{"id":1618704,"url":"https://alion.io/job/balfour-beatty-plc-cmmc-program-manager","title":"CMMC Program Manager","company":{"id":1842250,"name":"Balfour Beatty","domain":"balfourbeatty.com","url":"https://alion.io/company/balfourbeatty-com","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Dayforce","truth_index":{"grade":"B","score":80,"open_postings":3,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":14,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Management","role_family":"Management","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Falls Church, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":78000,"max_usd":147000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":3165},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[],"status":"live","first_seen_at":"2026-09-21T05:00:00Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-11T01:22:59Z","board_verified":true,"closed_at":null,"days_open":19,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":19},"description":"Summary\nBalfour Beatty Construction, LLC (Company), a member of the Balfour Beatty plc group of companies, is searching for a CMMC Program Manager to support its compliance with cyber and physical security requirements for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) associated with the Company’s Federal construction contracts, as well as equivalent requirements in private contracts. Candidates must have a strong working knowledge of FAR and DFARS requirements for the handling of FCI and CUI, excellent analytical, project management, communication, and organizational skills. \nThe selected candidate will ideally work out of our Falls Church, VA, office, but candidates based in Dallas, TX, will be considered as well. This is a hybrid position that requires working in the office three days per week and working from home two days per week.\nThe CMMC Program Manager is responsible for managing, maintaining, and continuously improving the organization's Cybersecurity Maturity Model Certification (CMMC) compliance program for the secure enclave supporting Department of Defense (DoD) and other Federal agency CUI, as well as the Company’s policies and procedures for handling FCI. The CMMC Program Manager will serve as the primary liaison between compliance & ethics, IT, legal, and operations as it relates to governance, reporting, monitoring, assessment and organizational adoption of security requirements necessary to maintain ongoing compliance with NIST SP 800-171, NIST SP 800-137, FAR and DFARS requirements, and CMMC Level 1 and Level 2.\n\nEssential Functions\nServe as the organization's primary internal authority for CMMC compliance within the secure enclave, providing guidance to IT, IT Security, Operations, Human Resources, Legal, Procurement, Communications and executive leadership regarding FCI, CUI and equivalent compliance obligations and governance requirements. \nOwn the organization's CMMC compliance program for the secure enclave, ensuring governance activities remain aligned with organizational objectives, contractual obligations, regulatory requirements, and evolving cybersecurity risks.\nDevelop, maintain, and periodically review the Continuous Monitoring Plan (CMP) and support ISCM procedures.\nDevelop, review, maintain, and coordinate approval of CMMC-related policies, standards, procedures, and supporting documentation.\nDefine and manage ISCM strategy, risk tolerance, and reporting cadence in coordination with the CIO, CISO, CLO, and US Compliance Team.\nLead initial implementation, as well as ongoing assessment of security control effectiveness, including vulnerability identification and reporting, configuration compliance, access reviews, and incident monitoring.\nLead annual CMMC self-assessments, risk assessments, internal audits, certification readiness activities, and coordination with Certified Third-Party Assessment Organizations (C3PAOs) for external CMMC assessments, as applicable.\nPresent compliance status, risk posture, and strategic recommendations to executive leadership and governance committees.\nDevelop and maintain evidence repositories supporting ongoing internal assessments, external certification activities, and audit readiness.\nEnsure compliance documentation—including the System Security Plan (SSP), POA&Ms, policies, procedures, system inventories, data flow diagrams, asset inventories, evidence repositories, and assessment records—remains complete, accurate, and current.\nTrack, report, coordinate, and validate remediation of deviations, exceptions, and findings discovered during monitoring or risk assessments.\nPrepare metrics dashboards and executive reports summarizing enclave risk posture and compliance trends.\nCoordinate compliance activities involving third-party service providers supporting the enclave, including review of agreements, security documentation, and shared responsibility requirements.\nReview proposed changes to enclave architecture, systems, applications, and operational processes to evaluate potential impacts to CMMC compliance and update compliance documentation as necessary.\nCoordinate with IT Operations and IT Security teams to ensure configuration baselines, asset inventories, and system changes remain aligned with approved security configurations and compliance requirements.\nCoordinate or participate in periodic incident response tabletop exercises involving IT, Legal, Human Resources, Executive Leadership, and applicable business stakeholders.\nCollect evidence management, control documentation, and audit preparation.\nCoordinate post-incident reviews, track corrective actions, and ensure lessons learned are incorporated into security controls, policies, procedures, training, and continuous monitoring activities to improve the organization's overall CMMC compliance posture.