- Location
- Charlotte, North Carolina, United States · Atlanta · Charlotte · Nashville · Remote, US
- Workplace
- Remote
- Department
- Management
- Seniority
- Manager
- Experience
- 7+ years
Description
Join Frazier & Deeter and be a part of a rapidly growing Top 50 accounting & advisory firm that has been repeatedly named a Best Firm to Work For, a Best Firm for Women and a Pacesetter firm among U.S. accounting firms. With several offices across the U.S., UK, and India, there is a spot for you!
We serve clients of all sizes across the United States and the globe, with a suite of services that grow every year. Our growth mindset and entrepreneurial environment translates into variety and opportunity for our people.
At Frazier & Deeter, we’re committed to training, mentoring, and developing our staff members. With our emphasis on Investing in Relationships to Make a Difference and a Firmwide Focus on Inclusion, we help each other grow in every aspect of life.
Job Summary:
We are currently seeking an Advisory Manager who will be responsible for overseeing a diverse portfolio of CMMC readiness and certification assessment engagements. This role encompasses the entire process, from initial scoping to the final reporting stages. Own client relationships, engagement economics, and delivery quality while directing teams performing evaluations against NIST SP 800-171 security requirements. Advise executive stakeholders on CUI scoping decisions, remediation strategy, and certification timelines. Contribute to practice growth through business development, methodology enhancement, and development of the CMMC team.
Duties & Responsibilities:
- Manage multiple concurrent CMMC Level 1 and Level 2 readiness assessments, gap analyses, and certification engagements, owning scope, budget, staffing, and delivery timelines.
- Serve as the primary point of contact for client executives and program leadership, advising on CUI and FCI scoping decisions, enclave strategy, and paths to certification.
- Direct and review the evaluation of security practices against NIST SP 800-171 and the assessment objectives in NIST SP 800-171A, including System Security Plans (SSPs), POA&Ms, policies, configurations, and technical evidence.
- Perform final review of assessment deliverables, workpapers, and reports to ensure technical accuracy, methodological consistency, and compliance with firm and CMMC Ecosystem quality standards.
- Resolve complex scoping, interpretation, and evidence-sufficiency questions, and escalate risk or independence matters to practice leadership as appropriate.
- Supervise, coach, and develop Senior Consultants and Consultants, including performance feedback, credential progression, and workload planning.
- Support business development through scoping calls, proposals, fee estimates, and identification of cross-serve opportunities across the firm’s tax, audit, and advisory practices.
- Partner with practice and marketing leadership to shape and execute the go-to-market strategy for the CMMC practice, including service offering design, target market definition, pricing, and campaign support.
- Build a presence as a thought leader in the marketplace through webinars, articles, whitepapers, and client briefings on CMMC and evolving DoD cybersecurity requirements.
- Represent the firm at CMMC-related conferences, industry associations, and CMMC Ecosystem events, developing relationships with clients, prospects, and referral sources.
- Contribute to practice development by refining assessment methodology, tooling, and templates, and by monitoring changes to CMMC, DFARS 252.204-7012/-7019/-7020/-7021, FAR 52.204-21, and related DoD requirements.
Education & Experience:
- Bachelor’s degree in information technology, Computer Science, Cybersecurity, Information Systems, or a related field.
- 7-10 years of experience in IT Audit, Cybersecurity, Risk Advisory, Compliance, or NIST SP 800-171 / CMMC assessments, including at least 2 years in a supervisory or engagement management capacity.
- Certified CMMC Professional (CCP) certification required; Certified CMMC Assessor (CCA) certification preferred, with the ability to serve on or lead CMMC Assessment Teams.
- Additional certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor are preferred.
- S. citizenship required in order to participate in CMMC assessment activities and access client CUI environments.
- Deep understanding of the CMMC Program, NIST SP 800-171 and 800-171A, and the identification, handling, and protection of CUI and FCI, with the judgment to resolve complex scoping and interpretation issues.
- Demonstrated experience managing assessment or audit engagements end to end, including budgeting, staffing, risk management, and quality review.
- Familiarity with IT General Controls (ITGCs), access management, vulnerability management, network security and segmentation, FIPS-validated encryption, logging/monitoring, and cloud service provider considerations including FedRAMP and External Service Provider requirements.
- Experience presenting assessment results, remediation strategy, and compliance risk to executive leadership, boards, and government contracting stakeholders.
- Proven ability to build and maintain client relationships and to support proposals, fee estimates, and practice growth initiatives.
- Experience recruiting, mentoring, and developing high-performing teams, including supporting credential attainment across the CMMC Ecosystem.
#LI - hybrid