Remote job
Chief Information Officer (CIO) – CMMC Compliance (Part-Time)
Job details
About this role
Role overview
A part-time fractional executive position is available for a seasoned Chief Information Officer to serve as the senior accountable leader for an organization's Cybersecurity Maturity Model Certification (CMMC) Level 2 program and Microsoft GCC High environment. The role centers on executive governance of compliance, risk, and security architecture rather than day-to-day IT operations, with roughly 20–40 hours of commitment each month and heavier involvement around audit windows. It is well suited to a retired or semi-retired executive who has guided a defense contractor or federal-focused organization through CMMC certification.
Responsibilities
- Serve as the designated executive owner of all CMMC-aligned activities and the systems that process, store, or transmit Controlled Unclassified Information (CUI). - Provide executive oversight of the CMMC Level 2 program, reviewing and approving policies, the System Security Plan, the CUI Management Plan, the POA&M, the Risk Register, and supporting evidence. - Lead risk management activities, including periodic assessments, treatment decisions, remediation oversight, and quarterly executive risk reviews. - Provide strategic oversight of the Microsoft GCC High environment, identity and access management, conditional access, endpoint security, monitoring, and incident response. - Participate in mock assessments, C3PAO assessments, and assessor interviews, ensuring artifacts accurately reflect implemented controls. - Engage with C3PAOs, compliance consultants, managed service providers, Microsoft partners, and federal customer representatives on scope and remediation matters.
Requirements
- At least 15 years of progressive IT leadership experience, including prior service as CIO, CISO, or an equivalent executive role. - Demonstrated history supporting CMMC Level 2 or NIST SP 800-171 compliance programs within DoD, federal contractor, or defense-industrial-base environments. - Working knowledge of Microsoft 365 GCC High, Entra ID, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Intune. - Experience aligning cybersecurity initiatives with federal regulations and contract requirements, including handling CUI and supporting executive attestations. - Proven ability to lead governance reviews, approve compliance documentation, and brief executive leadership on certification readiness.
Nice to have
- Track record of guiding one or more organizations through an actual CMMC certification. - Familiarity with DFARS 252.204-7012, 7019, 7020, and 7021, including SPRS submissions and executive affirmations. - Credentials such as CISSP, CISM, CGRC (formerly CAP), CCSP, CMMC Certified Professional (CCP), or CMMC Certified Assessor (CCA).
Benefits and work setup
- Remote arrangement with periodic onsite support as required for assessments and executive briefings. - Fractional executive consulting engagement with flexible monthly hours. - Reports to the President and Executive Leadership Team. - Equal opportunity employer committed to considering all qualified applicants.