> Markdown version of [/jobs/ext/559664-senior-microsoft-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/559664-senior-microsoft-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Microsoft Cloud Engineer - **Company:** PROVEN Inc. - **Location:** Tinley Park, IL, United States - **Experience:** Expert - **Salary:** $125,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Microsoft Online Services, Cyber Security, Identity and Access Management, Key Management, Virtual Desktops, Network Diagrams, Role-Based Access Control, Kusto Query Language, Sharepoint Document Library, Runbook, Microsoft SharePoint, Toolchain, Information Security Management System, Microsoft InTune, Microsoft Sentinel - **Published:** June 14, 2026 - **Apply:** https://www.juju.com/job/00000000g7wrf7 ## About the Role Candidates must have hands-on experience provisioning and administering Microsoft GCC High environments. Azure Commercial experience alone is insufficient - the build schedule has no capacity to absorb a GCC High learning curve., Candidates without direct GCC High or M365 Government environment experience will require a ramp period this build cannot accommodate. + M365 GCC High: hands-on tenant provisioning and administration; Azure Commercial equivalents do not qualify + Microsoft Sentinel: MSSP workspace architecture, cross-workspace KQL, Lighthouse-delegated RBAC, analytics rule configuration + Azure Virtual Desktop: deployment and administration in Azure Government (not commercial AVD) + Microsoft Intune (GCC High): device enrollment, Compliance policies, Conditional Access integration + Entra ID Governance: Privileged Identity Management (PIM), Conditional Access, Named Locations, Identity Protection + Microsoft Lighthouse: multi-tenant delegation configuration and RBAC scoping for MSSP management + Azure Arc: server and hybrid endpoint onboarding and management + SharePoint GCC High: site architecture, permissions model, and document library structure + Azure Key Vault: provisioning, access policy configuration, and secrets management Preferred Qualifications + CrowdStrike Falcon sensor deployment and policy baseline configuration - Falcon Gov and/or Falcon Commercial + Azure DevOps Boards configuration and administration + Prior experience building or operating within a CMMC Level 2 or FedRAMP High environment + Client-facing technical experience - security advisory, vCISO support, client onboarding, or security architecture reviews + Microsoft certifications: SC-200, SC-300, AZ-800/801, MS-102, or equivalent ## Description Infrastructure Build + Provision Atom's GCC High Operations Tenant through an AOS-G authorized partner and build the parallel Azure Commercial Operations Tenant as isolated sovereign tracks + Establish Entra ID baseline across both tenants: admin account structure, security group naming conventions, and identity governance configuration + Deploy Azure Virtual Desktop host pool in Azure Government for SOC analyst and vCISO secure access + Configure Microsoft Lighthouse delegation framework across both tracks to support multi-client MSSP management + Implement FIDO2/phish-resistant MFA and Conditional Access policies across all administrative accounts on both tenants Identity and Access Governance + Configure Privileged Identity Management (PIM) for all privileged roles across both tenants + Enroll all analyst devices, vCISO devices, and AVD session hosts into GCC High and Commercial Intune respectively + Document the separate Entra identity model (distinct UPNs per track) as a formal access control artifact Security Toolchain Deployment + Stand up Microsoft Sentinel MSSP workspaces on both tracks with baseline analytics rules, alert routing, and cross-workspace KQL queries + Apply Defender XDR P2 baseline policy across the GCC High tenant + Deploy CrowdStrike Gov endpoint agents to CMMC client environments; deploy CrowdStrike Commercial Falcon for non-CMMC clients + Activate Azure Arc and Intune management on Atom operations devices + Verify track separation end-to-end and reflect findings in finalized network diagrams Legacy Tool Migration + Build SharePoint GCC High site structure to receive runbooks, SOPs, and client documentation migrated from legacy documentation platforms + Configure Azure DevOps Boards (GCC High) as the ticketing and work management replacement + Provision Azure Key Vault and execute controlled credential migration with documented access policy review + Update Atom's System Security Plan (SSP) to remove transitional tool entries upon retirement confirmation Go-Live and Growth + Support compliance documentation sprints - provide infrastructure evidence artifacts for SSP completion + Conduct end-to-end Lighthouse delegation testing for both anchor clients prior to go-live + Complete final infrastructure verification pass against the go-live readiness checklist + Support onboarding of client accounts to the Atom service delivery model post-launch + As the practice scales, participate in client-facing technical work - including vCISO engagements, client onboarding, security architecture reviews, and direct advisory relationships with DIB and commercial clients ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Speeding up Web Apps performance with WebAssembly and Emscripten](https://www.wearedevelopers.com/videos/1985-speeding-up-web-apps-performance-with-webassembly-and-emscripten) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [The Power of Developer Communities](https://www.wearedevelopers.com/videos/1109-the-power-of-developer-communities) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026)