Job Description
Job Description
Position Overview
Execute the design, implementation, and operation of a comprehensive Microsoft GCC High technology stack within a FOCI-mitigated, CMMC Level 2 compliant defense manufacturing environment. Reporting to the Security Director, this role requires a hands-on technical leader who will architect, deploy, and maintain critical infrastructure while ensuring continuous and secure compliance with DoD requirements. This is a unique opportunity to build an enterprise IT environment from the ground up, establishing the technical foundation for a rapidly growing defense contractor.
Essential Duties and Responsibilities :
Technical Implementation
- Design and manage a Microsoft GCC High tenant including Entra ID, Conditional Access policies, Intune MDM, and Sentinel SIEM configurations
- Implement and maintain the full Atlassian suite (JIRA Service Management, Bitbucket Data Center, Confluence) including backend administration, SSO and webhook integrations
- Configure and manage Azure Stack HCI infrastructure, virtualization platforms, and hybrid cloud connectivity to AWS GovCloud
- Deploy Zero Trust architecture using Zscaler ZPA, Microsoft Conditional Access, and FIPS-compliant Cisco Meraki networking
- Implement security stack including SentinelOne EDR, Tenable.sc vulnerability management, Microsoft Purview DLP, and Delinea Secret Server PAM
- Configure automated patch management through PatchMyPC and Microsoft Autopilot for zero-touch provisioning
- Establish managed file transfer capabilities (MOVEit) and encrypted media controls (DataLocker) for CUI handling
- Manage and coordinate external consultants and contractors for CMMC assessment firms, and specialized security vendors; serve as primary technical liaison ensuring knowledge transfer, documentation of configurations, and successful transition of responsibilities to internal operations
- Design and implement Infrastructure as Code (IaC) using Ansible playbooks for automated deployment, configuration management, and compliance enforcement across Windows and Linux environments
- Deploy containerized applications using Docker and orchestration platforms for microservices architecture
Compliance & Security Operations
Maintain continuous CMMC Level 2 compliance through technical control implementation and evidence collectionConfigure and operate security monitoring tools ensuring 24 / 7 visibility of CUI environmentsImplement ITAR export control technical safeguards and FOCI mitigation measuresDevelop and maintain System Security Plans (SSP), POA&Ms, and technical compliance documentationExecute vulnerability management program with weekly scanning and monthly remediation cyclesCoordinate with external assessors for CMMC certification and annual compliance auditsImplement and maintain physical security integrations (Kastle Systems, Traction Guest)Process & Automation
Develop and maintain IT policies, procedures, and technical standards aligned with NIST 800-171 and CMMC Level 2Create automated workflows in JIRA Service Management for change control, incident response, and service requestsImplement AI-powered solutions for operational efficiencyDesign disaster recovery procedures leveraging Veeam and Zerto capabilitiesBuild PowerShell and Azure Automation runbooks for routine tasksEstablish Configuration Management Database (CMDB) and asset tracking systemsPerforms other related duties as assigned.Qualifications
Technical Expertise
5+ years hands-on experience with Microsoft Azure / M365 in government or regulated environmentsCisco networking proficiency required , including configuration and management of Meraki cloud-managed infrastructure, VLANs, network segmentation, FIPS-compliant implementations, and troubleshooting complex routing / switching issuesStrong expertise in Atlassian suite backend administration (JIRA, Confluence, Bitbucket) including database managementDeep experience implementing and managing GCC High tenants, including migration from commercial tenantsExpert knowledge of CMMC Level 2, NIST 800-171, and DFARS requirementsPrior experience with enterprise security tools (SIEM, EDR, DLP, PAM, vulnerability scanners)Strong PowerShell scripting and automation capabilitiesStrong Experience with virtualization platforms (Hyper-V, Azure Stack HCI) and backup solutionsExperience with configuration management and automation using Ansible, including playbook development, role creation, and AWX / Tower for enterprise orchestrationHands-on containerization experience with Docker, including Dockerfile creationCompliance & Regulatory
Direct experience in ITAR-controlled environments with understanding of export control requirementsKnowledge of FOCI mitigation measures and foreign person restrictionsExperience preparing for and supporting CMMC / DIBCAC assessmentsGreat Understanding of CUI marking, handling, and storage requirementsLeadership & Communication
Ability to work autonomously while aligning with organizational visionStrong technical documentation and procedure writing skillsExperience presenting technical concepts to non-technical stakeholdersProven ability to manage multiple complex projects simultaneouslyComfort working in rapidly changing, high-growth environmentsEducation / Experience
Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related fieldEquivalent combination of education and experience will be consideredPreferred Qualifications :
Certifications
Security certifications : CISSP, CCSP, or Security+CMMC Certified Professional (CCP) or Certified Assessor (CCA)Atlassian certifications (ACP-620, ACP-120)Cisco Certified Network Associate (CCNA)Meraki Solutions Specialist Certification (CMSS)Advanced Skills
AI / ML implementation experienceExperience with Zero Trust architecture design and implementationKnowledge of defense contractor business processes and workflowsExperience with KnowBe4 security awareness platform administrationFamiliarity with Deltek Costpoint or similar GovCon ERP systemsSecret or higher security clearance (or ability to obtain)Physical Demands / Work Environment :
Full-time on-site position with some remote work flexibilityMust be US CitizenAbility to lift to 50 lbs. for server / equipment installationOn-call rotation for critical infrastructure support