Senior Consultant, CMMC Cybersecurity Assessor

Multiple Locations: Charlotte, NC, USA • Atlanta, GA, USA • Tysons, VA, USA • Dallas, TX, USA • Tampa, FL, USA

Apply

Company Profile:

At FORVIS, your career is designed with a purpose. We want our team members to thrive professionally and feel the impact their work yields when serving clients, industries, and local communities. This starts by empowering team members to design a career journey that leverages their skills and fuels their passions.

Creating a best-in-class employee experience is at the heart of our vision for the future. With several industry focus areas, multiple service lines, and locations in five geographical regions across the country to choose from, the opportunities for your career are without limit.

About FORVIS

FORVIS is a Top-10 professional services firm providing assurance, tax, and advisory services, driven by our commitment to using our forward vision to provide rewarding career opportunities and deliver unmatched client experiences. Learn more at FORVIS.com

Design your career with purpose at FORVIS. For more information about our firm locations, visit FORVIS.com. FORVIS, LLP is an equal opportunity/affirmative action employer. Employment selection and related decisions are made without regard to age, race, color, sex, sexual orientation, national origin, religion, genetic information, disability, protected veteran status, or other protected classifications.

It is FORVIS's standard policy not to accept unsolicited referrals or resumes from any source other than directly from candidates.

• FORVIS expressly reserves the right not to consider unsolicited referrals and/or resumes from vendors including and without limitation, search firms, staffing agencies, fee-based referral services, and recruiting agencies.
• FORVIS further reserves the right not to pay a fee to a recruiter or agency unless such recruiter or agency has a signed vendor agreement with FORVIS.
• Any resume or CV submitted to any employee of FORVIS without having a FORVIS vendor agreement in place will be considered the property of FORVIS.

Requisition Number: 2235585

Position Title:

External Description: Description & Requirements

The IT Risk & Compliance team helps organizations manage IT governance, cybersecurity, and regulatory compliance across industries. With expertise in frameworks like CMMC, NIST, and ISO 27001, they offer services including IT audits, risk assessments, ransomware simulations, and control testing. Their tailored strategies ensure data security, regulatory alignment, and operational continuity-empowering clients to navigate today's complex digital risk landscape with confidence.

What You Will Do:

  • Support cybersecurity assessments by following government and industry standards like CMMC, NIST 800-171, NIST 800-53, and FedRAMP/StateRAMP.
  • Review IT systems to identify security issues or compliance gaps. Document findings and recommend practical solutions.
  • Assist with assessments based on NIST 800-171 to prepare for CMMC Level 2 certification.
  • Collaborate with team members and clients across industries on cybersecurity projects.
  • Contribute to defining system boundaries to determine which parts of the IT environment are in scope for compliance.
  • Draft and maintain documentation such as security plans, policies, procedures, and action plans.
  • Participate in designing tools, workflows, and processes that meet compliance needs and reduce risk.
  • Coordinate tasks across multiple projects to ensure deadlines and budgets are met.

Minimum Qualifications:

  • Associate's Degree in Cybersecurity, Management Information Systems (MIS), Computer Science, or a related field; or a minimum of six years of relevant experience.
  • 2+ years of relevant experience in cybersecurity, IT audit, or governance, risk, and compliance
  • Experience providing consulting, assessment, or implementation services associated with federal cyber compliance frameworks
  • Working knowledge of cyber risk management frameworks (CMMC / NIST 800-171, FISMA, FedRAMP, NIST Cybersecurity Framework, NIST SP 800-53)
  • General knowledge of common compliance frameworks (PCI DSS, ISO 27001, HIPAA/HITRUST)
  • Proficiency in Microsoft Office Suite

Preferred Qualifications:

  • Bachelor's Degree in Cybersecurity, MIS, Computer Science, or a relevant field
  • Professional services or consulting experience
  • CMMC Certified Assessor (CCA) credential
  • Current and valid cybersecurity and/or privacy-related certification(s), including but not limited to the following: CISSP, CISA, CISM, QSA, and CIPP

#LI-TPA, #LI-ATL, #LI-CLTSP, #LI-DFW, #LI-TYS

#LI-GM1

City: Charlotte

State: North Carolina

Community / Marketing Title: Senior Consultant, CMMC Cybersecurity Assessor

Location_formattedLocationLong: Charlotte, North Carolina US

CountryEEOText_Description:

With a legacy spanning more than 100 years, Forvis Mazars is committed to providing a different perspective and an unmatched client experience that feels right, personal and natural. We respect and reflect the range of perspectives, knowledge and local understanding of our people and clients. We take the time to listen to deliver consistent audit and assurance, tax, advisory and consulting services worldwide.

We nurture a deep understanding of our clients’ industries, delivering greater insight, deeper specialization and tailored solutions through people who listen to understand, are responsive and consult with purpose to deliver value.

About Forvis Mazars, LLP

Forvis Mazars, LLP is an independent member of Forvis Mazars Global, a leading global professional services network. Ranked among the largest public accounting firms in the United States, the firm’s 7,000 dedicated team members provide an Unmatched Client Experience® through the delivery of assurance, tax, and consulting services for clients in all 50 states and internationally through the global network. Visit forvismazars.us to learn more.

Forvis Mazars, LLP is an equal opportunity/affirmative action employer. Employment selection and related decisions are made without regard to age, race, color, sex, sexual orientation, national origin, religion, genetic information, disability, protected veteran status, gender identity, or other protected classifications.
It is Forvis Mazars, LLP standard policy not to accept unsolicited referrals or resumes from any source other than directly from candidates.

Forvis Mazars, LLP expressly reserves the right not to consider unsolicited referrals and/or resumes from vendors including and without limitation, search firms, staffing agencies, fee-based referral services, and recruiting agencies.
Forvis Mazars, LLP further reserves the right not to pay a fee to a recruiter or agency unless such recruiter or agency has a signed vendor agreement with Forvis Mazars, LLP.Any resume or CV submitted to any employee of Forvis Mazars, LLP without having a Forvis Mazars, LLP vendor agreement in place will be considered the property of Forvis Mazars, LLP.