Cybersecurity Consultant

Cyber Security Auditor

Company: BAA Consulting Location: Richmond, Virginia (Hybrid ) Employment Type: Full-Time Clearance Eligibility: Secret clearance eligibility required; active clearance preferred

Company Overview

BAA Consulting is a Richmond, Virginia-based IT consulting firm delivering enterprise-grade cybersecurity and compliance solutions to federal and state government clients. Our portfolio spans the Department of the Army, Office of Inspector General (OIG), Office of Personnel Management (OPM), and the State of Virginia, among others. We hold a GSA Schedule contract vehicle and are certified as a Registered Practitioner Organization (RPO) through the Cyber AB, positioning us as a trusted partner for organizations pursuing Cybersecurity Maturity Model Certification (CMMC).

Our team of certified professionals operates at the intersection of compliance, risk management, and mission-critical IT — implementing frameworks including RMF, NIST, FedRAMP, FISMA, DISA STIGs, CMMC, and PCI across complex government environments.

Role Summary

BAA Consulting is seeking a skilled and detail-oriented Cyber Security Auditor to join our growing compliance and risk management practice. In this role, you will conduct IT audits and assessments across a range of regulatory frameworks, with a particular emphasis on CMMC compliance support for Department of Defense (DoD) contractors and federal agencies. You will work directly with clients to evaluate security posture, identify gaps, and provide actionable guidance toward audit readiness and ongoing compliance.

This position requires a professional who brings both technical depth and strong interpersonal skills — someone capable of engaging with government clients, translating complex compliance requirements into practical recommendations, and supporting organizations through the full audit lifecycle.

Key Responsibilities

· Plan, execute, and document IT security audits across frameworks including RMF, NIST SP 800-171, CMMC (Levels 1 and 2), SOC-1, SOC-2 Type II, PCI DSS, FedRAMP, FISMA, and DISA STIGs

· Conduct CMMC readiness assessments and gap analyses for DoD contractors and government clients pursuing Level 1 Self-Assessments and Level 2 Third-Party Assessments (C3PAO)

· Assess the implementation and effectiveness of security controls against applicable frameworks and document findings with clarity and precision

· Develop detailed audit reports, Plans of Action and Milestones (POA&Ms), and remediation roadmaps for client stakeholders

· Guide clients through CMMC Level 1 Self-Assessment preparation, including documentation review, evidence collection, and control validation

· Support client preparation activities for CMMC Level 2 Third-Party Assessments, including pre-assessment mock reviews and evidence packaging

· Collaborate with client IT teams to evaluate system configurations, access controls, incident response procedures, and security documentation

· Communicate audit findings and compliance status to technical and executive-level audiences in clear, concise language

· Stay current with evolving CMMC standards, NIST guidelines, and DoD cybersecurity policy updates

· Contribute to the continuous improvement of BAA Consulting’s audit methodologies, templates, and service delivery practices

Required Qualifications

· Demonstrated experience conducting IT security audits using one or more of the following frameworks: RMF, NIST SP 800-53 / SP 800-171, SOC-1, SOC-2 Type II, PCI DSS, CMMC, FedRAMP, or FISMA

· Working knowledge of CMMC (Cybersecurity Maturity Model Certification) practices, including the 110 security requirements of NIST SP 800-171 and the CMMC Assessment Process (CAP)

· Active RP (Registered Practitioner) or RPA (Registered Practitioner Advanced) certification issued by the Cyber AB

· Minimum of one active Level 1 IT certification, such as:

o CompTIA A+

o CompTIA Security+

o CompTIA Network+

o Or an equivalent vendor-neutral foundational certification

· Ability to obtain and maintain a Secret security clearance (active clearance is preferred)

· Strong written and verbal communication skills, including the ability to produce professional audit documentation and present findings to government clients

· Demonstrated ability to work independently, manage competing priorities, and meet deadlines in a client-facing environment

Preferred Qualifications

· Active RP/RPA Certification

· Additional certifications such as CISSP, CASP+, CISM, or CISA

· Experience supporting CMMC Level 2 Third-Party Assessments (C3PAO engagements)

· Familiarity with DISA STIGs and system hardening practices for government IT environments

· Hands-on experience with cloud environments (AWS or Azure) in the context of government compliance programs such as FedRAMP or IL2/IL4/IL5

· Prior experience working with federal government clients, including DoD components, civilian agencies, or state government entities

· Experience using vulnerability management tools, GRC platforms, or POA&M tracking systems

· Background in enterprise IT infrastructure, systems administration, or network engineering

About the Opportunity

BAA Consulting is at a significant growth inflection. As a Cyber AB-certified RPO, we are actively expanding our CMMC advisory and audit readiness practice to meet rising demand across the Defense Industrial Base (DIB). This role offers the opportunity to work on meaningful, mission-critical engagements alongside a team of seasoned professionals holding certifications including CISSP, CASP+, Security+, and AWS/Azure Architect credentials.

You will be part of an organization that values technical rigor, client trust, and professional growth. With offices in Richmond, Virginia and Miami, FL as well as expansion plans underway in Colorado Springs, CO, BAA Consulting offers a stable, mission-driven environment with the energy and opportunity of a growing firm.

If you are a compliance professional who is passionate about cybersecurity, experienced in government audit frameworks, and ready to make a direct impact on how organizations achieve and maintain their security certifications — we want to hear from you.

BAA Consulting is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or veteran status.

For more information, visit or submit your resume and a brief cover letter outlining your relevant audit experience and certifications.

Pay: $80,000.00 - $105,000.00 per year

Benefits:

  • 401(k)
  • Flexible schedule
  • Health insurance
  • Paid time off
  • Professional development assistance
  • Referral program
  • Tuition reimbursement
  • Vision insurance

Work Location: Hybrid remote in Richmond, VA 23234

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...