Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

CMMC Consultant

AT Deloitte
Deloitte

CMMC Consultant

San Diego, CA

Position Summary

CMMC Senior Consultant

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

The recruiting for this role ends on 8/31/2025.

Work You'll Do

Deloitte provides CMMC advisory and implementation services to help clients achieve and maintain CMMC compliance. By combining our cyber risk and regulatory process expertise with deep technical knowledge, we deliver a full spectrum of services, including:

Want more jobs like this?

Get jobs in San Diego, CA delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


  • Advise: Develop CMMC compliance strategies, gap assessments, readiness roadmaps, policy and procedure development, risk and control frameworks, and stakeholder training.
  • Implement: Support the design and deployment of CMMC-compliant processes and technical controls, leveraging accelerators, templates, and proven methodologies.
  • Operate: Assist clients in ongoing CMMC program management, continuous monitoring, remediation activities, and preparation for CMMC assessments.

As a CMMC Senior Consultant, you will help organizations develop practical solutions to achieve and sustain CMMC compliance.

Key Responsibilities:

  • Leading and supporting CMMC readiness assessments and gap analyses for clients in the Defense Industrial Base (DIB) and other regulated sectors.
  • Developing comprehensive compliance roadmaps and creating detailed Plans of Action and Milestones (POA&M) to guide remediation efforts.
  • Designing and documenting cybersecurity policies, procedures, and process flows to align with CMMC requirements.
  • Distinguishing between compliance requirements and technical implementation, ensuring both policy documentation and operational practices align with CMMC domains such as Access Control, Incident Response, and Risk Management.
  • Engaging stakeholders by facilitating meetings, gathering requirements, and communicating complex compliance concepts to diverse audiences.
  • Collaborating with client stakeholders (CIO, CISO, IT, compliance, and business leaders) to build consensus and drive CMMC initiatives.
  • Facilitating CMMC awareness sessions, user training, and readiness workshops.
  • Demonstrating flexibility in prioritizing and completing tasks, and maintaining a self-starter mindset.

The Team

Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.

Skills and Qualifications

Required:

  • 4+ years of experience in cybersecurity, risk management, or compliance consulting, with a focus on frameworks such as NIST SP 800-171, CMMC, or similar.
  • 2+ years of experience performing gap assessments, readiness reviews, or remediation planning for CMMC or related regulatory requirements.
  • Experience designing and implementing cybersecurity policies, procedures, and technical controls aligned to CMMC practices.
  • Strong understanding of CMMC domains, practices, and assessment methodology.
  • Experience working with clients to define business and functional requirements and supporting implementation of compliance solutions.
  • BA/BS Degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Technology, or related field.
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited sponsorship maybe available.

Preferred:

  • Previous consulting or Big 4 experience.
  • Experience supporting organizations in the Defense Industrial Base (DIB) or federal sector.
  • Certifications such as CMMC-AB Certified Professional (CP) or Certified Assessor (CA), CISSP, CISM, CISA, or similar.
  • Experience with security tools and platforms supporting CMMC compliance (e.g., GRC, vulnerability management, endpoint security).

Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,225 - 155,375.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any depends on various factors, including, without limitation, individual and organizational performance.

Recruiting tips

From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.

Benefits

At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.

Our people and culture

Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.

Our purpose

Deloitte's purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.

Professional development

From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.

As used in this posting, "Deloitte" means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Requisition code: 303837

Job ID 303837

Client-provided location(s): San Diego, CA, USA
Job ID: Deloitte-303837
Employment Type: Other