> Markdown version of [/jobs/ext/227486-cybersecurity-consultant](https://www.wearedevelopers.com/jobs/ext/227486-cybersecurity-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Consultant - **Company:** BAA Consulting LLC - **Location:** Richmond, VA, United States - **Salary:** $80,000.0 - $105,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, CompTIA Network+, CompTIA Security+, Cyber Security, System Configuration, Information Technology Audit, PCI Data Security Standards, Software Vulnerability Management, Cloud Platform System, RSA Archer Platform - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d0293c399b5dfddb ## About the Role Do you have experience in Regulatory compliance?, This position requires a professional who brings both technical depth and strong interpersonal skills - someone capable of engaging with government clients, translating complex compliance requirements into practical recommendations, and supporting organizations through the full audit lifecycle., · Demonstrated experience conducting IT security audits using one or more of the following frameworks: RMF, NIST SP 800-53 / SP 800-171, SOC-1, SOC-2 Type II, PCI DSS, CMMC, FedRAMP, or FISMA · Working knowledge of CMMC (Cybersecurity Maturity Model Certification) practices, including the 110 security requirements of NIST SP 800-171 and the CMMC Assessment Process (CAP) · Active RP (Registered Practitioner) or RPA (Registered Practitioner Advanced) certification issued by the Cyber AB · Minimum of one active Level 1 IT certification, such as: o CompTIA A+ o CompTIA Security+ o CompTIA Network+ o Or an equivalent vendor-neutral foundational certification · Ability to obtain and maintain a Secret security clearance (active clearance is preferred) · Strong written and verbal communication skills, including the ability to produce professional audit documentation and present findings to government clients · Demonstrated ability to work independently, manage competing priorities, and meet deadlines in a client-facing environment Preferred Qualifications · Active RP/RPA Certification · Additional certifications such as CISSP, CASP+, CISM, or CISA · Experience supporting CMMC Level 2 Third-Party Assessments (C3PAO engagements) · Familiarity with DISA STIGs and system hardening practices for government IT environments · Hands-on experience with cloud environments (AWS or Azure) in the context of government compliance programs such as FedRAMP or IL2/IL4/IL5 · Prior experience working with federal government clients, including DoD components, civilian agencies, or state government entities · Experience using vulnerability management tools, GRC platforms, or POA&M tracking systems · Background in enterprise IT infrastructure, systems administration, or network engineering ## Description BAA Consulting is seeking a skilled and detail-oriented Cyber Security Auditor to join our growing compliance and risk management practice. In this role, you will conduct IT audits and assessments across a range of regulatory frameworks, with a particular emphasis on CMMC compliance support for Department of Defense (DoD) contractors and federal agencies. You will work directly with clients to evaluate security posture, identify gaps, and provide actionable guidance toward audit readiness and ongoing compliance., · Plan, execute, and document IT security audits across frameworks including RMF, NIST SP 800-171, CMMC (Levels 1 and 2), SOC-1, SOC-2 Type II, PCI DSS, FedRAMP, FISMA, and DISA STIGs · Conduct CMMC readiness assessments and gap analyses for DoD contractors and government clients pursuing Level 1 Self-Assessments and Level 2 Third-Party Assessments (C3PAO) · Assess the implementation and effectiveness of security controls against applicable frameworks and document findings with clarity and precision · Develop detailed audit reports, Plans of Action and Milestones (POA&Ms), and remediation roadmaps for client stakeholders · Guide clients through CMMC Level 1 Self-Assessment preparation, including documentation review, evidence collection, and control validation · Support client preparation activities for CMMC Level 2 Third-Party Assessments, including pre-assessment mock reviews and evidence packaging · Collaborate with client IT teams to evaluate system configurations, access controls, incident response procedures, and security documentation · Communicate audit findings and compliance status to technical and executive-level audiences in clear, concise language · Stay current with evolving CMMC standards, NIST guidelines, and DoD cybersecurity policy updates · Contribute to the continuous improvement of BAA Consulting's audit methodologies, templates, and service delivery practices ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)