M365 Cloud Engineer - US , GCC
Listed on 2026-07-04
-
IT/Tech
Cybersecurity
Atom Security Cybersecurity Engineer
Atom Security LLC is a specialized cybersecurity brand purpose-built on the foundation of Proven IT, a trusted managed services provider with a proven track record of delivering technology solutions to clients across the Midwest. Built to extend Proven IT's continued success into a dedicated security practice, Atom Security delivers exceptional Managed Security Services (MSSP), professional security consulting, and fractional Chief Information Security Officer (vCISO) services to organizations that require specialized expertise beyond the scope of a generalist technology provider.
Atom Security's launch focus is the Defense Industrial Base (DIB), serving defense contractors pursuing CMMC Level 2 certification through a purpose-built Microsoft GCC High sovereign platform. In parallel, Atom's commercial practice serves clients in regulated industries including healthcare, finance, and manufacturing. This is a ground-floor opportunity to help build and define a specialized security brand from inception, with direct impact on the architecture, culture, and client experience of a growing practice.
This role owns end-to-end engineering delivery of Atom Security's GCC High and Azure Commercial operations infrastructure — from tenant provisioning through security toolchain deployment and legacy tool migration — against an active, near-term go-live target. The platform supports a dual-track service model: a Microsoft GCC High sovereign track for CMMC-scoped DIB clients, and an Azure Commercial track for the broader managed security practice.
This is a build role with a clear growth trajectory. The initial phase is a structured engineering sprint with defined deliverables and milestones. As the platform becomes operational and Atom Security scales, this position is designed to flex based on organizational needs and individual strengths — evolving toward either deep infrastructure ownership and ongoing platform administration, or toward client-facing technical roles including vCISO support, client onboarding, and technical advisory engagements with DIB and commercial clients.
The right candidate will have both the technical depth to build the platform and the professional presence to engage with clients as the practice grows.
Candidates must have hands-on experience provisioning and administering Microsoft GCC High environments. Azure Commercial experience alone is insufficient — the build schedule has no capacity to absorb a GCC High learning curve.
Key Responsibilities
- Provision Atom's GCC High Operations Tenant through an AOS-G authorized partner and build the parallel Azure Commercial Operations Tenant as isolated sovereign tracks
- Establish Entra across both tenants: admin account structure, security group naming conventions, and identity governance configuration
- Deploy Azure Virtual Desktop host pool in Azure Government for SOC analyst and vCISO secure access
- Configure Microsoft Lighthouse delegation framework across both tracks to support multi-client MSSP management
- Implement FIDO2/phish-resistant MFA and Conditional Access policies across all administrative accounts on both tenants
Identity and Access Governance
- Configure Privileged Identity Management (PIM) for all privileged roles across both tenants
- Enroll all analyst devices, vCISO devices, and AVD session hosts into GCC High and Commercial Intune respectively
- Document the separate Entra identity model (distinct UPNs per track) as a formal access control artifact
Security Toolchain Deployment
- Stand up Microsoft Sentinel MSSP work spaces on both tracks with baseline analytics rules, alert routing, and cross-workspace KQL queries
- Apply Defender XDR P2 baseline policy across the GCC High tenant
- Deploy Crowd Strike Gov endpoint agents to CMMC client environments; deploy Crowd Strike Commercial Falcon for non-CMMC clients
- Activate Azure Arc and Intune management on Atom operations devices
- Verify track separation end-to-end and reflect findings in finalized network diagrams
Legacy Tool Migration
- Build SharePoint GCC High site structure to receive runbooks, SOPs, and client documentation migrated from legacy documentation…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).