On Call CCMC Assessor - San Diego, CA in San Diego, California at Epsilon Systems Solutions, Inc
Explore Related Opportunities
Job Description
Job ID: 2026-350
Date Posted: 2026-09-10T00:00:00
Location: San Diego, California
Minimum Experience: 2 years
Education: High School Diploma or Equivalent
Epsilon Systems Solutions, Inc., a 100% Employee-owned Company, is currently seeking one part-time, unscheduled (on-call) Certified CMMC Assessor (CCA) in San Diego, CA. This position is performed remotely, with travel to client facilities.
Summary:
The Certified CMMC Assessor (CCA) serves as a qualified assessment team member on Cybersecurity Maturity Model Certification (CMMC) Level 2 certification assessments performed on behalf of the Company's Certified Third-Party Assessor Organization (C3PAO). This is a part-time, unscheduled position: work is assigned by engagement rather than on a fixed weekly schedule, and hours will fluctuate with assessment demand. The ideal candidate is an experienced cybersecurity assessor with deep working knowledge of NIST SP 800-171 Rev. 2, NIST SP 800-171A, 32 CFR Part 170, and the CMMC Assessment Process (CAP), together with the professional independence and judgment required to render defensible certification decisions.
Duties and Responsibilities:
Serve as a Certified Assessor on CMMC Level 2 certification assessment teams under the direction of a Lead CMMC Certified Assessor (LCCA).
Review and validate the Organization Seeking Certification (OSC) assessment scope, asset categorization, System Security Plan (SSP), network and data flow diagrams, and shared responsibility documentation for cloud and external service providers.
Evaluate objective evidence against NIST SP 800-171A assessment objectives using the examine, interview, and test methods; conduct interviews with OSC personnel at all organizational levels.
Determine and document MET, NOT MET, and NOT APPLICABLE findings with clear, defensible rationale, and prepare, review, and quality-check assessment scoring, daily checkpoint briefings, artifacts, and final assessment reports.
Support recording and submission of assessment results in the applicable Government systems of record in accordance with C3PAO procedures and CMMC Program requirements.
Support closeout assessments of limited deficiencies and Plan of Action and Milestones (POA&M) items within the applicable correction period.
Safeguard all OSC data, evidence, and assessment materials in accordance with contract terms, non-disclosure agreements, and CMMC ecosystem confidentiality obligations.
Maintain the CCA credential in good standing, including annual renewal, continuing professional education, and any required delta or refresher training.
Respond to on-call engagement requests within the agreed notification period, confirm availability, and complete conflict-of-interest screening prior to each assignment.
Travel required by this position is estimated to be up to 30% and is engagement-driven, occurring in concentrated multi-day blocks rather than on a routine schedule.
Required Qualifications:
Highschool diploma or equivalency.
Minimum of two (2) years of cybersecurity experience, including at least one (1) year performing security control assessments or audits.
Active Certified CMMC Assessor (CCA) certification in good standing at the time of hire, including the prerequisite Certified CMMC Professional (CCP) credential, and compliance with all applicable ecosystem ethics, impartiality, and conflict-of-interest obligations.
Preferred Qualifications:
At least one active certification aligned to the Intermediate or Advanced proficiency level of DoD Cyber Workforce Framework Work Role 612, Security Control Assessor (e.g., CISSP, CISA, CCSP, CASP+/SecurityX, or GSNA).
Working knowledge of NIST SP 800-171 Rev. 2, NIST SP 800-171A, 32 CFR Part 170, the CMMC Assessment Process (CAP), and DFARS clauses 252.204-7012, -7019, -7020, and -7021, with practical experience evaluating System Security Plans and POA&Ms.
Strong technical writing, interviewing, communication, and problem-solving skills, with the ability to work independently and exercise impartial professional judgment.
Experience authoring Security Assessment Reports (SAR) or navigating the Cyber AB Assessment Information Management (CAIM) system.
Pay Range and Benefits:
The pay range for this role is $45.00 to $55.00 Per Hour. This is a part-time, unscheduled position; hours are not guaranteed and are assigned by engagement, and benefits eligibility (including paid sick leave, 401(k) contributions, and employee stock ownership plan [ESOP] participation) is determined by hours worked in accordance with the governing plan documents. Individual pay rates are determined by a variety of factors and candidate qualifications, such as skills, education, and experience.
ADA Notations:
Some sedentary work is performed in a remote home-office or office setting, with periodic work at client facilities that may include office, manufacturing, warehouse, or other industrial environments.
Must be able to remain in a stationary position and operate a computer for extended periods, including multi-hour interview and evidence review sessions.
Must be able to travel by air and ground to client facilities, including overnight travel, and must be able to drive to client facilities.
Must be able to move about client facilities to observe assets and validate controls, including walking between buildings, climbing stairs, entering server rooms and production floors, and occasionally lifting and carrying equipment weighing up to 25 pounds.
Must be able to work extended or irregular hours during assessment periods, including early morning or evening hours to accommodate client schedules across multiple time zones.
Epsilon Systems Solutions, Inc. is an equal opportunity employer. Qualified candidates will be considered without regard to legally protected characteristics.