Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

CMMC Security Engineer (Hybrid)

$120k - $170k
Full-time

Intelligent Technical Solutions (ITS)

Job Description

We are seeking a CMMC Security Engineer to design and build compliant Azure and Microsoft 365 environments for our CMMC consulting clients. This is a hands-on technical role. You will provision GCC and GCC High tenants, architect network security (Azure Firewall, VPN, NSGs), configure Entra ID with Conditional Access and Privileged Identity Management, deploy Intune for endpoint management, stand up Microsoft Sentinel for SIEM/SOAR, configure Purview for data protection, and deploy Defender for Endpoint across client environments. You will work from documented SOPs and a Control-Task Tracker that maps each NIST 800-171 control to specific Azure/M365 configurations. You will also capture technical evidence (screenshots, configuration exports, audit logs) to support the compliance documentation created by our GRC Consultants. 

 

Job Responsibilities

  • Design and deploy CMMC-compliant enclave architectures in Azure: cloud-only (GCC/GCC High), hybrid (on-prem + GCC), and on-premises environments. Select and implement the appropriate topology (hub-spoke, segmented) based on client requirements. 
  • Provision and configure Microsoft 365 GCC and GCC High tenants including initial setup, domain verification, licensing assignment, and tenant hardening.
  • Configure Microsoft Entra ID: user provisioning, Security Groups, Administrative Units, Conditional Access policies (MFA, device compliance, location-based, session controls), Privileged Identity Management (PIM), and Identity Protection risk policies.
  • Deploy and configure Microsoft Intune: device enrollment, compliance policies, configuration profiles, security baselines (CIS/STIG), BitLocker encryption with FIPS 140-2 compliance, Windows Update for Business rings, and application management via Company Portal.
  • Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules, automation playbooks (Logic Apps), and CMMC compliance workbooks/dashboards. 
  • Deploy and configure Microsoft Defender for Endpoint: device onboarding, antivirus policies, Attack Surface Reduction (ASR) rules, endpoint DLP, network protection, web content filtering, and vulnerability management. 
  • Configure Microsoft Purview: sensitivity labels (CUI, FCI, Public), auto-labeling policies, DLP policies across Exchange, SharePoint, Teams, and endpoints, and information barriers where required. 
  • Design and implement Azure networking: Virtual Networks, subnets, NSGs, Azure Firewall, Azure Bastion, VPN Gateway (site-to-site and point-to-site), Private Endpoints, route tables, and DDoS Protection. 
  • For hybrid environments: configure Azure AD Connect (or Cloud Sync), hybrid device join, pass-through authentication or password hash sync, split DNS, and Azure Arc for on-premises server management. 
  • Configure encryption across the environment: BitLocker (XTS-AES 256), FIPS 140-2 compliance mode, TLS 1.2+ enforcement, VPN encryption (IKEv2/AES-256), and Purview encryption for CUI-labeled content. 
  • Execute remediation tasks from the CMMC Remediation Tracker as assigned by the GRC Consultant. Each task maps a specific NIST 800-171 control objective to an Azure/M365 configuration with step-by-step instructions. 
  • Capture and organize technical evidence for each implemented control: configuration screenshots, policy exports (JSON), audit log samples, compliance reports, and test results. 
  • Support incident response capability deployment: Sentinel playbook creation, automated notification workflows, and incident response procedure testing. 
  • Perform client environment migrations to GCC/GCC High (tenant-to-tenant migration using BitTitan, ShareGate, or native Microsoft tools). 
  • Work across 4-7 concurrent client environments at various stages of build and remediation. 

Job Qualifications
Required Technical Experience

  • Willing to work in a hybrid setup—remotely or on-site at client locations, as required.
  • 3+ years hands-on experience administering Microsoft Azure and M365 environments in a professional capacity (not lab-only). 
  • Direct experience configuring Conditional Access policies, Entra ID PIM, and identity architecture (cloud-only and hybrid with Azure AD Connect). 
  • Direct experience deploying and managing Microsoft Intune for endpoint compliance, configuration profiles, security baselines, and BitLocker management. 
  • Direct experience deploying Microsoft Sentinel including data connectors, KQL query writing, analytics rules, and automation playbooks. 
  • Experience configuring Azure networking: VNets, NSGs, Azure Firewall or third-party NVA, VPN Gateway, and network security architecture. 
  • Experience deploying Microsoft Defender for Endpoint including device onboarding, ASR rules, and vulnerability management. 
  • Proficiency with PowerShell and Microsoft Graph API for automation and bulk configuration tasks. 
  • Understanding of NIST SP 800-171 controls and how they map to specific Azure/M365 technical implementations. 

