About the Role
Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right across the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements. We are looking for a mid-level CMMC and NIST practitioner who can step into active client delivery work, produce strong documentation, and help move projects forward without a lot of hand-holding.
This is a contract role that may be structured as part-time or full-time based on project needs and candidate availability.
What You Will Do
As a CMMC / NIST Consultant Analyst at Hotman Group you will contribute directly to active client engagements involving federal compliance frameworks. You will:
This is hands-on delivery work in a remote consulting environment. You will be expected to step into active projects and contribute from day one.
What You Bring
Experience supporting CMMC Level 2 efforts, CUI scoping, enclaves, or boundary discussions is a strong plus. Familiarity with POA&Ms, assessment readiness, and control crosswalks is also valued.
Active certifications such as CCP, CCA, CISSP, CISM, or CISA are preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one.
This role requires direct accountability for work product and outcomes. If your CMMC or NIST experience has been primarily observational or in a support capacity without ownership of documentation or deliverables, this role will be a significant adjustment.
Requirements
Our Hiring Process
Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on active client engagements. If you are confident in your CMMC and NIST expertise, this is your opportunity to show it.
Why Hotman Group
At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.
You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.
The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.
If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard — this is the place.
No phone calls please.

SSM Health

Voya Investment Management

Guidehouse

Turnitin

Northbridge Financial Corporation

Hotman Group, LLC

Hotman Group, LLC