HimalayasHimalayas logo
Insight AssuranceIA

Compliance Auditor CCA (CMMC, NIST, HITRUST)

Insight Assurance is a security and compliance firm providing auditing services to organizations, simplifying their journey toward compliance and trust.

Insight Assurance

Employee count: 51-200

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Insight Assurance is a global audit firm on a mission to transform how organizations achieve cybersecurity and compliance. Founded by former Big 4 (EY) professionals, we deliver next-generation audit services across SOC 2, ISO 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks.

We’re not your traditional audit firm — we’re tech-enabled, leveraging compliance automation and advanced collaboration tools to make audits faster, smarter, and more impactful for our clients.

Recognized on the Inc. 5000 and Fast 50 lists, Insight Assurance is one of the fastest-growing global audit firms, with 170+ professionals supporting nearly 2,000 clients across the Americas, EMEA, and APAC.

Position Summary

We are seeking a highly qualified CMMC Certified Assessor (CCA) to lead and execute cybersecurity compliance assessments for defense contractors and suppliers handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The ideal candidate will possess deep knowledge of the Cybersecurity Maturity Model Certification (CMMC) 2.0, NIST SP 800-171, and DFARS 252.204-7012 requirements.

This role will be responsible for conducting readiness assessments, formal CMMC evaluations, and remediation support for clients across the Defense Industrial Base (DIB). The assessor will play a key role in helping organizations achieve and maintain compliance with DoD cybersecurity requirements.

Key Responsibilities

  • Lead and/or participate as a CMMC Certified Assessor (CCA) in official CMMC assessments and readiness reviews for Level 1 and Level 2 certifications under CMMC 2.0.
  • Perform gap analyses comparing client environments against CMMC, NIST SP 800-171/172, and other relevant frameworks.
  • Review, validate, and document compliance artifacts including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), security policies, and technical evidence.
  • Conduct stakeholder interviews, review control implementations, and determine compliance status for required practices and processes.
  • Provide detailed assessment reports, identifying findings, risks, and actionable recommendations for remediation.
  • Collaborate with client teams (IT, InfoSec, Risk, Audit) to build and execute remediation plans that support certification readiness.
  • Stay current with evolving DoD cybersecurity requirements, CMMC 2.0 program updates, and related standards (e.g., NIST CSF, ISO 27001).
  • Communicate assessment results effectively to technical and executive audiences, including C-suite and compliance leadership.
  • Mentor junior team members and contribute to continuous improvement of the company’s CMMC assessment methodology and templates.

Required Qualifications

  • Active CMMC Certified Assessor (CCA) credential issued by The Cyber AB (Cyber Accreditation Body).
  • CCP-level candidates currently progressing toward CCA may be considered for certain roles.
  • U.S. Citizenship (required for DoD-related engagements).
  • 5+ years of professional experience in cybersecurity, compliance, or audit within regulated or defense-related environments.
  • In-depth understanding of CMMC 2.0, NIST SP 800-171/172, and DFARS 252.204-7012/7019/7020 requirements.
  • Proven experience conducting technical security assessments, gap analyses, and compliance reviews.
  • Strong analytical, organizational, and written communication skills.
  • Ability to manage multiple concurrent assessments and client engagements independently.

Preferred Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related discipline (or equivalent work experience).
  • Additional certifications such as CISSP, CISM, CISA, CAP, or Security+.
  • Experience working for or with a Certified Third-Party Assessment Organization (C3PAO).
  • Familiarity with government cloud environments (e.g., Microsoft GCC High, AWS GovCloud).
  • Active or previously held DoD security clearance (Tier 3 or above).

  • BENEFITS
    Flexible Paid Time Off and paid Holidays

    Performance Bonuses

    100% Remote

    Competitive salary and benefits package.
    Opportunities for professional growth and development.
    Collaborative and innovative work environment.

Insight Assurance is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Privacy Notice CCPA:

  • Insight Assurance shares your personal data/information with Greenhouse recruiting because this is the tool we use for the recruitment process.
  • Insight Assurance does not sell personal data/information under any circumstances.
  • You may exercise your rights under personal data protection legislation by reaching out to us via: HR@insightassurance.com or submit a request via mail at 400 N Tampa St. 15th Floor Suite 129, Tampa, FL 33602

Privacy Notice GDPR:

This notice informs you about the categories of Personal Data/ Information and the Purpose and Scope of Processing Activities to be undertaken by Insight Assurance (we, us, our), under its job application and recruitment process.

We resort to Greenhouse.com as the platform that supports our recruitment process, and therefore your Personal Data/ Information will be Processed on this tool (hosted, shared with, cross-referenced, accessed by our team); we have in place contractual terms and the commitment of Greenhouse.com that ensures the Security and Confidentiality plus Purpose limitation with regards to the Processing of your Personal Data.

When you reply to one of your job postings, you voluntarily and freely submit your Personal Data to us; this, allied with the fact that the Processing by us (and over Greenhouse.com) of that Personal Data has the sole Purpose of validating your application and proceeding with the inherent scrutiny and decision, allows us to argue having Legitimate Interest as the applicable Legal Basis to undertake the Processing of your Personal Data under this scope.

We are a U.S. based company, hence some or all Personal Data pertaining to you will be hosted in the U.S.

The categories of Personal Data under Processing consist of:

  • Identification
  • Contact
  • Education and Professional
  • Interview performance
  • Evaluation

You may exercise several Rights as determined under applicable Personal Data Protection legislation, in short:

  • Right of Access – meaning getting information about the Personal Data under Processing by us, except for the information you already know;
  • Right of Erasure – you may ask for us to erase all Personal Data pertaining to you under Processing; this may imply you being excluded from the recruitment process, for without information we cannot proceed with it;
  • Right of Opposition or Restriction of Processing – you may ask us to stop some Processing or restrict the Processing of some Personal Data, this may imply you being excluded from the recruitment process, at our sole discretion also for without information we cannot proceed with it;
  • Rectification – you can rectify your Personal Data at anytime

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Experience

5 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Insight Assurance

Learn more about Insight Assurance and their company culture.

View company profile

Insight Assurance is your partner in the journey towards security and compliance. Established by a team of former Big 4 professionals, we specialize in simplifying the complexities of auditing and compliance for organizations of various sizes. Our story began with a vision to support dynamic startups and industry giants alike, empowering them to navigate the intricate landscape of cybersecurity and regulatory requirements.

At Insight Assurance, we pride ourselves on delivering high-quality audit services that address a wide spectrum of needs, including SOC 1, SOC 2, PCI DSS, ISO certifications, HITRUST, GDPR, and more. Our commitment to client success is unwavering; we strive to build long-term partnerships grounded in trust and transparency. Our team brings together over 150 years of combined experience, ensuring that our solutions are not only innovative but also relevant in today’s ever-evolving digital landscape.

Claim this profileInsight Assurance logoIA

Insight Assurance

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

15 remote jobs at Insight Assurance

Explore the variety of open remote roles at Insight Assurance, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Insight Assurance

Remote companies like Insight Assurance

Find your next opportunity by exploring profiles of companies that are similar to Insight Assurance. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan