
This is a detail-oriented and proactive role to support and enhance our client’s governance, risk management, and CMMC compliance. This role is responsible for identifying, assessing, and mitigating risks while ensuring adherence to regulatory requirements, industry standards, and policies.
This role requires a strong working knowledge of CMMC Level 1 and Level 2 requirements. The individual will be responsible for scoping client environments to determine applicable compliance obligations, including the need for Microsoft 365 GCC or Microsoft 365 GCC High, as well as evaluating network architecture and physical security considerations.
The role involves active participation in client meetings, providing guidance on required documentation, and addressing client inquiries related to their CMMC compliance. The individual will participate in client assessments by leading or responding to questions concerning documentation, system environments, and control implementation.
Additionally, this position serves as an internal subject matter expert, providing advisory support to team members on CMMC-related matters and ensuring consistent interpretation and application of requirements across engagements.
The GRC Specialist will work directly with the Compliance Officer for direction as well as the GRC Admin in the preparation of documentation.
Key Responsibilities
Client Meetings
Documentation & Additional Responsibilities
Required Skills & Attributes
Preferred (Not Required) Experience
Why This Role Matters
Consistency and accuracy in scoping and documentation directly affect a client’s ability to pass a CMMC assessment. This role ensures that all GRC processes and procedures have been followed so the client can be validated the same—months or years later—by an assessor.