Schellman Logo

Schellman

Senior Associate, CMMC

Reposted 8 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
As a Senior Associate in CMMC, you will conduct cybersecurity assessments, manage projects, train team members, and ensure compliance with regulations.
The summary above was generated by AI

Schellman is a Top 50 CPA firm and a leading provider of attestation and compliance services. Our professional services focus on security and privacy audits, assessments, and certifications.  Schellman has become one of the largest cybersecurity assessment firms in the United States without providing any traditional accounting services.  We are an accredited multi-framework ISO Certification Body for security, privacy, business continuity, and quality; a globally licensed PCI Qualified Security Assessor and a top provider to clients serving the federal DoD space as a leading FedRAMP 3PAO and the first assessment firm authorized as a CMMC C3PAO. Our specialty and expertise remain in providing best in class Cybersecurity and IT Audits and Attestations. Our culture, approach with clients, and dedication to our values has led us to consistently be a Great Places to Work certified company and rated as a Best Firms to Work For by Accounting Today and a Glassdoor Best Places to Work. We deeply appreciate our employees, as shown by our first core value – People Come First. This is demonstrated in our culture, benefits, and how we handle business. Come see what makes Schellman special!

JOB SUMMARY 

Senior associates are primarily responsible for hands-on project execution.  Experienced senior associates have, or are working towards, specialization in one or more service lines and are assigned to projects accordingly. Senior associates are assigned to a specific service delivery principal that is responsible for supervising the associate’s career development.  Additionally, senior associate’s daily activities are closely supervised by the management teams of their assigned projects. Senior associates may supervise associates and/or senior associates when serving as a member of a project management team. 

As a CMMC Senior Associate at Schellman, you will play a critical role in delivering high-quality cybersecurity assessments for clients seeking compliance and assessment primarily for CMMC and NIST SP 800-171/2. You will be responsible for executing gap assessments, compliance assessments, and formal certification assessments across a diverse range of environments, including defense contractors, manufacturers, professional services firms, technology providers, and managed service providers. You will also be cross-trained to support FedRAMP and other engagements based on NIST 800-53, contributing to Schellman’s broader Federal Practice. 

CMMC Senior Associates perform a variety of responsibilities from start to finish during a project, including:  

  • Interviewing client Subject Matter Experts for different fields of the organization, including technical areas as well as Human Resources, SecDevOps, SOC/NOC, and Internal Compliance;   

  • Performing walkthroughs of client on-premise, cloud, and hybrid architectures 

  • Reviewing system security and technical configurations as they pertain to NIST 800-171 control requirements and CMMC scoping considerations; 

  • Analyzing technical documentation such as system security plans (SSPs), policies, procedures, and evidence artifacts;  

  • Documenting assessment findings, developing scoring rationales, and drafting formal deliverables; and 

  • Maintaining awareness of evolving DoD and CMMC program requirements, including updates to the CAP, scoping guides, and assessment guides to support Schellman methodology updates and client education. 

  • Working in Schellman’s Federal Practice will lead to the natural honing of your technical skills in a variety of fields including cryptography, network structures, system security tools, and CI/CD. You’ll also improve your understanding of organizational controls such as security training programs, configuration management/ system development, and incident response processes. But more than that, a career at Schellman will also support outside opportunities for further education through additional training and the pursuit of industry-accepted certifications such as CISA, CISSP, and others. 

CMMC assessors should expect to travel a minimum of 25% for onsite assessment activities. 

Essential Functions: 

  • Complying with Schellman’s code of ethics and professional conduct, methodologies, policies, and procedures 

  • Adhering to the professional and regulatory standards relevant to assigned service line specialization(s) 

  • Promoting Schellman’s company culture and exemplifying Schellman's values 

  • Establishing high quality relationships and rapport with client personnel 

  • Managing client expectations to ensure expectations are exceeded 

  • Completing assigned duties in a timely manner and with a high attention to detail 

  • Collaborating with fellow project team members in a productive and timely manner throughout the life cycle of each project 

  • Adhering to project schedules and keeping fellow project team members apprised of the progress of assigned tasks 

  • Escalating issues internally in a proper and timely manner 

  • Using discretion and decorum in the timing, form, and content of all client communications 

