CMMC Security Engineer (Hybrid)
$120k - $170kIntelligent Technical Solutions (ITS)
About the Job Job Description We are seeking a CMMC Security Engineer to design and build compliant Azure and Microsoft 365 environments for our CMMC consulting clients. This is a hands-on technical role. You will provision GCC and GCC High tenants, architect network security (Azure Firewall, VPN, NSGs), configure Entra ID with Conditional Access and Privileged Identity Management, deploy Intune for endpoint management, stand up Microsoft Sentinel for SIEM/SOAR, configure Purview for data protection, and deploy Defender for Endpoint across client environments. You will work from documented SOPs and a Control-Task Tracker that maps each NIST 800-171 control to specific Azure/M365 configurations. You will also capture technical evidence (screenshots, configuration exports, audit logs) to support the compliance documentation created by our GRC Consultants. Job Responsibilities:
- Design and deploy CMMC-compliant enclave architectures in Azure: cloud-only (GCC/GCC High), hybrid (on-prem + GCC), and on-premises environments. Select and implement the appropriate topology (hub-spoke, segmented) based on client requirements.
- Provision and configure Microsoft 365 GCC and GCC High tenants including initial setup, domain verification, licensing assignment, and tenant hardening.
- Configure Microsoft Entra ID: user provisioning, Security Groups, Administrative Units, Conditional Access policies (MFA, device compliance, location-based, session controls), Privileged Identity Management (PIM), and Identity Protection risk policies.
- Deploy and configure Microsoft Intune: device enrollment, compliance policies, configuration profiles, security baselines (CIS/STIG), BitLocker encryption with FIPS 140-2 compliance, Windows Update for Business rings, and application management via Company Portal.
- Deploy and configure Microsoft Sentinel: Log Analytics workspace setup, data connector deployment (M365, Entra ID, Defender, Azure Activity, Firewall, NSG flow logs), KQL-based analytics rules, automation playbooks (Logic Apps), and CMMC compliance workbooks/dashboards.
- Deploy and configure Microsoft Defender for Endpoint: device onboarding, antivirus policies, Attack Surface Reduction (ASR) rules, endpoint DLP, network protection, web content filtering, and vulnerability management.
- Configure Microsoft Purview: sensitivity labels (CUI, FCI, Public), auto-labeling policies, DLP policies across Exchange, SharePoint, Teams, and endpoints, and information barriers where required.
- Design and implement Azure networking: Virtual Networks, subnets, NSGs, Azure Firewall, Azure Bastion, VPN Gateway (site-to-site and point-to-site), Private Endpoints, route tables, and DDoS Protection.
- For hybrid environments: configure Azure AD Connect (or Cloud Sync), hybrid device join, pass-through authentication or password hash sync, split DNS, and Azure Arc for on-premises server management.
- Configure encryption across the environment: BitLocker (XTS-AES 256), FIPS 140-2 compliance mode, TLS 1.2+ enforcement, VPN encryption (IKEv2/AES-256), and Purview encryption for CUI-labeled content.
- Execute remediation tasks from the CMMC Remediation Tracker as assigned by the GRC Consultant. Each task maps a specific NIST 800-171 control objective to an Azure/M365 configuration with step-by-step instructions.
- Capture and organize technical evidence for each implemented control: configuration screenshots, policy exports (JSON), audit log samples, compliance reports, and test results.
- Support incident response capability deployment: Sentinel playbook creation, automated notification workflows, and incident response procedure testing.
- Perform client environment migrations to GCC/GCC High (tenant-to-tenant migration using BitTitan, ShareGate, or native Microsoft tools).
- Work across 4-7 concurrent client environments at various stages of build and remediation.
- Willing to work in a hybrid setup-remotely or on-site at client locations, as required.
- 3+ years hands-on experience administering Microsoft Azure and M365 environments in a professional capacity (not lab-only).
- Direct experience configuring Conditional Access policies, Entra ID PIM, and identity architecture (cloud-only and hybrid with Azure AD Connect).
