Implementation Specialist, CMMC
Lead end-to-end CMMC implementations for Secureframe customers, translating requirements into scoped plans with timelines, owners, and milestones. Coordinate technical configurations, evidence collection, remediation, secure environment planning, and training while building repeatable playbooks and processes for scalable delivery.
About the job
What You'll Do
- Lead end-to-end CMMC implementations for new and existing Secureframe customers, owning the customer experience from kickoff through handoff and readiness milestones.
- Translate customer requirements into clear implementation plans, including scope, timeline, milestones, owners, risks, dependencies, and success criteria.
- Help customers understand and operationalize CMMC requirements, including Level 1 FCI basics, Level 2 CUI handling, NIST SP 800-171 control expectations, SSP and POA&M workflows, evidence collection, asset inventory, and audit-readiness preparation.
- Partner with customers to identify where CUI lives today across email, file sharing, cloud applications, endpoints, engineering systems, specialized equipment, facilities, and third-party providers.
- Coordinate implementation work across Secureframe product configuration, control mapping, evidence automation, policies, procedures, owner assignments, remediation tracking, and readiness reporting.
- Support secure-environment planning discussions, including identity, endpoint management, logging, network segmentation, GCC High or Azure Government considerations, Google Workspace hardening, virtual desktops, physical controls, and partner-led remediation where relevant.
- Work with Sales and Customer Success to improve pre-sale scoping, implementation estimates, customer expectation-setting, and handoff quality.
- Collaborate with CMMC partners, MSPs, consultants, auditors, and C3PAOs while maintaining clear boundaries around Secureframe's role in preparation, platform tooling, implementation support, and independent assessment.
- Deliver live customer training and working sessions that help customers assign owners, collect evidence, remediate gaps, and use Secureframe as their operating system for CMMC readiness.
- Build repeatable implementation assets, including kickoff templates, project plans, RACI models, discovery questionnaires, evidence checklists, status reports, readiness criteria, risk registers, and handoff runbooks.
- Identify patterns across implementations and feed those insights back to Product, Engineering, Sales, Customer Success, and leadership.
- Use AI and automation thoughtfully to accelerate repeatable implementation work, summarize customer context, surface risks, and improve time to value.
What Success Looks Like
- Customers know exactly what they need to do, who owns each workstream, and how Secureframe supports their path to readiness.
- Implementations move from broad CMMC ambition to concrete operating rhythm: scoped assets, assigned controls, evidence owners, remediation plans, reporting, and handoff.
- Secureframe develops a repeatable CMMC implementation motion that can serve very small businesses, SMBs, mid-market companies, and more complex defense contractors without reinventing the process every time.
- Sales and Customer Success have sharper implementation packaging, better scoping inputs, and more confidence setting customer expectations.
- Product and Engineering receive clear feedback on what CMMC customers actually need to deploy, prove, and maintain readiness.
About You
- 2-5 years of experience in implementation, professional services, customer success, project management, technical consulting, GRC, security compliance, or a similar customer-facing delivery role.
- You are a builder who enjoys creating structure where it does not yet exist, documenting what works, improving rough processes, and helping a new team scale beyond heroic one-off delivery.
- Comfortable with ambiguity and early-stage operating environments; can make progress with incomplete information, identify the next best step, and keep customers moving.
- Strong project-management instincts to manage timelines, dependencies, risks, executive visibility, and cross-functional accountability.
- Technically fluent enough to discuss identity, endpoints, cloud environments, logging, access control, asset inventory, network boundaries, and secure collaboration with IT and security stakeholders.
- Understand, or are motivated to quickly learn, CMMC, NIST SP 800-171, CUI, FCI, SSPs, POA&Ms, evidence management, audit readiness, and the defense industrial base.
- Can work with a wide range of customers, from founder-led teams with minimal IT capacity to larger organizations managing multiple departments, frameworks, facilities, and stakeholders.
- Customer-centered and pragmatic; can explain complex compliance and technical concepts in plain language and help customers make decisions that fit their business, risk, and timeline.
- Communicate clearly in writing and live meetings, including project plans, status updates, executive summaries, implementation risks, and internal feedback.
- Resourceful with modern tools, including AI, and interested in building smarter workflows for implementation delivery.
Nice to Have
- Experience with CMMC, NIST SP 800-171, DFARS 252.204-7012, FedRAMP, ITAR, GCC High, Azure Government, AWS GovCloud, or defense-sector customers.
- Experience implementing or administering GRC platforms, compliance automation tools, ticketing systems, identity providers, MDM, EDR, SIEM, cloud collaboration suites, or secure enclave environments.
- Experience in professional services, managed services, security consulting, audit readiness, or partner-assisted delivery.
- Project management certification, security certification, or GRC certification such as PMP, CSM, Security+, CISA, CISM, CRISC, CCSK, or equivalent practical experience.
- Experience building implementation playbooks, service packages, onboarding programs, or customer delivery operations from an early stage.
Skills
Cmmc, Nist Sp 800-171, Cui, Fci, Ssp, Poa&M, GRC, Project Management, Compliance Automation, Gcc High, Azure Government, Aws Govcloud, FedRAMP, Itar
Similar jobs
Solutions Architecture jobsForward Deployed Engineer Interns write code and design customer-facing solutions for real-world AI/ML and data science applications. Candidates should be pursuing a bachelor’s or master’s degree, graduating in Spring 2027 or later, and have programming experience in Python, R, or another industry-standard language.
New-grad Forward Deployed Engineer developing custom AI solutions and enhancing customer workflows while working directly with clients. Requires programming experience, passion for AI/ML and data science, strong communication skills, and a 2027 degree graduation date.
Deploy and extend enterprise software in customer environments, building integrations, data pipelines, agent workflows, and tooling. The role requires 2–3 years of software experience, Python and TypeScript familiarity, third-party API integration experience, and comfort working directly with customers.
Early-career graduate program role deploying and configuring Celonis solutions, transforming customer data, and developing analytics and machine-learning use cases. Requires a relevant degree, 0–2 years of experience, basic programming and SQL knowledge, analytical ability, and customer-facing communication skills.
Leads client-facing integration and data projects for a SaaS platform, from scoping through delivery, while troubleshooting complex systems and mentoring teammates. Requires at least two years of technical integration or data-solution experience and strong client communication skills.