ISI Enterprises is seeking highly skilled individuals with strong technical expertise to join our team as CMMC/NIST 800‑171a Compliance Analysts. As a Managed Network Services provider supporting U.S. Government contractors, ISI Enterprises helps organizations achieve and maintain CMMC compliance through comprehensive assessment, remediation, and ongoing security governance.
Duties/Responsibilities:
- Lead and oversee NIST 800‑171a and CMMC gap assessment engagements, including evidence collection, control validation, environment reviews, and remediation planning.
- Utilize AI‑enabled tools to enhance efficiency and accuracy across assessment activities, including evidence gathering, documentation development, and compliance validation.
- Assist clients in developing and maintaining compliant policies, procedures, and required documentation such as Network Design Documents, Software Whitelists, POAMs, and SSPs.
- Provide recommendations and coordinate remediation efforts to address identified compliance gaps, collaborating closely with Cybersecurity, Engineering, and Support teams to ensure proper implementation and testing.
- Facilitate effective communication and collaboration across internal analysts, technical teams, and client stakeholders to ensure alignment and consistent execution throughout the engagement lifecycle.
- Serve as a primary liaison with C3PAO auditors during CMMC Level 2 assessments, supporting audit preparation, evidence submission, and clarifications as needed.
Qualifications
- Due to the nature of this role, candidates must present proof of U.S. citizenship prior to hire in accordance with federal regulations governing access to sensitive government information.
- Minimum of 5 years of experience within the Defense Industrial Base as a compliance analyst or in a closely related cybersecurity or audit function.
- Strong technical background with the ability to understand and articulate not only what NIST 800‑171 controls require, but how they are implemented and validated in practice.
- Current CMMC certification required: RP, CCP, or CCA.
- Previous experience in audit, compliance, or consulting role
- Highly detail oriented, process‑driven, and well‑organized with demonstrated ability to produce accurate and audit‑ready compliance documentation.
- Prior experience working for or directly supporting a Managed Service Provider (MSP).
- Comfortable presenting to clients, senior leaders, and internal teams, with strong professional verbal and written communication skills.
- Familiarity with the NIST Risk Management Framework (RMF) and the CMMC compliance ecosystem, including assessment methodologies and audit expectations.
- Self-starter with a proactive mindset and the ability to independently identify areas for support or process improvement
What We Offer
- Salary range of $90,000–$110,000, commensurate with experience.
- Hybrid work environment offering flexibility while supporting collaboration.
- Competitive salary and comprehensive benefits package.
- A casual, friendly, and supportive workplace culture.
- Professional development support, including certification growth and advancement opportunities.
Industrial Security Integrators, LLC (“IsI”) is an equal opportunity employer committed to affirmative action and diversity in the workplace. It is the policy of IsI to provide Equal Employment Opportunities (EEO) to Employees and Applicants, without regard to race, color, religion, sex, age, marital status, citizenship status, national origin, sexual orientation, gender identity, veteran status or disability or any other factor protected by law and to provide advancement opportunities for minorities, women, disabled individuals, and veterans. IsI is stronger and more effective when our workforce includes highly qualified individuals with diverse backgrounds, cultures, and traditions.
IsI Enterprises does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings or otherwise. Placement fees will not be paid to any recruiter unless IsI has an active agreement in place with the recruiter and such a request has been made by the IsI hiring team and such candidate was submitted to the IsI hiring team via our Applicant Tracking System. Any unsolicited resumes or other data submitted to IsI in violation of this policy may be used by IsI without obligation to pay any fees of any kind to the recruiter.