- Direct experience deploying and managing Microsoft Intune for endpoint compliance, configuration profiles, security baselines, and BitLocker management.
- Direct experience deploying Microsoft Sentinel including data connectors, KQL query writing, analytics rules, and automation playbooks.
- Experience configuring Azure networking: VNets, NSGs, Azure Firewall or third-party NVA, VPN Gateway, and network security architecture.
- Experience deploying Microsoft Defender for Endpoint including device onboarding, ASR rules, and vulnerability management.
- Proficiency with PowerShell and Microsoft Graph API for automation and bulk configuration tasks.
- Understanding of NIST SP 800-171 controls and how they map to specific Azure/M365 technical implementations.
- Experience with Microsoft 365 GCC or GCC High environments (tenant provisioning, licensing nuances, feature differences from commercial M365).
- Experience with tenant-to-tenant migrations (commercial to GCC/GCC High) using BitTitan MigrationWiz, ShareGate, or native Microsoft tools.
- Experience configuring Microsoft Purview: sensitivity labels, auto-labeling, DLP policies across Exchange, SharePoint, Teams, and endpoints.
- Experience with FIPS 140-2 configuration and DISA STIG or CIS benchmark implementation via Intune or GPO.
- Experience supporting defense industrial base (DIB) or federal contractor IT environments.
- Experience with Azure Arc for hybrid server management and Azure Bastion for secure remote administration.
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305) - Architecture design and decision-making.
- Microsoft Certified: Azure Administrator Associate (AZ-104) - Core Azure resource management.
- Microsoft Certified: Security Operations Analyst Associate (SC-200) - Sentinel, Defender, and security operations.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300) - Entra ID, Conditional Access, PIM.
- Microsoft Certified: Information Protection and Compliance Administrator (SC-400) - Purview, DLP, sensitivity labels.
- Microsoft Certified: Endpoint Administrator Associate (MD-102) - Intune and device management.
- CompTIA Security+ (SY0-701).
- CMMC Registered Practitioner (RP) - Understanding of CMMC framework from technical perspective.
- Microsoft Certified: Cybersecurity Architect Expert (SC-100).
- Microsoft 365 Certified: Administrator Expert (MS-102).
- Certified Information Systems Security Professional (CISSP).
- GIAC certifications (GSEC, GCIA, GCIH) - Deep security operations knowledge.
- Execution-focused: ability to follow SOPs and runbooks precisely while identifying when something does not match documented steps and escalating appropriately.
- Multi-tenant management: comfortable switching between 4-7 different client Azure/M365 environments daily without cross-contaminating configurations.
- Documentation discipline: every configuration change is documented, every evidence artifact is captured, every deviation from the SOP is noted.
- Troubleshooting: when Conditional Access blocks legitimate users, when Sentinel data connectors go unhealthy, or when WDAC blocks a required application, you can diagnose and resolve without waiting for escalation.
- Security mindset: you understand why least privilege matters, why default-deny is the correct network posture, and why FIPS-validated encryption is required for CUI.
- Clear written communication: when you find something in the client environment that does not match what the GRC Consultant scoped, you can document it clearly so the team can make decisions.
- Benefits.
- Medical Insurance Plan.
- Dental & Vision.
- Life Insurance.
- Disability Coverage.
- Paid Time Off (starts at 15 days per year).
- Maternity/Paternity Leave.
- Paid US Holiday.
- Retirement Plan.
- Salary Advancement/Loan.
- Health & Wellness Program.
- Company-paid training and certification.
- Supplemental Life Insurance (Employee-paid).
- Supplemental Health Plans (Employee-paid).
