTIA Security+ Cyber Security System Configuration Information Technology Audit PCI Data Security Standards Software Vulnerability Management Cloud Platform System RSA Archer Platform

Job description

BAA Consulting is seeking a skilled and detail-oriented Cyber Security Auditor to join our growing compliance and risk management practice. In this role, you will conduct IT audits and assessments across a range of regulatory frameworks, with a particular emphasis on CMMC compliance support for Department of Defense (DoD) contractors and federal agencies. You will work directly with clients to evaluate security posture, identify gaps, and provide actionable guidance toward audit readiness and ongoing compliance., · Plan, execute, and document IT security audits across frameworks including RMF, NIST SP 800-171, CMMC (Levels 1 and 2), SOC-1, SOC-2 Type II, PCI DSS, FedRAMP, FISMA, and DISA STIGs

· Conduct CMMC readiness assessments and gap analyses for DoD contractors and government clients pursuing Level 1 Self-Assessments and Level 2 Third-Party Assessments (C3PAO)

· Assess the implementation and effectiveness of security controls against applicable frameworks and document findings with clarity and precision

· Develop detailed audit reports, Plans of Action and Milestones (POA&Ms), and remediation roadmaps for client stakeholders

· Guide clients through CMMC Level 1 Self-Assessment preparation, including documentation review, evidence collection, and control validation

· Support client preparation activities for CMMC Level 2 Third-Party Assessments, including pre-assessment mock reviews and evidence packaging

· Collaborate with client IT teams to evaluate system configurations, access controls, incident response procedures, and security documentation

· Communicate audit findings and compliance status to technical and executive-level audiences in clear, concise language

· Stay current with evolving CMMC standards, NIST guidelines, and DoD cybersecurity policy updates

· Contribute to the continuous improvement of BAA Consulting’s audit methodologies, templates, and service delivery practices

Requirements

Do you have experience in Regulatory compliance?, This position requires a professional who brings both technical depth and strong interpersonal skills - someone capable of engaging with government clients, translating complex compliance requirements into practical recommendations, and supporting organizations through the full audit lifecycle., · Demonstrated experience conducting IT security audits using one or more of the following frameworks: RMF, NIST SP 800-53 / SP 800-171, SOC-1, SOC-2 Type II, PCI DSS, CMMC, FedRAMP, or FISMA

· Working knowledge of CMMC (Cybersecurity Maturity Model Certification) practices, including the 110 security requirements of NIST SP 800-171 and the CMMC Assessment Process (CAP)

· Active RP (Registered Practitioner) or RPA (Registered Practitioner Advanced) certification issued by the Cyber AB

· Minimum of one active Level 1 IT certification, such as:

o CompTIA A+

o CompTIA Security+

o CompTIA Network+

o Or an equivalent vendor-neutral foundational certification

· Ability to obtain and maintain a Secret security clearance (active clearance is preferred)

· Strong written and verbal communication skills, including the ability to produce professional audit documentation and present findings to government clients

· Demonstrated ability to work independently, manage competing priorities, and meet deadlines in a client-facing environment

Preferred Qualifications

· Active RP/RPA Certification

· Additional certifications such as CISSP, CASP+, CISM, or CISA

· Experience supporting CMMC Level 2 Third-Party Assessments (C3PAO engagements)

· Familiarity with DISA STIGs and system hardening practices for government IT environments

· Hands-on experience with cloud environments (AWS or Azure) in the context of government compliance programs such as FedRAMP or IL2/IL4/IL5

· Prior experience working with federal government clients, including DoD components, civilian agencies, or state government entities

· Experience using vulnerability management tools, GRC platforms, or POA&M tracking systems

· Background in enterprise IT infrastructure, systems administration, or network engineering

Benefits & conditions

Pulled from the full job description

  • Referral program
  • Professional development assistance
  • Tuition reimbursement
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance, * 401(k)
  • Flexible schedule
  • Health insurance
  • Paid time off
  • Professional development assistance
  • Referral program
  • Tuition reimbursement
  • Vision insurance

About the company

BAA Consulting is a Richmond, Virginia-based IT consulting firm delivering enterprise-grade cybersecurity and compliance solutions to federal and state government clients. Our portfolio spans the Department of the Army, Office of Inspector General (OIG), Office of Personnel Management (OPM), and the State of Virginia, among others. We hold a GSA Schedule contract vehicle and are certified as a Registered Practitioner Organization (RPO) through the Cyber AB, positioning us as a trusted partner for organizations pursuing Cybersecurity Maturity Model Certification (CMMC).

Our team of certified professionals operates at the intersection of compliance, risk management, and mission-critical IT - implementing frameworks including RMF, NIST, FedRAMP, FISMA, DISA STIGs, CMMC, and PCI across complex government environments., BAA Consulting is at a significant growth inflection. As a Cyber AB-certified RPO, we are actively expanding our CMMC advisory and audit readiness practice to meet rising demand across the Defense Industrial Base (DIB). This role offers the opportunity to work on meaningful, mission-critical engagements alongside a team of seasoned professionals holding certifications including CISSP, CASP+, Security+, and AWS/Azure Architect credentials.

You will be part of an organization that values technical rigor, client trust, and professional growth. With offices in Richmond, Virginia and Miami, FL as well as expansion plans underway in Colorado Springs, CO, BAA Consulting offers a stable, mission-driven environment with the energy and opportunity of a growing firm.

If you are a compliance professional who is passionate about cybersecurity, experienced in government audit frameworks, and ready to make a direct impact on how organizations achieve and maintain their security certifications - we want to hear from you.

BAA Consulting is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or veteran status.

For more information, visit www.baaconsulting.org or submit your resume and a brief cover letter outlining your relevant audit experience and certifications.

Pay: $80,000.00 - $105,000.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

Videos

See all

Related articles

See all