# CMMC Lead Consultant (CCA/CCP) — Independent Contractor
Engagement: Part time, ~9 months | Location: Remote, with periodic short trips to the UAE (expenses covered) | Rate: Competitive hourly, commensurate with credentials | Start: Near-term
## About the engagement
Dhyati is mobilizing a CMMC Level 2 readiness program for a containerized, cloud-hosted application environment in the Middle East. The program takes the environment from early NIST SP 800-171 maturity to first-pass C3PAO assessment posture: boundary definition, gap assessment against all 110 controls, CUI enclave architecture, hands-on remediation, full documentation suite, and a mock assessment with Go/No-Go recommendation.
You will be the named CMMC authority on the engagement, directing a capable offshore security engineering and GRC team. They build;
you make sure what's built will pass.
## Responsibilities
- Serve as the named CMMC authority for the engagement, representing your credentials and past performance as key personnel
- Own the CMMC technical strategy: assessment boundary definition, CUI data-flow scoping decisions, and control-inheritance approach for the sovereign cloud platform
- Lead the gap assessment against NIST SP 800-171 (110 controls) and approve the remediation roadmap
- Review and approve the CUI enclave architecture (segmentation, trust zones, identity/access model, logging)
- Direct remediation priorities and adjudicate control-implementation questions raised by the engineering team;
define evidence standards and review evidence sufficiency the way an assessor would
- Guide the SSP, POA&M;, and policy suite to assessor-ready quality
- Support the mock C3PAO assessment and co-author the Go/No-Go readiness recommendation
- Act as senior client counterpart in phase-gate reviews;
attend key onsite milestones in the UAE (kickoff, discovery, remediation verification, mock assessment)
## Required qualifications
- Active CCA (Certified CMMC Assessor) credential in positive standing with the Cyber AB;
strong CCP candidates with substantial Level 2 delivery experience will be considered
- Demonstrated delivery of at least 2 CMMC Level 2 or NIST SP 800-171 readiness engagements end-to-end (scoping through assessment or mock assessment)
- Deep working knowledge of NIST SP 800-171 / 800-171A assessment objectives, CMMC 2.0 scoping guidance, and evidence expectations of C3PAO assessment teams
- At least one referenceable client willing to speak to your CMMC/800-171 work
- Comfortable directing a remote/offshore engineering team and working across time zones (US/India/UAE overlap)
- Able to travel to the UAE (no visa impediments)
## Preferred
- Experience with containerized/cloud-native environments (Kubernetes, DevSecOps pipelines) and cloud shared-responsibility/control-inheritance mapping
- Experience with non-US or sovereign cloud platforms, or environments without FedRAMP inheritance
- Prior work as part of, or alongside, a C3PAO assessment team
- RP/RPA registration history or RPO affiliation
## Engagement structure
Independent contractor (consulting agreement) with milestone-aligned hours: heavier involvement during boundary definition, gap assessment, and validation phases;
steady advisory cadenceduring remediation. Approximately 8–12 hours/week average, with peaks around phase gates and onsite visits. As a named key-personnel role, we ask for a good-faith commitment through the full program (~9 months). Further engagement details shared with shortlisted candidates under NDA.
To apply / discuss: Please include your Cyber AB credential ID, a summary of relevant CMMC/800-171 engagements, and your hourly rate.
-
📌 Cybersecurity: Cmmc Lead Consultant (Cca/Ccp) — Independent Contractor (Erode)
🏢 Dhyati
📍 Erode