  • Booking travel reservations in a timely manner and in accordance with Schellman's travel and expense policies and procedures 

  • Performing the essential functions of other service delivery positions when qualified and called upon to do so 

  • Attending project kick-off and closing meetings 

  • Executing assigned testing procedures, performing detailed analysis, reaching conclusions, documenting results in accordance with company standards and CMMC requirements and guidance (e.g., CAP, 32 CFR Part 170), and suggesting ideas for improvements, where applicable 

  • Drafting project deliverables 

  • Serving as a contact for clients' basic questions regarding an engagement 

  • Participating in recruiting and candidate interview activities 

  • Training project team members 

  • Acclimating newer team members to Schellman 

  • Contributing to Schellman's practice development efforts 

  • Developing an expert knowledge of professional and regulatory standards relevant to assigned service line specialization(s) 

  • Contributing to Schellman's thought leadership (e.g., articles, webinars, public speaking, etc.) 

  • Collaborate with internal teams to ensure consistent application of methodologies and quality standards. 

  • Support client education and advisory efforts related to CMMC and NIST SP 800-171 compliance. 

  • Participate in FedRAMP readiness and assessment engagements as part of cross-training and service line expansion. 

  • Contribute to Schellman’s thought leadership through webinars, articles, and public speaking. 

 

Knowledge, Skills, and Abilities: 

  • Working knowledge of Schellman’s services, methodology, and relevant professional standards 

  • Requisite knowledge of applicable technology and security domains 

  • High level of attention to detail and quality of work product 

  • Client service oriented 

  • Excellent time management, organizational, and verbal and written communication skills 

  • Ability to work on-site or remotely as a valuable contributor to a collaborative team 

  • Capable of simultaneously managing assigned tasks for multiple projects 

  • Proficient using Microsoft Word, Excel, and PowerPoint, as well as Schellman’s service delivery applications 

  • Full understanding and application of ethics, independence and Schellman’s values 

Education, Work Experience and Certifications 

  • Bachelor's degree in accounting, finance, business management, technology, or other relevant subject area, or equivalent years of experience directly related to the duties and responsibilities specified 

  • Has completed at least one year of service at Schellman or relevant professional services experience in financial auditing, operational auditing, information systems auditing, internal auditing, information security management or consulting and/or risk consulting 

  • Must have CCP and a favorable Tier 3 determination from DoD  

  • Ideal candidate has all 3 of the following certifications: CCP, CCA, and a favorable Tier 3 determination from DoD  

 

Schellman is an equal opportunity employer (EOE) and strongly supports diversity in the workplace; therefore, providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. Schellman uses E-Verify in our hiring process.
 

At Schellman, we strive to provide a flexible and balanced environment and therefore offer the opportunity to work remotely, unless otherwise stated in the job requirements. Connecting, collaborating and continuous education are also highly valued and therefore we require some travel annually for our Internal Service Delivery roles, which can include in-person training, team meet-ups, and strategy meetings. Service Delivery team members will also be required to travel based on business and client needs.

Top Skills

Cmmc
Cybersecurity
Fedramp
Giac
Nist 800-171
Pci
Ssp

Similar Jobs

15 Minutes Ago
Remote or Hybrid
70K-90K Annually
Entry level
70K-90K Annually
Entry level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
The Administrative Assistant provides support to the SVP of Global Media Operations, managing schedules, organizing meetings, handling travel arrangements, and preparing materials.
Top Skills: ExcelMS OfficeOutlookPowerPointTeamsWord
15 Minutes Ago
Remote or Hybrid
USA
85K-128K Annually
Mid level
85K-128K Annually
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Manage 60-70 Enterprise accounts, develop account strategies, negotiate agreements, engage key decision-makers, and collaborate with cross-functional teams to drive sales.
Top Skills: CloudCybersecuritySaaSSalesforce
16 Minutes Ago
Remote or Hybrid
3 Locations
160K-215K Annually
Senior level
160K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead and manage a federal civilian sales team to drive cybersecurity product sales across the assigned region by developing account strategies, building executive relationships, managing pipeline/forecasting, leveraging partners, and closing deals to exceed revenue targets.
Top Skills: CdmClarityCloudCybersecurityGsaSaaSSalesforceSewp

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account