Strongly Preferred Technical Experience

  • Experience with Microsoft 365 GCC or GCC High environments (tenant provisioning, licensing nuances, feature differences from commercial M365). 
  • Experience with tenant-to-tenant migrations (commercial to GCC/GCC High) using BitTitan MigrationWiz, ShareGate, or native Microsoft tools. 
  • Experience configuring Microsoft Purview: sensitivity labels, auto-labeling, DLP policies across Exchange, SharePoint, Teams, and endpoints. 
  • Experience with FIPS 140-2 configuration and DISA STIG or CIS benchmark implementation via Intune or GPO. 
  • Experience supporting defense industrial base (DIB) or federal contractor IT environments. 
  • Experience with Azure Arc for hybrid server management and Azure Bastion for secure remote administration.

Required Certifications 

(must hold at least two from this list): 

  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305) - Architecture design and decision-making. 
  • Microsoft Certified: Azure Administrator Associate (AZ-104) - Core Azure resource management. 
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) - Sentinel, Defender, and security operations. 
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) - Entra ID, Conditional Access, PIM. 
  • Microsoft Certified: Information Protection and Compliance Administrator (SC-400) - Purview, DLP, sensitivity labels. 
  • Microsoft Certified: Endpoint Administrator Associate (MD-102) - Intune and device management. 

Preferred Certifications

(significant advantage): 

  • CompTIA Security+ (SY0-701) 
  • CMMC Registered Practitioner (RP) - Understanding of CMMC framework from technical perspective. 
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) 
  • Microsoft 365 Certified: Administrator Expert (MS-102) 
  • Certified Information Systems Security Professional (CISSP) 
  • GIAC certifications (GSEC, GCIA, GCIH) - Deep security operations knowledge. 

Skills & Competencies

  • Execution-focused: ability to follow SOPs and runbooks precisely while identifying when something does not match documented steps and escalating appropriately. 
  • Multi-tenant management: comfortable switching between 4-7 different client Azure/M365 environments daily without cross-contaminating configurations. 
  • Documentation discipline: every configuration change is documented, every evidence artifact is captured, every deviation from the SOP is noted. 
  • Troubleshooting: when Conditional Access blocks legitimate users, when Sentinel data connectors go unhealthy, or when WDAC blocks a required application, you can diagnose and resolve without waiting for escalation. 
  • Security mindset: you understand why least privilege matters, why default-deny is the correct network posture, and why FIPS-validated encryption is required for CUI. 
  • Clear written communication: when you find something in the client environment that does not match what the GRC Consultant scoped, you can document it clearly so the team can make decisions. 

Compensation

Pay rate ranges from $120,000.00/annum up to $170,000.00/annum and may vary by experience and location. 


Benefits

  • Benefits
  • Medical Insurance Plan
  • Dental & Vision
  • Life Insurance
  • Disability Coverage
  • Paid Time Off (starts at 15 days per year)
  • Maternity/Paternity Leave
  • Paid US Holiday
  • Retirement Plan
  • Salary Advancement/Loan
  • Health & Wellness Program
  • Company-paid training and certification
  • Supplemental Life Insurance (Employee-paid)
  • Supplemental Health Plans (Employee-paid)

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the CMMC Security Engineer (Hybrid) in Las Vegas, NV vacancy
  • $104k - $156k

     ...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they access. You will help... 
    Suggested
    Remote work

    Relativity

    Las Vegas, NV
    4 days ago
  • TensorWave in Las Vegas is seeking a Security Architect to build security frameworks across high-performance computing environments. This hybrid role involves collaborating with cross-functional teams to design and implement security solutions in coding languages like Go... 
    Suggested

    TensorWave

    Las Vegas, NV
    21 hours ago
  •  ...TensorWave Security Architect Our mission is simple: deliver seamless, secure, reliable...  ...CISO and partnering with leads across Engineering, Platform, and the business, you'll be the...  ...code that makes it real. This is a hybrid architect-builder role. You'll move between... 
    Suggested
    Temporary work
    Work at office
    Flexible hours
    Shift work

    TensorWave

    Las Vegas, NV
    2 days ago
  • $112k - $134k

    JT4 is seeking a Cyber Security Analyst for an onsite position at Edwards...  ..., Azure, Google Cloud) and hybrid environments. Strong...  ...e.g., NIST, ISO 27001, GDPR, CMMC, HIPAA). Experience with scripting...  ...Reimbursement About Us JT4, LLC provides engineering and technical support to... 
    Suggested
    Contract work
    Work experience placement
    Immediate start