\nCollaborate with internal stakeholders:\nBusiness Stakeholders: program managers, project managers, and functional owners using enclave resources. Assist with onboarding, offboarding and transfers as needed.\nInternal and secure enclave MSSP and IT Security Teams: administrators, network engineers, and analysts managing enclave systems and monitoring tools.\nPolicy and Procedure Enforcement: detect and document deviations or non-compliance, collaborate with HR and/or Legal to resolve violations, and ensure corrective or disciplinary actions are applied and recorded in accordance with organizational policy and audit requirements.\nCMMC Training Program Management: review, develop, and adjust security awareness or role-based training content to ensure alignment with current government, DOD, and CMMC requirements and to address evolving cyber security and enclave operational risks.\nExecutive Leadership: provide compliance reporting, risk briefings, POA&M status, and recommendations for risk acceptance decisions.\nFamiliarity with export control requirements such as International Traffic in Arms Regulations and Export Administration Regulations.\nContinuously review and improve ISCM processes, automation, and reporting frequency to align with organizational risk tolerance.\nFacilitate risk assessments and coordinate risk acceptance activities with executive leadership where appropriate.\nSupervise and direct security measures necessary for implementing the applicable requirements of the NISPOM and related USG security requirements to ensure the protection of classified information.\nEstablish and execute an insider threat program to gather, integrate, and report relevant and available information indicative of potential or actual insider threat.\nSupport broader Ethics & Compliance initiatives, including performing other ethics, compliance, and special projects as assigned by the Vice President, Ethics & Compliance and as workload and business needs permit.\n\nMinimum Qualifications\nThis position requires access to export-controlled information. To comply with U.S. government regulations and contract obligations applicable so such information, all applicants must be U.S. persons under the U.S. export control regulations.\nBachelor’s degree in Risk Management, Compliance and Regulation, Information Security, Information Systems, or a related field. Equivalent experience working within a Department of Defense agency will also be considered.\n7+ years in cybersecurity, governance, risk management, compliance, or information security, including at least 3 years supporting NIST SP 800-171 related programs.\nHands-on experience with NIST SP 800-137 implementation or continuous monitoring frameworks.\nFamiliarity with NIST SP 800-171, CMMC Level 1 and 2, and FAR and DFARS.\nDemonstrated experience developing or managing System Security Plans (SSP) and POA&Ms.\nStrong analytical, documentation, and executive-reporting skills.\nAbility to coordinate cross-functional teams and enforce accountability.\nComplete FSO training within 6 months of hire if not already completed.\nComplete ITPSO training.\n\nPreferred Qualifications / Certifications\nExperience supporting Department of Defense, Federal Government, or other regulated markets with significant information security requirements.\nCMMC: Certified CMMC Professional (CCP) or Certified CMMC Assessor (CCA) or CMMC Registered Practitioner Advanced (RPA)\nCyber security: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Security+ or CySA+\nExperience operating in secure enclave or DoD contractor environments.\n\nPerformance Indicators\nTimeliness and completeness of annual ISCM assessments\nPercentage of controls with continuous monitoring coverage\nNumber of open POA&M items vs. remediation rate\nAccuracy and quality of compliance metrics / dashboards\nPolicy and Procedure enforcement\nSuccessful CMMC C3PAO recertification every 3 years\n\nPay Rate: $125,000-195,000/year \n*This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee's pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, any collective bargaining agreements, and business or organizational needs. No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, incentive, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law and any applicable plan documents.","description_format":"text","description_chars":9887,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security","AI Agents"],"lifecycle":[{"event":"open","at":"2026-10-01T20:39:57Z"}],"visa":[],"liveness":{"score":38,"band":"fade","label":"Fading","p_open":1,"p_active":0.69,"p_room":0.55,"age_days":19,"expected_fill_days":14,"reasons":["conf:1","velocity","win:tail","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/balfour-beatty-plc-cmmc-program-manager","json_url":"https://alion.io/job/balfour-beatty-plc-cmmc-program-manager.json","meta":{"generated_at":"2026-10-11T02:24:55Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3781,"day_limit":5000,"remaining_today":1219,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":1842250},"rest":"https://alion.io/mcp/rest/get_company?id=1842250"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fbalfour-beatty-plc-cmmc-program-manager"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fbalfour-beatty-plc-cmmc-program-manager"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fbalfour-beatty-plc-cmmc-program-manager"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/balfour-beatty-plc-cmmc-program-manager\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fbalfour-beatty-plc-cmmc-program-manager"}]}