Chief Information Officer (CIO) / CMMC Compliance
flexprofessionalsllc.com
Job at a glance
IT and Management Consulting firm based in Vienna, VA, seeks a part-time Chief Information Officer (CIO) with CMMC Compliance knowledge. Hours/Schedule : Approximately 15-20 hours/week depending on compliance activities and assessment schedule. Job Type : Contract to perm Location Requirements : Mostly remote with periodic onsite support as required (1-2 times/month) Rate : $75-85/hour Job Description : Our client is seeking an experienced Part-Time Chief Information Officer (CIO) to provide executive leadership and operational oversight for the organization's Cybersecurity Maturity Model Certification (CMMC) Level 2 program and Microsoft GCC High environment.
The CIO will serve as the executive owner of the organization's CMMC compliance posture, ensuring that cybersecurity controls, governance processes, technical implementations, risk management activities, and assessment preparation efforts remain compliant, sustainable, and audit-ready. This position is ideal for a senior technology executive with deep experience in NIST SP 800-171, CMMC, Microsoft GCC High, federal government contracting, and cybersecurity governance.
This role is intended to provide the organization with an experienced executive capable of serving as the accountable CIO for CMMC compliance while leveraging existing internal resources for day-to-day administration and technical operations. Responsibilities : Executive Leadership & Governance Serve as the organization's designated CIO for all CMMC-related activities. Act as executive owner of systems that process, store, or transmit Controlled Unclassified Information (CUI).
Ensure cybersecurity initiatives align with business objectives, contract requirements, and federal regulations. Provide strategic technology guidance to executive leadership regarding compliance, security, and risk management. Participate in executive compliance reviews and readiness briefings. Support annual affirmations and executive attestations relating to CMMC certification readiness. CMMC Program Oversight Provide executive oversight of the organization's CMMC Level 2 program.
Review and approve CMMC policies, procedures, plans, and compliance artifacts. Ensure alignment among the System Security Plan (SSP), CUI Management Plan, POA&M, Risk Register, and supporting evidence repositories. Review compliance metrics, remediation activities, and audit findings. Support preparation for self-assessments, mock assessments, and formal C3PAO assessments. Participate in assessor interviews and executive-level discussions during audits.
Technical & Security Oversight Provide executive oversight of the Microsoft GCC High environment, Entra ID / Identity & Access Management, Conditional Access and MFA, endpoint security and device management, security monitoring and incident response, vulnerability management activities, and configuration and change management processes. Review security architecture and ensure alignment with CMMC control requirements.
Evaluate impacts of major technology changes on CMMC scope and security posture. Risk Management Lead annual and periodic cybersecurity risk assessments. Review risk treatment decisions and approve risk acceptance recommendations. Ensure corrective actions and remediation plans are effectively managed. Provide governance oversight for POA&M development and closure activities. Monitor compliance risks affecting certification status and federal contract eligibility.
Documentation & Audit Readiness Review and approve the System Security Plan (SSP), Policies and Procedures, Continuous Monitoring Plan, Incident Response Documentation, Risk Assessment Reports, CUI Management Documentation, and Evidence Management Processes. Ensure documentation accurately reflects implemented controls and operational practices. Conduct periodic readiness reviews and executive quality checks on compliance artifacts.
Vendor & External Stakeholder Engagement Interface with C3PAOs, compliance consultants, managed servi