Jobs · Legal · Colorado

CMMC Compliance Manager

PCL Construction · Denver, CO · 4 days ago
Legal$127k–$175k/yrFull-time

Responsibilities

  • Manages the company’s CMMC compliance and government cybersecurity program across the PCL’s U.S.-based operations, with accountability for readiness, assessment preparation, and ongoing compliance.
  • Establishes, maintains, and enforces the cybersecurity compliance framework, including policies, procedures, standards, workflows, control ownership models, system security plans, POA&Ms, compliance matrices, evidence inventories, and readiness trackers across the U.S.
  • Owns implementation and sustainment of NIST SP 800-171, CMMC, DFARS/FAR safeguarding requirements, and related CUI handling obligations across applicable U.S. government contract work.
  • Leads day-to-day cross-functional execution of required technical and administrative controls, coordinating with business technology, information technology, cybersecurity, legal/compliance, contracts, operations, and other stakeholders to drive delivery, timelines, evidence collection, and issue resolution.
  • Owes CMMC readiness and assessment preparation, including boundary definition, control narratives, inheritance strategy, evidence organization, assessment support files, and engagement with assessors, customers, and external auditors.
  • Maintains cybersecurity requirements in solicitations, contracts, modifications, and flow-down provisions, including DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, FAR 52.204-21, and related safeguarding clauses.
  • Coordinates subcontractor and supplier compliance activities where cybersecurity clauses, safeguarding requirements, or CUI handling obligations apply.
  • Tracks remediation items, follow-up actions, milestone dates, and compliance gaps to closure, and maintains audit-ready records in designated repositories in accordance with company governance requirements.
  • Supports incident reporting workflows, escalation paths, and documentation related to government cybersecurity reporting obligations.
  • Develops and administers role-based training and awareness for CMMC, CUI handling, safeguarding obligations, and project-level compliance execution.
  • Prepares recurring status reports, dashboards, metrics, and executive summaries regarding cybersecurity compliance posture, readiness, and program progress.
  • Participates in internal working groups and stays current on changes to government cybersecurity requirements, assessing impacts and communicating updates to internal stakeholders.

Qualifications

  • Bachelor’s degree in cybersecurity, information systems, business, legal studies, government contracting, compliance, or related field preferred.
  • Minimum 3–7 years of experience in government contract compliance, cybersecurity compliance, IT governance, audit support, risk management, or related work.
  • Experience supporting U.S. government contract requirements strongly preferred.
  • Working knowledge of CMMC, NIST SP 800-171, DFARS cyber clauses, FAR safeguarding requirements, and Controlled Unclassified Information requirements preferred.
  • Experience coordinating compliance documentation, assessments, evidence collection, or audit support strongly preferred.
  • Familiarity with policy/procedure management, issue tracking, database development and corrective action follow-up.
  • Experience working across legal/compliance, IT, contracts, operations, and business stakeholders preferred.
  • Demonstrated ability to work as member of a team and trusted client advisor.
  • Ability to establish and maintain good rapport with executives, district office management and other internal clients.

Similar jobs

Regulatory CMC Manager

Neurocrine BiosciencesSan Diego, CA· 2 wk ago
Legal$133k–$182k/yrapply on neurocrine.wd5.myworkdayjobs.com

Clinical Compliance Manager

Neurocrine BiosciencesSan Diego, CA· 1 wk ago
Legal$131k–$179k/yrapply on neurocrine.wd5.myworkdayjobs.com