Full-Time
Cybersecurity compliance consulting for defense contractors
$120k - $150k/yr
Remote in USA
Remote
Bachelor's
See people who can refer or advise you
CyberSheath provides cybersecurity and compliance services for organizations handling sensitive government data, especially defense contractors. It helps meet standards like NIST 800-171 and CMMC through consulting, risk assessments, compliance assessments, incident response, and staffing resources. It integrates compliance into daily operations, offers privileged access risk assessments, and focuses on outcome-based deployment and risk-based professional services to deliver audit-ready evidence. Its goal is to help clients achieve verifiable, auditable compliance while reducing cyber risk and ensuring expertise is available on demand.
Company Size
51-200
Company Stage
N/A
Total Funding
N/A
Headquarters
Reston, Virginia
Founded
2012
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Remote Work Options
Flexible Work Hours
SEP achieves CMMC Level 2 certification. SEP news. Westfield, IN - July 27, 2026 - SEP, one of Indiana's largest software development firms, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 certification for its development environment, reflecting full implementation of all 110 NIST SP 800-171 Rev 2 security controls with a perfect SPRS score of 110/110. CMMC Level 2 is a Department of Defense certification confirming a contractor fully implements the 110 security controls required to handle Controlled Unclassified Information (CUI) on defense programs. SEP has served aerospace and defense clients since 1989, building software across web, mobile, desktop, embedded, and cloud systems. A small fraction of companies in the Defense Industrial Base (DIB) currently hold CMMC certification, and SEP pursued certification early, building with CyberSheath and assessed by A-LIGN, to give existing and prospective defense clients confidence in how their most sensitive data is handled. "Too many contractors treat CMMC as a box to check. We approached certification to ensure continuity for the defense clients we already serve, and to build a foundation for the work ahead," said Marty Draper, Vice President of IT, Security, and Compliance at SEP. "It was important to us that we could keep supporting our existing defense clients while building toward what's next, without reworking how we operate." SEP partnered with CyberSheath, one of the most experienced CMMC compliance firms in the Defense Industrial Base, to architect the security controls, access policies, and system configurations behind the certification. The environment was independently assessed by A-LIGN, a Certified Third-Party Assessor Organization (C3PAO). SEP's certification is scoped to its defense development environment, which CyberSheath architected alongside SEP's internal IT & Security team to keep pace with SEP's broader business. That structure lets SEP bring on new defense clients within the existing compliance boundary, without expanding scope or reworking the architecture project by project. "Congratulations to SEP for achieving CMMC Level 2 certification. This accomplishment demonstrates a strong commitment to safeguarding valuable information to protect our nation, developing a competitive advantage, and creating a culture of security," said Petar Besalev, EVP of Compliance and Cybersecurity Services at A-LIGN. "We're proud to support this integral step in SEP's compliance journey with a high-quality assessment process and deep expertise in federal compliance." "SEP's accomplishment demonstrates a strong commitment to safeguarding valuable information to protect our nation, developing a competitive advantage, and creating a culture of security." Petar Besalev EVP of Compliance and Cybersecurity Services at A-LIGN Contractors and subcontractors that handle CUI are legally obligated to safeguard it under DFARS clause 252.204-7012, independent of where CMMC's broader certification framework lands. According to the Cyber AB, as of March 2026 only 1,074 organizations nationwide had achieved CMMC Level 2 certification, against a Defense Industrial Base the Department of War has estimated at roughly 80,000 contractors. "This certification is a foundation, not a finish line. We built it to support the defense clients we serve today and to give us room to grow with the ones we haven't met yet," said Draper. "As the requirements around this work continue to evolve, we intend to continue to be a leader in the strategic adoption of them." SEP designs and builds custom software for organizations ranging from Fortune 100 companies to scale-ups. One of Indiana's largest software development firms, SEP's services span the full product lifecycle: strategy, development, design, data, and AI. SEP works across industries including aerospace and defense, heavy machinery, pharma, precision ag, fintech, life sciences and medical devices, consumer IoT, and industrial IoT. Building for the DIB? See the security controls, scope, and partners behind SEP's CMMC Level 2 certified development environment. AI post recap. SEP, an Indiana software development firm serving aerospace and defense clients since 1989, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 with a perfect SPRS score of 110 out of 110. The certification confirms SEP fully implements all 110 NIST SP 800-171 Rev 2 security controls required to handle Controlled Unclassified Information for Department of Defense programs. CyberSheath architected the security controls, and