Cybersecurity: cmmc lead consultant (cca/ccp) — independent contractor
Dhyati · India
Job Description
# CMMC Lead Consultant (CCA/CCP) — Independent Contractor
**Engagement:** Part-time, ~9 months | **Location:** Remote, with periodic short trips to the UAE (expenses covered) | **Rate:** Competitive hourly, commensurate with credentials | **Start:** Near-term
## About the engagement
Dhyati is mobilizing a CMMC Level 2 readiness program for a containerized, cloud-hosted application environment in the Middle East. The program takes the environment from early NIST SP 800-171 maturity to first-pass C3 PAO assessment posture: boundary definition, gap assessment against all 110 controls, CUI enclave architecture, hands-on remediation, full documentation suite, and a mock assessment with Go/No-Go recommendation.
You will be the named CMMC authority on the engagement, directing a capable offshore security engineering and GRC team. They build; you make sure what's built will pass.
## Responsibilities
- Serve as the named CMMC authority for the engagement, representing your credentials and past performance as key personnel
- Own the CMMC technical strategy: assessment boundary definition, CUI data-flow scoping decisions, and control-inheritance approach for the sovereign cloud platform
- Lead the gap assessment against NIST SP 800-171 (110 controls) and approve the remediation roadmap
- Review and approve the CUI enclave architecture (segmentation, trust zones, identity/access model, logging)
- Direct remediation priorities and adjudicate control-implementation questions raised by the engineering team; define evidence standards and review evidence sufficiency the way an assessor would
- Guide the SSP, POA& M, and policy suite to assessor-ready quality
- Support the mock C3 PAO assessment and co-author the Go/No-Go readiness recommendation
- Act as senior client counterpart in phase-gate reviews; attend key onsite milestones in the UAE (kickoff, discovery, remediation verification, mock assessment)
## Required qualifications
- Active **CCA (Certified CMMC Assessor)** credential in good standing with the Cyber AB; strong **CCP** candidates with substantial Level 2 delivery experience will be considered
- Demonstrated delivery of at least 2 CMMC Level 2 or NIST SP 800-171 readiness engagements end-to-end (scoping through assessment or mock assessment)
- Deep working knowledge of NIST SP 800-171 / 800-171 A assessment objectives, CMMC 2.0 scoping guidance, and evidence expectations of C3 PAO assessment teams
- At least one referenceable client willing to speak to your CMMC/800-171 work
- Comfortable directing a remote/offshore engineering team and working across time zones (US/India/UAE overlap)
- Able to travel to the UAE (no visa impediments)
## Preferred
- Experience with containerized/cloud-native environments (Kubernetes, Dev Sec Ops pipelines) and cloud shared-responsibility/control-inheritance mapping
- Experience with non-US or sovereign cloud platforms, or environments without Fed RAMP inheritance
- Prior work as part of, or alongside, a C3 PAO assessment team
- RP/RPA registration history or RPO affiliation
## Engagement structure
Independent contractor (consulting agreement) with milestone-aligned hours: heavier involvement during boundary definition, gap assessment, and validation phases; steady advisory cadence during remediation. Approximately 8–12 hours/week average, with peaks around phase gates and onsite visits. As a named key-personnel role, we ask for a good-faith commitment through the full program (~9 months). Further engagement details shared with shortlisted candidates under NDA.
**To apply / discuss:** Please include your Cyber AB credential ID, a summary of relevant CMMC/800-171 engagements, and your hourly rate.
Details
| Company | Dhyati |
| Location | India |
| Type | FULL TIME |
| Niche | tech |
| Experience | permanent |
