Only applications submitted through this page and including a resume in PDF format will be considered.
CCA certification and a favorable Tier 3 determination are required for this position. Applicants who do not meet both requirements should not apply.
Position Overview
Resilient IT is seeking a Director of Compliance to lead the company's compliance, cybersecurity assurance, and CMMC programs. This role serves as a senior subject matter expert in CMMC, NIST, ISO/IEC 17020:2012, and related cybersecurity and regulatory requirements, while providing leadership across client advisory, assessment activities, internal compliance, and business development.
The Director of Compliance will be responsible for maintaining and advancing Resilient IT's compliance programs, ensuring that client engagements, assessments, and internal operations are performed in accordance with applicable requirements, established policies and procedures, and the standards expected of an authorized C3PAO and Level 2 Certified MSP. The Director will monitor evolving regulatory and program requirements, translate those changes into actionable guidance, and work across leadership, sales, and technical teams to maintain a consistent, high-quality compliance program.
Director of Compliance Benefits
Employment Options
- Full-time: 40 hours per week
- Part-time: Up to 25 hours per week
- Work arrangement: Remote/telework and/or onsite at our Springfield, VA office
- Employment classification: W-2 employee
- Compensation: Compensation is based on the selected full-time or part-time employment option and corresponding W-2 rate. This is an employee position and is not a 1099 or consultant engagement.
Full-Time Benefits
- Salary range: $140,000–$165,000 annually, depending on qualifications and experience
- 401(k) available
- Generous paid time off (PTO)
- Medical, dental, vision, and life insurance options
- Stipend opportunities may be available for employees who elect to continue coverage through an existing health plan
- Professional development and continuing education opportunities
- Opportunity to work directly with CMMC, NIST, DoD, and ISO/IEC 17020:2012 compliance programs
Benefits eligibility may vary based on employment status and applicable plan requirements.
Only applications submitted through this page and include a resume in PDF will be considered.
Key Responsibilities
Client Relationship
- Lead NIST SP 800-171 readiness assessments and compliance advisory engagements
- Translate CMMC, NIST, DFARS, and related requirements into clear, actionable guidance for client leadership.
- Serve as the primary compliance advisor for clients preparing for CMMC Level 2 assessments.
- Participate in prospective client meetings as the senior Compliance SME.
- Build client confidence by clearly explaining assessment requirements, timelines, risks, and remediation priorities.
-
Maintain appropriate separation between consulting/advisory activities and independent C3PAO assessment activities.
Technical Expertise
-
Serve as a subject matter expert in CMMC, NIST SP 800-171, DFARS, and related DoD cybersecurity requirements.
-
Participate in CMMC assessment engagements under Resilient IT's C3PAO authorization.
- Execute applicable assessment objectives in accordance with the CMMC Assessment Process (CAP), maintaining impartiality, objectivity, and rigor.
- Collaborate with Certified CMMC Assessors and assessment team members to ensure accurate, consistent, and defensible assessment results.
- Provide technical guidance on control implementation, assessment objectives, evidence requirements, and remediation.
- Ensure NIST and compliance-related services are delivered consistently with Resilient IT's established policies and procedures.
-
Support the technical team in maintaining required security evidence, artifacts, and documentation.
Administrative Work
- Maintain compliance documentation, policies, procedures, records, and objective evidence.
- Maintain the evidence and documentation required to demonstrate conformity with ISO/IEC 17020:2012 and applicable Cyber AB C3PAO requirements.
-
Track corrective actions, findings, remediation activities, and compliance commitments through completion.
-
Coordinate preparation for internal reviews, external audits, assessments, surveillance activities, and accreditation activities.
-
Maintain compliance reporting and metrics for leadership.
- Ensure required client and internal compliance records remain accurate, current, and properly controlled.
- Ensure compliance activities remain aligned with Resilient IT's policies, procedures, and C3PAO obligations.
- Maintain and enforce appropriate impartiality, independence, confidentiality, and conflict-of-interest controls applicable to C3PAO assessment activities.
Required Qualifications
-
CMMC Certified Assessor (CCA) with a favorable Tier 3 determination; Lead CCA qualification preferred.
- Demonstrated experience with ISO/IEC 17020:2012 and C3PAO accreditation requirements.
- Demonstrated experience leading or managing a cybersecurity, compliance, GRC, risk, or assessment program.
- Minimum 5 years of experience in cybersecurity, compliance, IT risk management, or a related field.
- Demonstrated expertise in NIST SP 800-171 and DoD compliance requirements.
- Strong communication skills with the ability to simplify technical concepts for executives and clients.
- Prior experience working with managed services providers (MSPs) or regulated industries strongly preferred.
Personal Evolution
-
Maintain current knowledge of CMMC, NIST SP 800-171, DFARS, ISO/IEC 17020:2012, and The Cyber AB requirements.
-
Track changes to CMMC program requirements and communicate their impact to leadership, sales, technical, and delivery teams.
- Continuously improve Resilient IT's compliance methodologies, processes, templates, and guidance.
- Pursue and maintain applicable professional certifications and qualifications.
-
Develop and deliver internal training on CMMC, NIST, ISO/IEC 17020:2012, DFARS, and related compliance requirements.
Autonomy
-
Own and lead Resilient IT's CMMC, NIST, and cybersecurity compliance programs.
- Lead and maintain the organization's ISO/IEC 17020:2012 compliance and C3PAO accreditation program in accordance with The Cyber AB's applicable requirements.
- Establish and maintain the compliance roadmap, priorities, and continuous-improvement initiatives.
- Advise executive leadership on compliance risks, regulatory changes, assessment readiness, and remediation priorities.
- Identify compliance gaps and risks and develop appropriate remediation plans.
- Exercise independent judgment in evaluating compliance risks while escalating significant issues to leadership.
- Provide leadership, mentoring, and subject matter expertise to internal personnel responsible for compliance, cybersecurity, technical delivery, and client services.