About this role
Lead enterprise Controlled Unclassified Information (CUI) operational compliance and drive CMMC certification readiness for Boeing. Manage a team responsible for documentation, security assessments, audits, remediation closure, and reporting to senior leadership.
Key Responsibilities
- Lead ISSMs and ISSOs for CMMC documentation and technical security assessments
- Manage enterprise CUI compliance operations for protection/handling/dissemination per NIST SP 800-171
- Implement and maintain CMMC compliance strategies, policies, and risk mitigation
- Coordinate assessor engagement, facilitate CMMC assessments, and track remediation closure
- Conduct compliance assessments and audits and monitor regulatory/CMMC updates while briefing leadership
Technical Overview
Own and advance CUI compliance per applicable laws, regulations, and NIST guidance including NIST SP 800-171, while implementing and maintaining CMMC compliance strategies, policies, and audit readiness. Coordinate technical security assessments, manage assessor engagement, and oversee IAM, logging/monitoring, and encryption controls within DoD/DFARS environments.
Ideal Candidate
The ideal candidate is a cybersecurity compliance leader with 10+ years in information security, compliance, or program/project management, with hands-on experience implementing NIST SP 800-171 in DoD/DFARS contractor environments. They have strong CMMC leadership experience (including audits, assessor coordination, remediation tracking, and System Security Plans) and can manage IAM, logging/monitoring, and encryption as part of CUI operational compliance.
Must-Have Skills
Tier 5 Investigation (T5)Single Scope Background Investigation (SSBI)Continuous Vetting program10+ years of experience in information securitycomplianceor project management implementing and maintaining NIST SP 800-171business and/or organizational change managementdeveloping and managing road mapsbudgetstimelinesand stakeholder metricsCMMC compliance in DFARS and DoD contractor environmentsIdentity and Access Management (IAM)logging/monitoringencryption
Nice-to-Have Skills
using security relevant toolssystemsand applications in support of Risk Management Framework (RMF)
Tools & Platforms
Identity and Access Management (IAM) toolslogging/monitoring toolsencryptionSystem Security Plans
Required Skills
Controlled Unclassified Information (CUI) compliance operationsNIST SP 800-171CMMCSystem Security PlansDFARSDoD contractor environmentsIdentity and Access Management (IAM)logging/monitoringencryptionRisk Management Framework (RMF)compliance auditsremediation trackingbusiness and organizational change managementroad mapsbudgetstimelinesstakeholder metrics
Hard Skills
Controlled Unclassified Information (CUI) compliance operationsCUI protectionhandlingand disseminationNIST SP 800-171CMMCCMMC certificationCMMC compliance strategiesCMMC compliance policiesSystem Security Planstechnical security assessmentscompliance assessments and auditsremediation trackingthird-party auditsrisk mitigation strategiesbusiness and organizational change managementroad mapsbudgetstimelinesstakeholder metricsIdentity and Access Management (IAM)IAM toolslogging/monitoringencryptionRisk Management Framework (RMF)DoD contractor environmentsDFARSDoD guidanceCMMC updatesregulatory changesexternal assessor engagementtechnical reporting and briefings to senior leadership
Soft Skills
leadershipteam managementstakeholder managementcross-functional collaborationcommunicationrisk management communicationmentoringexecutive reportingprogram status briefing
Certifications
Preferred
IAM Level 1 DoD 8140.01 (previously 8570.01) compliant certificationCompTIA Security+ CE (CompTIA Security+)Certified Information Systems Security Professional (CISSP)CompTIA Advanced Security Practitioner (CASP) (CASP/CASP+)Certified Information Security Manager (CISM)GIAC? (Not specified; only CAP listed)CAP (designation as listed in posting)
Keywords for Your Resume
Cybersecurity Controlled Unclassified Information (CUI) Compliance Operations Senior ManagerControlled Unclassified Information (CUI)CUI complianceCMMCCMMC certificationSystem Security PlansNIST SP 800-171NIST 800-171DFARSDoDDepartment of Defense guidanceDoD contractorContinuous VettingTier 5 Investigation (T5)Single Scope Background Investigation (SSBI)Identity and Access Management (IAM)IAM toolslogging/monitoringencryptionRisk Management Framework (RMF)DoD 8140.018570.01
Deal Breakers
Must have successfully completed a Tier 5 Investigation (T5) (formerly Single Scope Background Investigation (SSBI)) within the last 5 years or be enrolled in a Continuous Vetting program within the last 5 years, Must have 10+ years of experience implementing and maintaining NIST SP 800-171 or similar NIST compliant environments, Must have experience in CMMC, DFARS, and DoD contractor environments
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile