Location: Remote (U.S.-based preferred)
Engagement Type: Independent Contractor (1099) — B2B / Subcontract Basis
Compensation: $88–$110/hour DOE
Hours: Project-based, flexible — scoped around your availability and client demand
About the Role
We are an established Managed Services Provider (MSP) looking to partner with independent cybersecurity and compliance consulting solo practitioners to support client engagements around CMMC 2.0 readiness and certification and broader security posture improvement for organizations pursuing or maintaining Department of Defense (DoD) contract eligibility.
This engagement is built for consultants who run their own IT or cybersecurity practice and are looking to take on additional project-based work without giving up ownership of their business. You'll work as an independent subcontractor — not an employee — bringing your own expertise, methodology, and tools to supplement client engagements alongside our MSP engineering team.
We're flexible on engagement structure: single-project statements of work, ongoing part-time capacity, or overflow support during peak assessment periods. You set your availability; we scope the work around it. This is well suited to consultants who already serve their own client base and want to fill capacity with additional project work, or who prefer the autonomy of contract-to-contract engagements over a single fixed placement.
You will work directly with client leadership, internal IT teams, and our MSP engineers to assess environments, identify compliance gaps against CMMC 2.0 requirements, and guide organizations through certification readiness.
Responsibilities
- Conduct cybersecurity and compliance assessments aligned to CMMC 2.0 requirements across Level 1 (Foundational) and Level 2 (Advanced) scopes
- Perform gap analyses against NIST SP 800-171 Rev. 2 (and awareness of the Rev. 3 transition) and map findings to the CMMC 2.0 assessment scope
- Support development and maintenance of a System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
- Assist clients with SPRS (Supplier Performance Risk System) score calculation and submission readiness
- Help clients prepare for self-assessments, C3PAO-led certification assessments, or DIBCAC engagements, depending on required CMMC level
- Develop and review security policies, procedures, and system documentation required for audit evidence
- Recommend and help implement remediation plans and security controls to close identified gaps
- Collaborate with internal MSP engineers and client stakeholders throughout the engagement
- Assist with incident response planning, risk assessments, and general security best practices
- Participate in client meetings and provide executive-level guidance on compliance posture and timelines
- Help organizations mature their overall security operations and general audit readiness
Required Qualifications
- Active independent consulting practice, LLC, or S-Corp (or willingness to engage on a B2B/1099 basis) — this role is structured for business owners, not W-2 placement
- Proven, hands-on experience preparing organizations for CMMC 2.0 — not just general cybersecurity consulting
- One or more of the following credentials strongly preferred:
- CMMC Certified Professional (CCP) or CMMC Certified Assessor (CCA) — Cyber AB credentials
- CISSP
- CISA or equivalent GRC/compliance certification
- Strong working knowledge of:
- NIST SP 800-171 / NIST SP 800-172 (for Level 3 awareness)
- NIST Cybersecurity Framework
- CMMC 2.0 scoping, assessment methodology, and documentation requirements (SSP, POA&M, SPRS)
- Microsoft 365 GCC High / commercial security and compliance tools
- Endpoint protection and identity management
- MFA, conditional access, and security hardening
- Experience working with government contractors, defense manufacturers, or other CUI-handling regulated environments
- Ability to independently manage client engagements and communicate professionally with executives
- Strong documentation and technical writing skills
- Prior MSP, MSSP, or independent consulting experience highly preferred
Preferred Technical Experience
- Microsoft Defender suite
- Azure AD / Entra ID
- SIEM/SOC tooling
- Vulnerability management platforms
- Security awareness training programs
- Backup, disaster recovery, and ransomware mitigation strategies
- Secure network architecture, firewall technologies, and CUI enclave design
Why This Engagement Works for Independent Consultants
- You stay independent. This is a subcontract relationship, not an offer of employment — invoice under your own business, retain your other clients, and set the terms of your availability
- No exclusivity required. Take on as much or as little project work as fits alongside your existing book of business
- Project-based and recurring work available. Single engagements, overflow capacity, or longer-term recurring project relationships — your choice
- Remote-first, with occasional client-facing calls during standard business hours for scheduled engagements
- Long-term potential for a steady pipeline of CMMC 2.0 project work as client demand grows
To Apply
Please submit a resume or company capability statement highlighting your cybersecurity consulting, CMMC 2.0, and NIST 800-171 experience, along with your business structure (independent contractor, LLC, etc.) and current availability for project work.
Pay: $88.00 - $110.00 per hour
Benefits:
Application Question(s):
- Are you an independent Security Consultant that has flexibility in their schedule to work with our customers?
Experience:
- government contractors, defense manufacturers: 5 years (Preferred)
- CMMC 2.0: 5 years (Preferred)
Work Location: Remote