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the CMMC Security Engineer (Hybrid) in United States vacancy
- ...Cmmc Security Engineer We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and leading cybersecurity... ...remediation tracking, and continuous risk management across hybrid and cloud environments. Support incident response, threat...SuggestedRemote work
- ...seeking a Cybersecurity Advisor specializing in CMMC compliance to enhance client cybersecurity posture. This hybrid role requires a minimum of three days per week onsite... ...essential. Join a team focused on innovation, security, and career advancement. #J-18808-Ljbffr Eccalon...Suggested3 days per week
$55 - $70 per hour
...Security Engineer / IT Support / Grapevine TX / Hybrid Grapevine, Texas Hybrid Contract $55/hr - $70/hr A technology startup in the Grapevine, TX... ...Experience Experience supporting or contributing to CMMC, NIST 800-171, or similar compliance initiatives...SuggestedFull timeContract workTemporary workFlexible hours- ...candidate will have a bachelor's degree in a related field and 4-6 years of experience, particularly with CMMC compliance and tools like SentinelOne. The role supports a hybrid working environment with a focus on collaboration and a vibrant workplace culture. #J-18808-Ljbffr...Suggested
$120k - $160k
...market applications. We are seeking a Security & Infrastructure Engineer to help build and operate secure,... ...across the company, including a new CMMC-compliant enclave environment supporting... ...internal systems as the company grows. Hybrid role -- candidates must be located in...SuggestedLocal areaRelocation$140k - $150k
...CMMC Security Engineer/T3/CCA/CCP Philadelphia, Pennsylvania 100% Remote Full Time $140k - $150k Join a fully remote, full-time opportunity with a rapidly growing cybersecurity consulting firm specializing in federal compliance and defense sector clients....Full timeFor contractorsRemote work- ...dedicated, collaborative and innovative workforce This is a hybrid position where approximately 40% of the work time is spent at... ...San Francisco, California. Summary The IT Security Engineer performs core security functions for the enterprise. The primary...Work experience placementWork at officeLocal areaRemote workWork from homeHome officeWork visaRelocation package
- ...Security Engineer- Hybrid NTT DATA Services strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Security...Work at officeLocal areaRemote work
- ...Vulnerability Detection Engineer CrowdStrike is looking for a Vulnerability Detection... ...and technical solutions. This role is hybrid, requiring 2-3 days per week on-site at... ...and other threats. Work experience in the security industry is highly desirable, including...Work experience placementWork at officeRemote work2 days per week3 days per week
- ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Security Engineer- Hybrid to join our team in Fort Washington, Pennsylvania (US-PA), United States (US). The Security Engineer is a hands-on...Work at officeLocal areaRemote workFlexible hours
- ...Hello, Job Title: Security Engineer II Location: Newport Beach, California ***Must sit hybrid in the Newport Beach, CA location (2 days a week onsite) On W2 Contract, Rate part is bit challenging for this role but we can discuss on the rate...Contract workLocal area2 days per week
- Lyft is seeking a Software Engineer with a focus on Security to join their team in Seattle. This role involves designing secure processes, improving... ...solid understanding of networking protocols. Lyft offers a hybrid work model and competitive benefits, making it a great...
- B Capital in San Francisco is seeking a hands-on Senior Security Engineer to lead and scale security efforts in a rapidly growing team. You... ...proven experience in a startup environment. This role offers a hybrid work model, ensuring flexibility and competitive benefits....
- ...Texas. The role requires a bachelor's degree and experience in security technologies. Duties involve designing and supporting IAM solutions... ...in IAM and strong communication skills. Simeio offers a hybrid work environment and a commitment to diversity and inclusion. #J...
- Greenberg Traurig is seeking an Identity and Security Engineer in West Palm Beach, Florida. This role focuses on engineering, architecture,... ...with competitive compensation and benefits. You will work in a hybrid setting, contributing to complex identity systems and...
