CMMC / NIST Consultant / Analyst

Other Jobs To Apply

No other job posts for this day.

<p><strong>About the Role</strong> </p> <p>Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements. We are looking for a mid-level CMMC and NIST practitioner who can step into active client delivery work, produce strong documentation, and help move projects forward without a lot of hand-holding. </p> <p>This is a contract role that may be structured as part-time or full-time based on project needs and candidate availability. </p> <p></p> <p><strong>What You Will Do</strong> </p> <p>As a CMMC / NIST Consultant Analyst at Hotman Group you will contribute directly to active client engagements involving federal compliance frameworks. You will: </p> <ul><li>Support client engagements related to CMMC readiness, implementation, and documentation </li><li>Develop, update, and maintain System Security Plans </li><li>Assist with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and related deliverables </li><li>Gather, organize, and review evidence supporting control implementation </li><li>Support CUI scoping discussions, boundary definition, and enclave design </li><li>Draft and refine control narratives, policies, procedures, and related compliance documentation </li><li>Identify gaps and support development of POA&Ms and remediation tracking </li><li>Work directly with client stakeholders to collect information, validate details, and keep deliverables moving </li><li>Contribute to readiness efforts tied to assessments, documentation, and ongoing compliance activities </li><li>Participate in peer review of deliverables before they go to clients — your work will be reviewed and you will review others </li></ul> <p>This is hands-on delivery work in a remote consulting environment. You will be expected to step into active projects and contribute from day one. </p> <p></p> <p><strong>What You Bring</strong> </p> <ul><li>3 to 5 years of relevant experience in GRC, cybersecurity compliance, or related consulting work </li><li>Hands-on experience with CMMC-related work -- this is required, not a nice to have </li><li>Direct experience developing or contributing to System Security Plans, evidence collection, remediation documentation, and compliance policies -- also required </li><li>Familiarity with NIST SP 800-171, NIST SP 800-53, and FedRAMP </li><li>Strong writing and documentation skills -- your deliverables are clear, accurate, and do not require heavy editing before they go to a client </li><li>The ability to work directly with client stakeholders, gather information, manage follow-through, and keep work moving </li><li>Strong organization and professionalism in a client-facing environment </li><li>Comfort stepping into projects that are already in motion and contributing independently with minimal ramp-up time </li><li>A default toward communication — you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client </li></ul> <p>Experience supporting CMMC Level 2 efforts, CUI scoping, enclaves, or boundary discussions is a strong plus. Familiarity with POA&Ms, assessment readiness, and control crosswalks is also valued. </p> <p>Active certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one. </p> <p>This role requires direct accountability for work product and outcomes. If your CMMC or NIST experience has been primarily observational or in a support capacity without ownership of documentation or deliverables, this role will be a significant adjustment. </p> <p></p> <p><strong>Requirements</strong> </p> <ul><li>Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future </li><li>Able to pass a background check </li><li>Reliable high-speed internet and a secure, private remote workspace </li></ul> <p></p> <p><strong>Our Hiring Process</strong> </p> <p>Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on active client engagements. If you are confident in your CMMC and NIST expertise, this is your opportunity to show it. </p> <p></p> <p><strong>Why Hotman Group</strong> </p> <p>At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions. </p> <p>You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it. </p> <p>The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable. </p> <p>If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard — this is the place. </p> <p>No phone calls please. </p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...