> Markdown version of [/jobs/ext/1233739-senior-systems-engineer](https://www.wearedevelopers.com/jobs/ext/1233739-senior-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Systems Engineer - **Company:** nuvioIT LLC - **Location:** Norfolk, VA, United States - **Experience:** Expert - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Application Firewall, Systems Engineering, Microsoft Azure, Microsoft Online Services, Cloud Computing, Cyber Security, Computer Networks, Dynamic Host Configuration Protocol, Domain Name System (DNS), Hyper-V, Identity and Access Management, Virtual Private Networks (VPN), Microsoft Security Essentials, Microsoft Office, Windows Servers, Network Architecture, Network Diagrams, Routing, Network Segmentation, Windows PowerShell, Kusto Query Language, Virtual Local Area Networks, Virtualization Technology, Software Vulnerability Management, EndPointSecurity, Computer Networking Systems, Firewalls (Computer Science), Microsoft InTune, Build Tools, Cisco, Vmware - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7f950983d39869cd ## About the Role * 7+ years of systems or security engineering experience, with at least 3 years in regulated environments (DoD contractors, federal, healthcare, or financial services). * Direct experience supporting CMMC or NIST SP 800-171 compliance programs, including control implementation and evidence production. * Hands-on experience with Microsoft 365 GCC High, including its licensing, service parity differences from commercial, and data residency and export control considerations (ITAR/EAR awareness). * Deep proficiency with the Microsoft security stack: Defender for Endpoint, Defender for Office 365, Sentinel, Entra ID and Conditional Access, Intune, and Purview. * Strong networking experience: firewall administration, routing and switching, VLANs and network segmentation, VPN, DNS/DHCP, and structured troubleshooting. * Hands-on virtualization experience with Hyper-V and/or VMware, including host management, Windows Server administration, and workload migrations. * Strong identity and access management fundamentals: MFA enforcement, PIM, role-based access, and device compliance policies. * Experience writing technical documentation suitable for assessor review., * CMMC ecosystem credentials: Certified CMMC Professional (CCP). * Microsoft certifications such as SC-200, SC-300, AZ-500, or MS-102. * Experience at an MSP or MSSP serving multiple client tenants concurrently. * Familiarity with Azure Government, AVD or Windows 365 Cloud PC, and secure remote support architectures. * Experience with ConnectWise Manage, NinjaOne, Cisco Duo, or comparable PSA, RMM, and MFA platforms. * Scripting and automation skills (PowerShell, Microsoft Graph API, KQL). ## Description nuvioIT is hiring a Senior Engineer to design, deploy, and operate secure Microsoft cloud environments for defense contractors and commercial clients. This is a hands-on senior technical role: you will architect and administer Microsoft 365 GCC High and commercial tenants, implement and tune Microsoft security tooling, engineer and support client networks and virtualization platforms, support CMMC Level 2 readiness and assessment activities, and serve as a technical escalation point for our service desk and systems engineering team. The right candidate has lived inside regulated environments. You understand why a control exists, what an assessor will ask for, and how to build systems that produce their own evidence. You are comfortable being accountable for client environments where mistakes have contractual and compliance consequences., Environment Architecture and Administration * Design, deploy, and administer Microsoft 365 GCC High and commercial tenants for DIB and commercial clients, including migrations into GCC High. * Implement and maintain Microsoft security tooling across client environments, including Defender, Sentinel, Entra ID with Conditional Access, Intune, and Purview. * Manage privileged identity management (PIM) and least-privilege access models across client tenants. * Harden endpoints and identities to CMMC Level 2 aligned baselines using Intune and, where applicable, Active Directory Group Policy. * Design, implement, and troubleshoot client network infrastructure, including firewalls, routing and switching, VLAN segmentation, VPN, and wireless. * Administer virtualization platforms (Hyper-V, VMware) and Windows Server environments, including upgrades, capacity planning, and migrations to cloud infrastructure. Security Operations * Build, tune, and maintain Sentinel analytics rules, workbooks, and automation for client environments. * Investigate and respond to security incidents as a senior SOC resource, including containment, remediation, and client communication. * Perform vulnerability management, flaw remediation, and configuration drift review across managed environments. CMMC and Compliance Engineering * Implement technical controls mapped to NIST SP 800-171 and CMMC Level 2 practices, and document how each control is enforced. * Contribute to System Security Plans (SSPs), POA&Ms, asset inventories, network diagrams, and shared responsibility matrices. * Produce and organize assessment evidence, and support clients through C3PAO assessments and readiness reviews. * Apply correct CMMC scoping discipline, including CUI asset, Security Protection Asset, and external service provider classifications. Team and Client Leadership * Act as a technical escalation point for desktop and systems engineers, and mentor junior staff. * Lead client-facing technical work: onboarding, architecture reviews, and change planning, documented through the PSA (ConnectWise Manage). * Maintain accurate, current documentation as a first-class deliverable, not an afterthought. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)