Lead CMMC consulting engagements, architect tailored security programs, and guide organizations through compliance while mentoring a team of security consultants.
Work with a nationally ranked CPA and advisory firm that is passionate for what's next. Aprio has 30 U.S. office locations, one in the Philippines and more than 2,100 team members that speak 60+ languages across the globe. By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.
Join Aprio's Risk Advisory and Assurance Services team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a Senior Manager to join their dynamic team.
Ready to do more with your Microsoft security expertise? Join SecurityBricks, powered by Aprio, and help organizations across industries navigate complex cybersecurity and compliance landscapes with confidence.
At SecurityBricks, we’re not just checking boxes—we’re securing the future. As a Senior Microsoft Security Engineer, you’ll work with cutting-edge Microsoft tools, support high-impact compliance frameworks like FedRAMP and CMMC, and help shape the security posture of both public and private sector organizations.
We are seeking an experienced Senior Manager of Security and Compliance to lead our CMMC consulting practice serving small to enterprise organizations across the Defense Industrial Base. This senior leadership role will guide clients through their CMMC Level 2 certification journey, architecting tailored security programs that leverage Microsoft's enterprise security ecosystem while ensuring practical, cost-effective compliance for organizations of varying sizes and maturity levels.
Key Responsibilities:
CMMC Consulting Practice Leadership
- Lead CMMC Level 2 consulting engagements from initial assessment through certification readiness
- Conduct gap assessments against NIST SP 800-171 and CMMC Level 2 requirements for diverse client environments
- Develop customized remediation roadmaps scaled to client size, budget, and technical capabilities
- Prepare organizations for C3PAO assessments and provide certification readiness reviews
- Support multiple concurrent client engagements across various industries and organizational sizes
Microsoft Security Solutions Architect
- Design right-sized Microsoft security solutions appropriate for small business through enterprise clients
- Architect scalable implementations of Microsoft 365 (Business Premium to E5/G5), Azure, and Defender suite based on client maturity and budget
- Implement Microsoft Purview, Azure Information Protection, and DLP solutions tailored to CUI protection requirements
- Deploy Microsoft Sentinel or cost-effective alternatives for security monitoring across client environments
- Guide clients on Azure Government vs. commercial cloud decisions based on CMMC requirements
- Create reusable frameworks and templates that accelerate client implementations
Client Advisory & Strategic Guidance
- Serve as trusted advisor to C-suite and senior leadership on CMMC strategy and investment priorities
- Translate complex CMMC requirements into actionable business recommendations
- Provide guidance on scope definition, boundary establishment, and enclave strategies
- Advise on contractor teaming arrangements and CMMC compliance flow-down requirements
- Present security program maturity assessments and executive-level progress reporting
- Support proposal development and contract reviews for CMMC-related security requirements
Team Leadership & Practice Development
- Build and mentor a team of 4-6 security consultants with diverse skill sets and experience levels
- Develop standardized methodologies, playbooks, and accelerators for CMMC consulting engagements
- Establish quality assurance processes and peer review mechanisms for client deliverables
- Create training programs to elevate team capabilities in CMMC and Microsoft security technologies
- Foster culture of client success, technical excellence, and continuous learning
- Manage resource allocation and workload distribution across concurrent client engagements
Practice Growth & Thought Leadership
- Identify opportunities to expand consulting services and develop new offerings
- Contribute to business development activities and proposal responses
- Represent the practice at client events
- Develop thought leadership content on CMMC implementation best practices
- Build relationships with Microsoft partners, C3PAOs, and industry organizations
- Stay current on CMMC program updates and DoD cybersecurity requirements
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or related field (Master's preferred)
- 10+ years of progressive experience in information security and compliance, with significant consulting experience
- 5+ years leading teams and managing multiple concurrent projects or client engagements
- Proven track record successfully guiding organizations through CMMC/NIST SP 800-171 implementations
- Deep expertise working with small businesses through enterprise organizations on compliance initiatives
- Extensive hands-on experience implementing Microsoft security solutions across varied environments
- Strong understanding of Defense Industrial Base, CUI handling requirements, and DFARS compliance
- Experience translating technical requirements into business terms for non-technical stakeholders
Technical Competencies
- CMMC Level 2 and NIST SP 800-171 control implementation across diverse environments