    JT4

    Las Vegas, NV
    2 days ago
  •  ...Cloud Network Security Engineer Key Responsibilities: Design and implement AWS network architectures including VPCs, subnets, NAT gateways, and Transit Gateways Manage hybrid network solutions (VPN, AWS Direct Connect, etc.) Configure and monitor... 
    Suggested

    3B Staffing LLC

    Las Vegas, NV
    1 day ago
  •  ...Senior Information Security Engineer ANDMORE is seeking a Senior Information Security Engineer which is a senior, hands-on security engineering...  ...cross-functional collaboration Work Environment Hybrid role (Monday & Friday, Remote with Tuesday through Thursday... 
    Work at office
    Remote work
    Monday to Friday

    Juniper Networks

    Las Vegas, NV
    1 day ago
  • $76.98k - $115.47k

    Arcadis is seeking a qualified Civil Engineer in Las Vegas, Nevada, to join its multi-national team. This role involves supporting diverse...  ...assessment and remediation projects while enjoying hybrid work flexibility. Candidates must possess a Bachelor’s in Civil... 

    Arcadis

    Las Vegas, NV
    3 days ago
  • A global consultancy company is looking for a Civil Engineer to join their team in Las Vegas. This position involves working on environmental...  ...specifications, and project management. The role offers a hybrid work structure, with 1-2 days in the office. Ideal candidates... 
    Work at office

    Arcadis

    Las Vegas, NV
    1 day ago
  • $104k - $154k

     ...Information Systems Security Engineer Womble Bond Dickinson (US) LLP is seeking an Information Systems Security Engineer (ISSE) for our Phoenix, AZ, Denver, CO, or Las Vegas, NV office. The Information Systems Security Engineer reports to the Information Systems Security... 
    Work at office
    Flexible hours

    Womble Bond Dickinson LLP

    Las Vegas, NV
    21 hours ago
  • Job Overview Beacon Technologies is seeking a Security/Application Security Engineer for our client partner. The Security and Application Security Engineer...  ...with experience in securing wide area networks and a hybrid approach for on‑premise/cloud/colocation technology... 
    Work experience placement
    Work at office
    Local area
    Remote work

    Beacon Technologies

    Las Vegas, NV
    21 hours ago
  •  ...Specialist Engineer The Specialist Engineer will have eight or more years of experience designing and deploying enterprise-level cybersecurity...  ...for collaboratively designing and leading implementation for security controls across the enterprise, in a cloud first, mobile first... 
    Full time
    Work experience placement
    Remote work

    Caesars Entertainment

    Las Vegas, NV
    1 day ago
  • $95.63k - $135.01k

     ...Exempt Anticipated Salary Range: $95,626.00 - $135,012.80 Security Clearance: Top Secret Level of Experience: Senior This...  ...provide cybersecurity oversight, RMF documentation, system security engineering support, and continuous monitoring for advanced modeling and... 
    Full time
    Work experience placement
    Local area
    Worldwide

    Huntington Ingalls Industries

    Nellis Air Force Base, NV
    4 days ago
  • Ernst & Young Oman is looking for an Application Security Engineer based in the United States. You will be responsible for managing application development platforms and optimizing security tools. Your key responsibilities include enhancing security practices and collaborating... 

    Ernst & Young Oman

    Las Vegas, NV
    4 days ago
  • $132.9k - $182.7k

    A leading engineering firm in the United States is looking for a Senior Mechanical (Plumbing) Engineer to work on complex industrial projects...  ...junior engineers, and contribute to innovative solutions in a hybrid work environment. Strong communication, analytical skills, and... 
    Remote job

    Jacobs

    Las Vegas, NV
    3 days ago
  •  ...Sr Cloud Security Engineer | | Las Vegas, NV Day1 Onsite Position Summary The Cloud Security Engineer supports the AVP of Security Operations in a variety of information technology security functions within the Information Technology Department. Responsibilities... 

    Maintec Technologies

    Las Vegas, NV
    2 days ago
  • $123.6k - $170k

    Jacobs is seeking a Senior Mechanical HVAC Engineer to deliver innovative HVAC design solutions for our Advanced Manufacturing clients....  ...degree in Mechanical Engineering, and a PE License. Jacobs offers a hybrid work model and a salary range of $123,600 - $170,000, along... 

