> Markdown version of [/jobs/ext/2014180-m365-cloud-engineer-us-only-gcc-high](https://www.wearedevelopers.com/jobs/ext/2014180-m365-cloud-engineer-us-only-gcc-high). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # M365 Cloud Engineer - US Only, GCC High - **Company:** PROVEN Inc. - **Location:** Tinley Park, IL, United States - **Salary:** $125,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Engineering, Cyber Security, Identity and Access Management, Key Management, Virtual Desktops, Network Diagrams, Role-Based Access Control, Kusto Query Language, Sharepoint Document Library, Runbook, Microsoft SharePoint, Toolchain, Information Security Management System, Microsoft InTune, Microsoft Sentinel - **Published:** August 10, 2026 - **Apply:** https://www.juju.com/job/00000000gmgoy9 ## About the Role Candidates must have hands-on experience provisioning and administering Microsoft GCC High environments. Azure Commercial experience alone is insufficient - the build schedule has no capacity to absorb a GCC High learning curve., Candidates without direct GCC High or M365 Government environment experience will require a ramp period this build cannot accommodate. + M365 GCC High: hands-on tenant provisioning and administration; Azure Commercial equivalents do not qualify + Microsoft Sentinel: MSSP workspace architecture, cross-workspace KQL, Lighthouse-delegated RBAC, analytics rule configuration + Azure Virtual Desktop: deployment and administration in Azure Government (not commercial AVD) + Microsoft Intune (GCC High): device enrollment, Compliance policies, Conditional Access integration + Entra ID Governance: Privileged Identity Management (PIM), Conditional Access, Named Locations, Identity Protection + Microsoft Lighthouse: multi-tenant delegation configuration and RBAC scoping for MSSP management + Azure Arc: server and hybrid endpoint onboarding and management + SharePoint GCC High: site architecture, permissions model, and document library structure + Azure Key Vault: provisioning, access policy configuration, and secrets management Preferred Qualifications + CrowdStrike Falcon sensor deployment and policy baseline configuration - Falcon Gov and/or Falcon Commercial + Azure DevOps Boards configuration and administration + Prior experience building or operating within a CMMC Level 2 or FedRAMP High environment + Client-facing technical experience - security advisory, vCISO support, client onboarding, or security architecture reviews + Microsoft certifications: SC-200, SC-300, AZ-800/801, MS-102, or equivalent ## Description Infrastructure Build + Provision Atom's GCC High Operations Tenant through an AOS-G authorized partner and build the parallel Azure Commercial Operations Tenant as isolated sovereign tracks + Establish Entra ID baseline across both tenants: admin account structure, security group naming conventions, and identity governance configuration + Deploy Azure Virtual Desktop host pool in Azure Government for SOC analyst and vCISO secure access + Configure Microsoft Lighthouse delegation framework across both tracks to support multi-client MSSP management + Implement FIDO2/phish-resistant MFA and Conditional Access policies across all administrative accounts on both tenants Identity and Access Governance + Configure Privileged Identity Management (PIM) for all privileged roles across both tenants + Enroll all analyst devices, vCISO devices, and AVD session hosts into GCC High and Commercial Intune respectively + Document the separate Entra identity model (distinct UPNs per track) as a formal access control artifact Security Toolchain Deployment + Stand up Microsoft Sentinel MSSP workspaces on both tracks with baseline analytics rules, alert routing, and cross-workspace KQL queries + Apply Defender XDR P2 baseline policy across the GCC High tenant + Deploy CrowdStrike Gov endpoint agents to CMMC client environments; deploy CrowdStrike Commercial Falcon for non-CMMC clients + Activate Azure Arc and Intune management on Atom operations devices + Verify track separation end-to-end and reflect findings in finalized network diagrams Legacy Tool Migration + Build SharePoint GCC High site structure to receive runbooks, SOPs, and client documentation migrated from legacy documentation platforms + Configure Azure DevOps Boards (GCC High) as the ticketing and work management replacement + Provision Azure Key Vault and execute controlled credential migration with documented access policy review + Update Atom's System Security Plan (SSP) to remove transitional tool entries upon retirement confirmation Go-Live and Growth + Support compliance documentation sprints - provide infrastructure evidence artifacts for SSP completion + Conduct end-to-end Lighthouse delegation testing for both anchor clients prior to go-live + Complete final infrastructure verification pass against the go-live readiness checklist + Support onboarding of client accounts to the Atom service delivery model post-launch + As the practice scales, participate in client-facing technical work - including vCISO engagements, client onboarding, security architecture reviews, and direct advisory relationships with DIB and commercial clients ## Related Videos - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Speeding up Web Apps performance with WebAssembly and Emscripten](https://www.wearedevelopers.com/videos/1985-speeding-up-web-apps-performance-with-webassembly-and-emscripten) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [The Power of Developer Communities](https://www.wearedevelopers.com/videos/1109-the-power-of-developer-communities) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)