- Microsoft 365 security architecture (Business Premium through E5/G5 licensing)
- Azure and Azure Government cloud security configurations
- Microsoft Defender suite deployment and optimization
- Microsoft Purview, Azure Information Protection, and data classification strategies
- Microsoft Sentinel and cost-effective SIEM alternatives
- Identity and Access Management solutions (Azure AD, Conditional Access)
- Network segmentation and boundary protection strategies
- Security documentation and technical writing
Preferred Certifications
- CISSP, CISM, or equivalent security leadership certification
- Microsoft security certifications (SC-200, SC-300, SC-400, AZ-500)
- NIST SP 800-171 assessment experience or DIBCAC certification
- Additional relevant certifications (Security+, CISA, GCIH, GIAC)
Key Competencies
- Client Relationship Management: Build trust and credibility with stakeholders at all organizational levels
- Adaptive Communication: Translate technical concepts for audiences from small business owners to enterprise CISOs
- Scalable Solutions Design: Right-size security programs based on organizational maturity, resources, and risk tolerance
- Business Acumen: Balance security requirements with operational realities and budget constraints
- Project Leadership: Manage complex, multi-phase engagements with competing priorities and timelines
- Mentorship: Develop junior consultants and elevate overall team capabilities
- Problem-Solving: Navigate unique challenges across diverse client environments and technical landscapes
Travel Requirements
- Approximately once per month for client site visits, assessment activities, team meetings, or industry conferences. Travel frequency may increase during initial client onboarding phases or certification preparation periods. Expectation is 10-15% travel annually.
Ideal Client Engagement Experience
- Small businesses (50-500 employees) new to CMMC requirements
- Mid-market companies establishing CUI handling environments
- Enterprise defense contractors optimizing existing compliance programs
- Organizations transitioning from NIST SP 800-171 self-assessment to CMMC Level 2 certification
- Companies implementing Microsoft cloud solutions for government contracting
- Defense Industrial Base supply chain participants navigating flow-down requirements
The application window is anticipated to close on April 9th and may be extended as needed.
Why work for Aprio:
Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.
Perks/Benefits we offer for full-time team members:
- Medical, Dental, and Vision Insurance on the first day of employment
- Flexible Spending Account and Dependent Care Account
- 401k with Profit Sharing
- 9+ holidays and discretionary time off structure
- Parental Leave – coverage for both primary and secondary caregivers
- Tuition Assistance Program and CPA support program with cash incentive upon completion
- Discretionary incentive compensation based on firm, group and individual performance
- Incentive compensation related to origination of new client sales
- Top rated wellness program
- Flexible working environment including remote and hybrid options
What’s in it for you:
- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.
- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience. We call it the Aprio Way. This shared mindset creates lasting relationships between team members and with clients.
- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.
- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.
- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.
- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.
EQUAL OPPORTUNITY EMPLOYER
Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.
Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.
Top Skills
Azure
Azure Information Protection
Microsoft 365
Microsoft Defender
Microsoft Purview
Microsoft Sentinel
Similar Jobs
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
Lead the design and implementation of AI-based products, collaborate with stakeholders for strategic guidance, and build scalable systems while mentoring teams. Required to have significant experience in coding and AI technologies.
Top Skills:
AngularAWSAzureGCPGenaiGoJavaLlmsPythonReactSQL
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Senior Executive Events & Experiences Manager designs and delivers high-impact executive engagements, ensuring premium experiences and flawless execution for C-level audiences, while managing logistics and collaborating with various teams.
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
As a Sales Engineer at CrowdStrike, you will leverage your security expertise to articulate solutions, change market perceptions, and collaborate with various teams to drive success. You should be skilled in presenting to diverse audiences and have extensive contacts in the security field.
Top Skills:
AvAWSAzureBashEdrEndpoint SecurityFirewallForensicsGCPHips/IdsIncident ResponsePowershellPythonSIEM
What you need to know about the Austin Tech Scene
Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.
Key Facts About Austin Tech
- Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
- Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
- Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
- Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center