$130k - $150k
Piper Companies is seeking a SOC II Engineer (Tier II Support) to bolster security operations for a leading technology firm. This role demands hands-on incident... ...000, accompanied by a complete benefits package and a hybrid work schedule in RTP, NC or Fulton, MD. Applications...$43.59 - $51.59 per hour
...Genesis10 is currently seeking a Senior Information Security Engineer (Network Security) for a hybrid position with a Global Financial Institution located in Irving, TX or Charlotte, NC. This is an 18+ month contract opportunity. We are looking for a skilled and driven...Hourly payPermanent employmentContract workWork experience placement- ...We are seeking a skilled and motivated Firewall & Network Security Engineer with hands-on experience supporting Palo Alto Networks Next-Generation... ..., is preferred. _ This position offers flexibility for a hybrid work schedule, combining in-office and virtual work, and must...Work at officeLocal areaRemote workRelocation packageFlexible hours
$100k - $140k
...Network Security Engineer Dallas, Texas Hybrid Full Time $100k - $140k We are hiring a Network & Security Engineer for a full-time opportunity supporting a large-scale industrial and enterprise environment across multiple locations including Dallas, TX;...Full time- ...Network Security Engineer / Hybrid / Dallas / Phoenix A senior level network security engineering opportunity is available with a large enterprise organization supporting a modern, highly secure infrastructure. This hybrid role is based in Charlotte, NC, Dallas, TX...Full timeWork at office
- ...Sr. Network Security Engineer Location: Spring, TX. Hybrid. Type of Job: Contract. Qualifications: Mandatory Skills: Checkpoint, Fortinet, Palo Alto • A bachelor's degree from an accredited institution ~8+ years' experience mid...Contract work
$60 - $75 per hour
...Information Systems Security Engineer / Hybrid in DC Washington, District Of Columbia Hybrid Contract $60/hr - $75/hr A growing technology organization supporting federal and enterprise environments is seeking an Information Systems Security Engineer (ISSE...Full timeContract workTemporary workFlexible hours3 days per week- ...Mid-level Information System Security Engineer (ISSE) Coalfire Federal is a market leading cybersecurity consultancy firm that provides... ...mitigate the impact of such threats. Location Details Hybrid - 3 days on government client site What You'll Do The...Local areaFlexible hours
$123k - $145k
Faro-Health-Inc. is seeking a Senior Security Engineer to protect our cloud infrastructure and customer data. This hands-on role will involve... ...with equity and comprehensive benefits including health care and a hybrid work environment. #J-18808-Ljbffr Faro-Health-Inc.- A leading financial systems firm in North Bergen, NJ is seeking a Security Engineer specializing in digital identity and encryption. This hybrid role involves administering digital certificate systems, maintaining encryption infrastructure, and troubleshooting authentication...
- International Logic Systems, Inc. is looking for a Middleware Engineer in Fairfax, VA, specializing in IBM Security Access Manager (ISAM) and application server... ...within a secure federal environment. This hybrid role requires two on-site days per week, making local...Local area2 days per week
$100k - $120k
A staffing agency is seeking a Senior Security Engineer to provide cybersecurity solutions for clients in a hybrid working environment. The role requires strong technical expertise, including server and PC security solutions, and the ability to lead junior engineers. Responsibilities...- ...financial services firm in San Francisco is looking for a Senior Security Operations Engineer to prevent, detect, and respond to security threats in... ...to ensure robust security measures. The role offers a hybrid work environment, requiring a minimum of three days in the...Remote jobWork at office
- A leading cybersecurity firm is seeking a Senior Network Security Engineer to develop and deploy robust network security for their operations. This hybrid role requires 7+ years in network security engineering, focusing on DDoS mitigation and protocol management. The candidate...Flexible hours
$40 - $44 per hour
Akraya Inc. is seeking a Network Security Engineer in Plano, Texas to provide critical expertise on Next Generation Firewall (NGFW) technologies. In this hybrid role, you will collaborate with product and engineering teams to enhance customer satisfaction and ensure optimal...Hourly pay
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to CMMC Security Engineer (Hybrid). Be the first to apply!
Related searches
- information system security engineer United States
- staff security engineer United States
- senior application security engineer United States
- sr information security engineer United States
- security engineering manager United States
- electronic security engineer United States
- java security engineer United States
- security operations engineer United States
- junior network security engineer United States
- cloud security engineer United States