A-LIGN, a Certified Third-Party Assessor Organization, conducted the independent assessment. What is CMMC Level 2 certification? CMMC Level 2 is a Department of Defense cybersecurity certification confirming a contractor fully implements all 110 NIST SP 800-171 security controls needed to handle Controlled Unclassified Information (CUI) on defense programs. Does SEP have experience working in aerospace and defense? Yes. SEP has served aerospace and defense clients since 1989, building web, mobile, desktop, embedded, and cloud software for the industry. Links to the A&D industry page. Who helped SEP get CMMC Level 2 certified? CyberSheath architected SEP's security controls and access policies, and A-LIGN, a Certified Third-Party Assessor Organization (C3PAO), conducted the independent assessment. July 27, 2026 Published: July 27, 2026 At SEP, Software Engineering Professionals, Inc. make vital software. The kind that keeps airplanes in the sky, helps farmers feed a growing population, and makes medical devices safe. Whatever industry you're in, bring Software Engineering Professionals, Inc. your toughest challenge. Software Engineering Professionals, Inc. is wired to tackle what really matters - to you, to Software Engineering Professionals, Inc., and to its world. 317.843.1640 16080 Westfield Blvd. Carmel, IN 46033
CyberSheath supports CTG Federal's achievement of CMMC Level 2 certification. RESTON, Va. - March 31, 2026 - CyberSheath, a leading provider of cybersecurity and compliance services for the defense industrial base, supported CTG Federal, a U.S. small-business government IT solutions provider, in the implementation and successful achievement of Cybersecurity Maturity Model Certification (CMMC) Level 2. CTG Federal delivers advanced IT infrastructure and mission systems to U.S. government customers, including organizations within the Department of War. As part of its commitment to protecting controlled unclassified information (CUI) and maintaining the highest standards of cybersecurity, CTG Federal established a comprehensive security program aligned to the CMMC Level 2 framework. To support this effort, CTG Federal worked with CyberSheath to augment internal capabilities across several areas of the program, including security architecture validation, control implementation support, and ongoing operational processes required to meet CMMC Level 2 standards. "Defense contractors responsible for handling controlled unclassified information must operate with a high degree of discipline and technical rigor," said Emil Sayegh, CEO of CyberSheath. "CTG Federal demonstrated a strong internal cybersecurity foundation, and we were proud to support their team as they finalized the architecture and operational controls necessary to meet CMMC Level 2 requirements." The formal assessment was conducted by Cybersec Investments, a Certified Third-Party Assessor Organization (C3PAO). Achieving CMMC Level 2 certification validates that CTG Federal's security environment and operational processes meet the Department of War requirements for safeguarding controlled unclassified information. "Cybersecurity and responsible stewardship of government information are core to how we operate," said Brian Reynolds, President and CEO of CTG Federal. "Our team invested significant effort in building a mature security program aligned with CMMC, and CyberSheath provided valuable support during the implementation and validation process. Achieving CMMC Level 2 reinforces our commitment to protecting the missions and information entrusted to us by our government customers." As CMMC requirements expand across the defense industrial base, CTG Federal's certification ensures the company is positioned to continue supporting defense customers that require validated cybersecurity maturity. About CyberSheath Established in 2012, CyberSheath is one of the most experienced and trusted IT security services partners for the U.S. defense industrial base. From CMMC compliance to strategic security planning to managed security services, CyberSheath offers a comprehensive suite of offerings tailored to clients' information security and regulatory compliance needs. Learn more at https://www.cybersheath.com/. About CTG Federal CTG Federal, a Cohesive Technology Group company, is a U.S.-based small business federal IT solutions provider and trusted partner to civilian, defense, and intelligence agencies. The company designs, integrates, and supports mission-ready infrastructure and platforms spanning sovereign AI and high-performance computing (HPC), storage and data management, secure networking, and enterprise services. CTG Federal specializes in delivering complex technology deployments in sensitive environments, with a strong emphasis on cybersecurity, supply chain assurance, and operational excellence. Through a disciplined, customer-first approach and partnerships with leading technology providers, CTG Federal helps government organizations modernize IT, accelerate mission outcomes, and protect critical information. CyberSheath Kristen Morales Lexie Capperella Gregory for CyberSheath
RESTON, Va. - Aug. 21, 2025 - CyberSheath, the largest CMMC managed service vendor in the DIB, has appointed Emil Sayegh as Chief Executive Officer.
CyberSheath, the largest CMMC managed service vendor in the DIB, will host its sixth annual free virtual conference, CMMC CON 2025: Compliance Blueprint - Plan.
CyberSheath launches revamped CMMC CON ninja training program as compliance enforcement intensifies.