We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

CMMC Engineer (Associate)

RSM US LLP
United States, Pennsylvania, Harrisburg
Aug 18, 2026

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM.

The CMMC Engineer is an entry-level technical member of the CMMC Engineering team responsible for supporting the implementation, configuration, maintenance, and monitoring of technologies used within CMMC-aligned client environments.

This role provides an opportunity to develop hands-on experience across cybersecurity, Microsoft cloud technologies, systems administration, automation, and compliance-focused engineering. The engineer will work alongside experienced engineering and compliance professionals to help implement technical security controls aligned with the Cybersecurity Maturity Model Certification (CMMC) and NIST SP 800-171.

The ideal candidate has a strong technical foundation, an interest in cybersecurity and cloud technologies, and a willingness to learn new technologies. Prior CMMC experience is beneficial but is not required. Training and mentorship will be provided to develop the technical and compliance knowledge necessary for the role.

Key Responsibilities:

CMMC Engineering Support

  • Assist with implementing and maintaining technical security controls within CMMC-aligned environments.
  • Learn how CMMC and NIST SP 800-171 requirements translate into technical configurations and security controls.
  • Support senior engineers with the deployment and configuration of technologies used to protect Controlled Unclassified Information (CUI).
  • Perform technical implementation tasks using established engineering standards, procedures, and deployment documentation.
  • Assist with identifying and remediating technical configuration issues that may impact security or compliance.
  • Validate configurations against established technical standards and requirements.
  • Escalate complex technical or compliance issues to senior engineering resources when appropriate.

Microsoft & Cloud Technologies

  • Assist with the configuration and administration of Microsoft 365 and Azure environments.
  • Support Microsoft Entra ID identity and access management configurations.
  • Assist with Microsoft Intune endpoint configuration and device management.
  • Support Microsoft Defender security capabilities and endpoint protection.
  • Assist with implementing Multi-Factor Authentication (MFA), Conditional Access, Role-Based Access Control (RBAC), and other identity security controls.
  • Support configuration and troubleshooting of Windows endpoints and servers.
  • Develop familiarity with Microsoft GCC, GCC High, and Azure Government environments where applicable.

Security Engineering

  • Assist with deploying and maintaining endpoint security, vulnerability management, logging, monitoring, and other cybersecurity technologies.
  • Review security alerts, configuration findings, and vulnerability results as directed by senior engineers.
  • Assist with remediation and validation of identified security issues.
  • Support secure system configuration and hardening activities.
  • Perform routine health checks to verify that security technologies are operating as expected.
  • Assist with troubleshooting connectivity, authentication, agent deployment, logging, and configuration issues.

Automation & Scripting

  • Develop basic scripts and automation to improve repetitive engineering tasks.
  • Use technologies such as PowerShell, Python, APIs, and JSON under the guidance of more experienced engineers.
  • Assist with automating activities such as configuration checks, evidence collection, reporting, and system health validation.
  • Learn how APIs and automation platforms can be used to connect security and infrastructure technologies.
  • Contribute to reusable scripts and tools maintained by the CMMC Engineering team.

Compliance & Control Validation

  • Assist with gathering technical evidence demonstrating that security controls have been implemented.
  • Perform established technical validation procedures to verify security configurations.
  • Help identify configuration changes or drift that could impact compliance.
  • Support recurring control-validation activities.
  • Assist with organizing technical evidence and maintaining supporting documentation.
  • Develop an understanding of how technical implementations support CMMC assessment requirements.

Engineering Operations & Troubleshooting

  • Perform routine maintenance and operational tasks for supported CMMC technologies.
  • Monitor platform health and assist with resolving technical issues.
  • Troubleshoot common endpoint, identity, networking, and cloud configuration issues.
  • Support software deployments, upgrades, configuration changes, and maintenance activities.
  • Follow established change management and engineering processes.
  • Escalate issues appropriately when additional expertise is required.

Documentation

  • Create and maintain technical documentation for configurations and engineering procedures.
  • Update implementation guides, troubleshooting documentation, and engineering runbooks.
  • Document technical changes and configuration decisions.
  • Assist with maintaining architecture diagrams and technical inventories.
  • Contribute solutions and lessons learned to team knowledge bases.
  • Follow established documentation standards to ensure work is repeatable and supportable.

Team Collaboration & Development

  • Work closely with CMMC engineers and other technical resources to complete assigned engineering tasks.
  • Participate in technical training, knowledge-sharing sessions, and team meetings.
  • Develop knowledge of CMMC, NIST SP 800-171, Microsoft security technologies, and cybersecurity engineering practices.
  • Collaborate with other RSM Defense engineering and service teams when troubleshooting or implementing shared technologies.
  • Seek guidance from senior engineers when encountering unfamiliar technologies or complex technical requirements.
  • Continuously develop technical skills through hands-on experience, training, labs, and industry certifications.

Required Skills & Knowledge

  • Foundational understanding of cybersecurity concepts and security best practices.
  • Basic knowledge of Microsoft Windows operating systems.
  • Familiarity with Microsoft 365, Azure, or other cloud technologies.
  • Basic understanding of networking concepts including TCP/IP, DNS, DHCP, firewalls, and VPNs.
  • Understanding of identity and access management concepts such as user accounts, permissions, MFA, and least privilege.
  • Basic troubleshooting and problem-solving skills.
  • Ability to follow technical procedures and document completed work.
  • Strong willingness to learn cybersecurity, cloud, automation, and compliance technologies.
  • Ability to communicate effectively and work within a collaborative engineering environment.

Preferred Skills & Experience

The following are beneficial but not required:

  • Internship, coursework, lab, military, help desk, systems administration, networking, or cybersecurity experience.
  • Exposure to Microsoft Azure, Microsoft 365, Entra ID, Intune, or Defender.
  • Basic PowerShell or Python scripting experience.
  • Familiarity with REST APIs or JSON.
  • Exposure to vulnerability management, endpoint security, SIEM, or other cybersecurity technologies.
  • Familiarity with NIST cybersecurity frameworks or CMMC.
  • Experience using Git or other version-control technologies.
  • Entry-level certifications such as Security+, Network+, Azure Fundamentals, or Microsoft Security fundamentals certifications.

Core Competencies

  • Technical aptitude
  • Willingness to learn
  • Problem solving
  • Attention to detail
  • Cybersecurity fundamentals
  • Technical troubleshooting
  • Documentation
  • Communication
  • Team collaboration
  • Ownership and accountability

Role Expectations

The CMMC Engineer is expected to grow into a well-rounded cybersecurity engineer capable of supporting CMMC-aligned environments across multiple technologies.

This is a developmental engineering position. The engineer is not expected to enter the role as a CMMC subject-matter expert or independently design complex CMMC architectures. Instead, the individual will work under the guidance of experienced engineers while progressively developing expertise in CMMC, NIST SP 800-171, Microsoft security technologies, cloud engineering, automation, and cybersecurity.

As technical proficiency increases, the engineer will be expected to take greater ownership of implementations, troubleshooting, automation, and technical control validation while contributing to the continued standardization and scalability of RSM Defense's CMMC engineering capabilities.

At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits.

All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership.RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at 800-274-3978 or send us an email at careers@rsmus.com.

RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.

RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.

At RSM, an employee's pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.

Compensation Range: $66,100 - $117,200
Applied = 0

(web-77cf7d65c7-zggqq)