Horizon Industries Limited
Chief Information Officer (CIO) – CMMC Compliance (Part-Time)
remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Executive
- Work mode
- Remote-friendly
- First seen by hirly
- 11 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Chief Information Officer (CIO) – CMMC Compliance (Part-Time)
Location: Remote with periodic onsite support as required
Employment Type: Part-Time Consulting / Fractional Executive
Reports To: President and Executive Leadership Team
Expected Time Commitment : Approximately 20–40 hours per month, depending on compliance activities and assessment schedule.
Position Overview
Horizon Industries is seeking an experienced Part-Time Chief Information Officer (CIO) to provide executive leadership and operational oversight for the company’s Cybersecurity Maturity Model Certification (CMMC) Level 2 program and Microsoft GCC High environment. The CIO will serve as the executive owner of the organization's CMMC compliance posture, ensuring that cybersecurity controls, governance processes, technical implementations, risk management activities, and assessment preparation efforts remain compliant, sustainable, and audit-ready. This position is ideal for a senior technology executive with deep experience in NIST SP 800-171, CMMC, Microsoft GCC High, federal government contracting, and cybersecurity governance.
Key Responsibilities
Executive Leadership & Governance
Serve as Horizon's designated CIO for all CMMC-related activities.
Act as executive owner of systems that process, store, or transmit Controlled Unclassified Information (CUI).
Ensure cybersecurity initiatives align with business objectives, contract requirements, and federal regulations.
Provide strategic technology guidance to executive leadership regarding compliance, security, and risk management.
Participate in executive compliance reviews and readiness briefings.
Support annual affirmations and executive attestations relating to CMMC certification readiness.
CMMC Program Oversight
Provide executive oversight of Horizon's CMMC Level 2 program.
Review and approve CMMC policies, procedures, plans, and compliance artifacts.
Ensure alignment among the System Security Plan (SSP), CUI Management Plan, POA&M, Risk Register, and supporting evidence repositories.
Review compliance metrics, remediation activities, and audit findings.
Support preparation for self-assessments, mock assessments, and formal C3PAO assessments.
Participate in assessor interviews and executive-level discussions during audits.
Technical & Security Oversight
Provide executive oversight of:
Microsoft GCC High environment
Entra ID / Identity & Access Management
Conditional Access and MFA
Endpoint security and device management
Security monitoring and incident response
Vulnerability management activities
Configuration and change management processes
Review security architecture and ensure alignment with CMMC control requirements.
Evaluate impacts of major technology changes on CMMC scope and security posture.
Risk Management
Lead annual and periodic cybersecurity risk assessments.
Review risk treatment decisions and approve risk acceptance recommendations.
Ensure corrective actions and remediation plans are effectively managed.
Provide governance oversight for POA&M development and closure activities.
Monitor compliance risks affecting certification status and federal contract eligibility.
Documentation & Audit Readiness
Review and approve:
System Security Plan (SSP)
Policies and Procedures
Continuous Monitoring Plan
Incident Response Documentation
Risk Assessment Reports
CUI Management Documentation
Evidence Management Processes
Ensure documentation accurately reflects implemented controls and operational practices.
Conduct periodic readiness reviews and executive quality checks on compliance artifacts.
Vendor & External Stakeholder Engagement
Interface with:
C3PAOs
Compliance consultants
Managed Service Providers
Microsoft partners
Federal customer representatives as required
Review third-party service providers that affect CMMC compliance boundaries.
Support assessment planning and remediation activities with external partners.
Increased availability may be required during:
Mock assessments
Self-assessments
C3PAO certification assessments
Significant remediation initiatives
Required Qualifications
Minimum 15 years of progressive IT leadership experience.
Previous experience serving as CIO, CISO, or equivalent executive role.
Demonstrated experience supporting CMMC Level 2 or NIST SP 800-171 compliance programs.
Experience operating within DoD, federal contractor, or defense-industrial-base environments.
Strong working knowledge of:
Microsoft 365 GCC High
Entra ID
Microsoft Defender
Microsoft Purview
Microsoft Sentinel
Intune
Identity and Access Management
Preferred Qualifications
Successfully supported one or more organizations through CMMC certification.
Experience participating in DoD cybersecurity assessments.
Familiarity with DFARS 252.204-7012, 7019, 7020, and 7021.
Experience with SPRS submissions and executive affirmations.
Certifications such as:
CISSP
CISM
CGRC (formerly CAP)
CCSP
CMMC Certified Professional (CCP)
CMMC Certified Assessor (CCA)
Key Deliverables
The Part-Time CIO will be expected to:
Maintain executive oversight of Horizon's CMMC compliance program.
Conduct monthly compliance governance reviews.
Review and approve major compliance documentation.
Provide quarterly executive risk assessments.
Participate in internal audit and assessment preparations.
Support executive readiness for C3PAO assessments.
Validate SSP accuracy and compliance traceability.
Advise leadership on cybersecurity investments, risk acceptance, and CMMC sustainment strategies.
This role is intended to provide Horizon with an experienced executive capable of serving as the accountable CIO for CMMC compliance while leveraging existing internal resources for day-to-day administration and technical operations.
Horizon is an Equal Employment Opportunity employer, and it is our policy to consider all applicants for employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.
EOE/Vet/Disabled
Listed on hirly, a job board. hirly is not the employer: Horizon Industries Limited is hiring for this role.
Similar jobs
- Deputy Chief Information OfficerHeadquarters, NASA · Sandusky County, Ohio, United StatesFirst seen today
- Chief Medical Information OfficerMulticareFirst seen yesterday
- Associate Chief Medical Information Officer (ACMIO) for RadiologyOchsner · New Orleans - New Orleans Region - LouisianaFirst seen 2d ago
- Chief Information OfficerNvent · St Louis Park, MN, USFirst seen 2d ago
- Executive Assistant to the Enterprise Chief Information Officer (CIO) - Information SolutionsMusc · CharlestonFirst seen 2d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job