×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Security & Compliance Engineer- M365 GCCH​/CMMC

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: ServiceNow, Inc.
Full Time position
Listed on 2026-03-02
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: Staff Security & Compliance Engineer- M365 GCCH/ CMMC

It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — Service Now stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work.

But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.

About the team:

We are the backbone of Microsoft-powered collaboration  team owns and manages the organization's Microsoft infrastructure — spanning Outlook, SharePoint, One Drive, Microsoft Teams, and the broader collaboration ecosystem — ensuring employees have the tools, access, and experience they need to work seamlessly.

Beyond keeping the lights on, we take a strong stance on security and governance within the Microsoft environment. From access controls and data policies to compliance frameworks, we ensure our collaboration platforms are not just productive — but safe, compliant, and built to scale.

Whether it's enabling the workforce through modern collaboration tools or safeguarding the integrity of our Microsoft ecosystem, the DT Collaboration team sits at the intersection of productivity and trust.

About the role:

We are seeking a senior individual contributor to lead the technical design, implementation, and ongoing security operations of a Microsoft 365 GCC High environment supporting Controlled Unclassified Information (CUI). This role is accountable for implementing and evidencing compliance with CMMC Level 2, DFARS 7012, and NIST 800-171 controls.

The engineer will act as the technical owner of the GCC High enclave, partnering with Security, Legal, and IT to ensure audit readiness and successful certification by May 2026.

This role requires independent execution, deep security expertise, and the ability to translate regulatory requirements into enforceable technical controls.

The impact you'll make:
Architecture & Tenant Build
  • Lead GCC High tenant design and deployment

  • Define secure architecture for:

  • Entra  (Azure AD)

  • Exchange Online

  • SharePoint/One Drive

  • Teams

  • Intune

  • Defender Suite

  • Purview Compliance

  • Establish Zero Trust and least-privilege administrative model

  • Design CUI boundary protections and data segmentation

Compliance Implementation (CMMC/NIST 800-171)
  • Map CMMC practices to technical controls and configurations

  • Develop and maintain:

  • System Security Plan (SSP)

  • Control narratives

  • Evidence repository

  • POA&M

  • Implement:

  • MFA/Conditional Access

  • Device compliance & endpoint hardening

  • Logging/monitoring/SIEM integration

  • DLP & data classification

  • Incident response workflows

  • Lead readiness reviews and assessment preparation with C3

    PAOs

Security Operations
  • Own security baselines and tenant hardening

  • Manage vulnerability remediation lifecycle

  • Oversee incident investigations and root cause analysis

  • Establish monitoring, alerting, and audit logging standards

  • Drive continuous improvement of controls

Cross-Functional Leadership (IC4 Scope)
  • Serve as technical authority for GCC High security decisions

  • Provide guidance to operations engineers and offshore support

  • Partner with Legal/Compliance on regulatory interpretation

  • Present risk posture and compliance metrics to leadership

  • Mentor junior engineers (without direct management responsibility)

  • U.S. Person (citizen or permanent resident) – required for GCC High/CUI access.

  • 6–10+ years Microsoft 365/Azure security engineering experience.

  • Hands-on implementation of GCC High or FedRAMP/DoD environments.

  • Direct experience with:

  • CMMC or NIST 800-171 control implementation

  • Intune & endpoint security

  • Entra l Access/PIM

  • Defender suite

  • Purview (DLP/eDiscovery/Insider Risk)

  • Experience preparing for security audits or assessments.

  • Strong technical documentation skills.

Extras:
  • CISSP, CISM, or Security+

  • Microsoft SC-100, SC-200, SC-300, MS-102

  • Gov/DoD contracting environment experience

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary