Insight Global logo

CMMC Security Architect - Research

Insight Global

Santa Barbara, CAJobNo compensation foundPosted 1mo agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Santa Barbara, CA
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

CISSPCISMSecurity+CMMC-Related Credentials

Job overview

Insight Global is hiring a CMMC Security Architect - Research. The CMMC Security Architect will serve as a senior cybersecurity compliance lead, supporting a university's CMMC readiness and certification efforts across complex research environments. This role involves owning CMMC compliance execution, partnering with IT Security, Research IT, Export Compliance, and faculty. The individual will assess existing research environments, guide remediation, and design scalable frameworks for secure enclaves handling sensitive data.

Key focus areas include Serve as the central owner of CMMC compliance execution, Partner across IT Security, Research IT, Export Compliance, and faculty stakeholders, and Align security requirements with how research is conducted.

Successful candidates bring 10+ Years Cybersecurity Experience. Important skills include CMMC Compliance Execution, Security Architecture, Compliance Leadership, Program Execution, CMMC / NIST SP 800-171 Controls Implementation, and CMMC Level 2 Audits Preparation. Preferred (not required): CMMC Level 2 Certification Support and External Audits (C3PAO) Support.

Skills & qualifications

RequiredNice to have

Skills

CMMC Compliance ExecutionSecurity ArchitectureCompliance LeadershipProgram ExecutionCMMC / NIST SP 800-171 Controls ImplementationCMMC Level 2 Audits PreparationRegulated EnvironmentsDetailed Gap Assessments Against CMMC / NIST 800-171Audit Readiness EffortsC3PAO Assessments PreparationCompliance Documentation DevelopmentSystem Security Plans (SSPs)POA&MsAudit ArtifactsTranslate Compliance Requirements Into Actionable Implementation PlansSystem Boundaries and Enclave Design for CUI EnvironmentsEnd-to-End Data Flow MappingSecurity Control AlignmentCUI ScopingAsset CategorizationComplex, Distributed EnvironmentsCollaboration Across Technical TeamsCollaboration Across Non-Technical StakeholdersTranslate Complex Security Requirements Into Practical WorkflowsResearch EnvironmentsHigher Education Security ModelsMulti-Enclave or Distributed IT EnvironmentsNon-Standard InfrastructureLab SystemsShared Research EquipmentCMMC Level 2 Certification SupportExternal Audits (C3PAO) SupportExport Control / Research Compliance RequirementsGrant-Funded or Federally Sponsored Programs

Qualifications

10+ Years Cybersecurity Experience10+ Years Information Security Experience10+ Years Compliance-Driven Environments ExperienceCISSPCISMSecurity+CMMC-Related Credentials

Full job description

Job Description

We are seeking a senior cybersecurity compliance lead to support a university’s effort to achieve CMMC (Cybersecurity Maturity Model Certification) readiness and certification across complex research environments.

This individual will serve as the central owner of CMMC compliance execution, partnering across IT Security, Research IT, Export Compliance, and faculty stakeholders to align security requirements with how research is actually conducted.

The role is a blend of security architecture, compliance leadership, and program execution. This person will assess existing research environments, guide remediation efforts, and design scalable frameworks that enable multiple independent labs to operate within compliant, secure enclaves handling sensitive data (e.g., CUI, ITAR).

In addition to driving audit readiness, this individual will support the full research data lifecycle, working with researchers during proposal planning to define security requirements and ensuring secure handling of data through project execution and disposal.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements

~10+ years of experience in cybersecurity, information security, or compliance-driven environments

Hands-on experience implementing CMMC / NIST SP 800-171 controls and preparing environments for CMMC Level 2 audits

Experience working in regulated environments (e.g., DoD, federal, ITAR, CUI systems)

Proven ability to:

  • Conduct detailed gap assessments against CMMC / NIST 800-171

  • Drive audit readiness efforts, including preparation for C3PAO assessments

  • Develop and maintain compliance documentation (e.g., - System Security Plans (SSPs), POA&Ms, audit artifacts)

  • Translate compliance requirements into actionable implementation plans for technical teams

Strong understanding of:

  • System boundaries and enclave design for CUI environments

  • End-to-end data flow mapping and security control alignment

  • CUI scoping and asset categorization

Experience working across complex, distributed environments (e.g., multiple enclaves, hybrid on-prem/cloud systems)

Ability to operate as a lead-level resource, collaborating across technical teams and non-technical stakeholders (e.g., faculty, researchers, export control) to drive execution and translate complex security requirements into practical workflows Experience working in:

  • Research environments (universities, labs, or R&D orgs)

  • Higher education security models

Prior exposure to:

  • Multi-enclave or distributed IT environments (non-standard infrastructure, lab systems, shared research equipment)

  • Experience supporting CMMC Level 2 certification or external audits (C3PAO)

Familiarity with:

  • Export control / research compliance requirements

  • Grant-funded or federally sponsored programs

Certifications such as:

  • CISSP, CISM, Security+, CMMC-related credentials

You've read the whole posting — now see how you match it.