    Jacobs

    Las Vegas, NV
    21 hours ago
  • $130k - $180k

    Slickdeals is seeking a seasoned Data Engineer to join our team in Las Vegas, NV, where you will manage and modernize core data pipelines...  ...skills, and experience with BI tools like Tableau. This is a hybrid role, requiring visits to the office three days a week. Compensation... 
    Work at office
    3 days per week

    Slickdeals

    Las Vegas, NV
    3 days ago
  • $105.79k - $141.05k

     ...our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads...  ...experience with controls validation and compliance testing of CMMC audits, SSAE 16, AT-101 (SOC 1 / SOC 2), PCI, ISO, HIPAA, Privacy... 
    Full time
    Temporary work
    Remote work

    Lumen

    Las Vegas, NV
    4 days ago
  •  ...operations by ensuring the reliability, security, and performance of classified network infrastructure...  ...Technology, Computer Science, Engineering, or related field OR Associate's degree...  ...operations Knowledge of cloud and hybrid environments (AWS, Azure, Google, Oracle... 
    Contract work
    For contractors
    Local area

    Amentum

    Las Vegas, NV
    3 days ago
  • $90k - $130k

     ...to join their Las Vegas team. This full-time position offers a hybrid work option and a competitive salary range of $90k-$130k...  ...profit sharing. The successful candidate will be responsible for engineering control valves, managing customer relationships, and collaborating... 
    Full time

    Caltrol, Inc.

    Las Vegas, NV
    1 day ago
  • $100k - $172.5k

     ...Learn more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job Category:...  ...for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options... 
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Las Vegas, NV
    2 days ago
  •  ...We are seeking a highly skilled Network Engineer, Consultant to implement, support, and optimize...  ...on expertise across routing, switching, security, and data center technologies, with the...  ...tools (e.g., SolarWinds) Hybrid This role requires employees to be... 
    Work at office
    2 days per week

    Blue Shield of CA

    Las Vegas, NV
    1 day ago
  •  ...the intersection of adversarial machine learning, enterprise security architecture, and governance. You will lead the design and execution...  ...ISO 27017 cloud security controls Partner closely with engineering, security, and compliance functions Present findings... 

    C-Serv

    Las Vegas, NV
    2 days ago
  • $190.4k - $238k

     ...Cohesity Inc. is seeking a Sales Engineer in Las Vegas, Nevada. You will drive opportunities by articulating the Data Cloud portfolio and provide tailored support throughout the sales cycle. Candidates should have proven experience in pre-sales engineering, strong communication... 

    Cohesity

    Las Vegas, NV
    2 days ago
  • A technology solutions provider in Las Vegas is seeking a Security/Application Security Engineer responsible for cybersecurity infrastructure and application security testing. The ideal candidate will have a strong background in information security and experience with... 

    Beacon Technologies

    Las Vegas, NV
    21 hours ago
  •  ...Caesars Entertainment is expanding its Technology team in Las Vegas, seeking a Network Engineer. In this role, you will be responsible for the design, maintenance, and security of the local and wide-area networks. You will support and implement network equipment and software... 
    Local area

    Caesars Entertainment

    Las Vegas, NV
    1 day ago
  • $89k - $143.75k

     ...Job Sub Function: R&D Software/Systems Engineering Job Category: Scientific/...  ...basis and if approved by the Company. #Li-Hybrid We are searching for the best talent...  ...Performing periodic risk assessment of security vulnerabilities in software for the product... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Night shift

    Johnson & Johnson

    Las Vegas, NV
    1 day ago
  • Integrations Engineer We are seeking a highly skilled Integrations Engineer to design, develop, and maintain integrations across our enterprise systems. This role will be responsible for building and supporting solutions in Azure API, Azure Data Factory, Master Data Management... 
    Contract work
    Local area
    Visa sponsorship

    Energy Jobline ZR

    Las Vegas, NV
    3 days ago
  • $89.7k - $162.15k

    00100 LEIDOS, INC. is seeking a Network Engineer to support the Department of the Air Force Air Combat Command's base readiness initiative...  ...with TCP/IP networks. Certifications like CCNA and Security+ are required. The pay range is from $89,700 to $162,150 annually... 

    00100 LEIDOS, INC.

    Las Vegas, NV
    21 hours ago
  • $77k - $143k

     ...Network Engineer At Aristocrat, we are relentless in our pursuit of excellence and innovation...  ...Do Architect, deploy, and maintain secure and scalable network solutions across LAN...  ...with cloud networking (AWS, Azure) and hybrid environments is desirable. Why... 
    Full time
    Visa sponsorship
    Work visa

    Aristocrat

    Las Vegas, NV
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to CMMC Security Engineer (Hybrid). Be the first to apply!