C

Microsoft Systems Engineer - CMMC Compliance & Intune Administration

CBTS United State
Remote
Apply
AI Summary

Serve as the primary Microsoft systems engineer for a government defense program, ensuring CMMC compliance across Microsoft 365, Azure AD/Entra ID, Intune, and Defender technologies. Own device enrollment, compliance policies, and endpoint management while supporting security operations and Varonis data governance. Must be a U.S. citizen with government security clearance eligibility.

Key Highlights
CMMC compliance requirements for Microsoft 365 and endpoint security
Primary responsibility for Microsoft Intune device and app management
U.S. citizen required with government security clearance eligibility
Key Responsibilities
Serve as the primary resource for Microsoft Intune, owning all aspects of device enrollment, compliance policies, configuration profiles, app deployment, Autopilot, and Conditional Access
Engage with the implementation partner during the transition overlap period, attend technical working sessions, review documentation, and shadow deployment activities to ensure a smooth handoff
Take full operational ownership of Intune post-handoff, including ongoing administration, troubleshooting, policy lifecycle management, and end-user escalation support
Administer and support Microsoft Defender for Endpoint including onboarding, policy configuration, alert triage, and integration with the broader Microsoft security stack
Monitor Defender for Endpoint dashboards for threat detections, vulnerability findings, and device compliance signals — coordinating with the security team for investigation and remediation
Serve as the operational point of contact for Varonis within the Microsoft 365 environment, including monitoring data access activity, managing alerts, and reviewing user behavior analytics across SharePoint, OneDrive, Exchange, and Teams
Leverage Varonis to identify and remediate overexposed or misconfigured data permissions across M365 workloads, working in close coordination with the security and compliance teams
Provide Tier 2/3 escalation support for Microsoft and Intune-related issues, working in coordination with the program's help desk and IT staff
Collaborate with the security team to maintain endpoint compliance posture, device health reporting, and vulnerability remediation tracking
Provide informal training and guidance to adjacent IT staff on Intune, Microsoft 365, and Varonis best practices
Technical Skills Required
Microsoft Intune Azure Active Directory / Microsoft Entra ID Microsoft Defender for Endpoint
Benefits & Perks
Fully remote work
Contract position with potential conversion to permanent employment
Nice to Have
Microsoft certifications: MD-102 (Endpoint Administrator), MS-101, SC-300, AZ-104, or equivalent
Varonis certification or formal Varonis training (DatAdvantage, Data Classification Engine, or equivalent)
Prior experience using Varonis to support CMMC, FISMA, NIST 800-171, or DISA STIG compliance in a government or defense contractor environment
Experience integrating Varonis with Microsoft Sentinel or Microsoft Purview for unified data security visibility
Prior experience supporting federal government programs or working within compliance frameworks such as FedRAMP, FISMA, CMMC, or DISA STIGs
Familiarity with Microsoft Defender for Endpoint, Defender for Identity, or Microsoft Sentinel
Experience transitioning a Microsoft environment from a third-party implementation partner
PowerShell scripting proficiency for Microsoft 365 and Intune automation tasks
Experience with SCCM/MECM co-management in hybrid Intune environments

Job Description


CBTS is seeking a well-rounded Microsoft Systems Engineer to support a high-visibility government defense program operating under CMMC compliance requirements. This is a contract position with the potential to convert to permanent employment based on performance and program needs. In this fully remote role, you will be the go-to resource for all things Microsoft — supporting the full Microsoft 365 ecosystem, Azure Active Directory / Entra ID, Microsoft Defender, and endpoint management through Intune. The environment demands a practitioner who understands how Microsoft technologies intersect with CMMC controls, and who can ensure the program’s endpoint posture, data access governance, and security configurations remain audit-ready. While this role spans the breadth of the Microsoft stack, Intune will serve as a primary area of emphasis given an active implementation currently underway


Microsoft Intune — Primary Emphasis

  • Serve as the primary resource for Microsoft Intune, owning all aspects of device enrollment, compliance policies, configuration profiles, app deployment, Autopilot, and Conditional Access.
  • Engage with the implementation partner during the transition overlap period, attend technical working sessions, review documentation, and shadow deployment activities to ensure a smooth handoff.
  • Take full operational ownership of Intune post-handoff, including ongoing administration, troubleshooting, policy lifecycle management, and end-user escalation support.
  • Maintain Intune configurations in alignment with government security and compliance requirements including CMMC, DISA STIGs, NIST 800-171, CIS benchmarks, and applicable federal frameworks, ensuring endpoint posture directly supports the program’s compliance obligations.


Microsoft Ecosystem Administration

  • Serve as the primary support resource for all Microsoft technologies across the environment — functioning as the first call for anything Microsoft-related, from M365 workloads to identity, security, and endpoint management.
  • Administer and support the full Microsoft 365 suite: Exchange Online, SharePoint Online, Microsoft Teams, OneDrive for Business, and related workloads.
  • Manage Azure Active Directory / Microsoft Entra ID including users, groups, roles, licensing, and Conditional Access policies.
  • Support Windows 10/11 endpoint management including OS deployment, patching strategy (WUfB/WSUS), and update compliance reporting.
  • Manage Microsoft 365 tenant health, licensing, and service configurations in support of program operations.


Microsoft Defender — Security Operations Support

  • Administer and support Microsoft Defender for Endpoint including onboarding, policy configuration, alert triage, and integration with the broader Microsoft security stack.
  • Monitor Defender for Endpoint dashboards for threat detections, vulnerability findings, and device compliance signals — coordinating with the security team for investigation and remediation.
  • Support Microsoft Defender for Identity and Defender for Office 365 configurations as applicable to the program environment.
  • Assist with Microsoft Sentinel integration for unified security event correlation across Defender signals, Intune compliance data, and Entra ID activity.
  • Contribute to security incident response efforts by providing Microsoft-stack telemetry, isolating affected endpoints via Intune/Defender, and documenting findings per program procedures.


Transition, Documentation & Knowledge Management

  • Proactively engage with the implementation partner to capture configuration decisions, design rationale, and operational procedures.
  • Develop and maintain comprehensive runbooks, SOPs, and technical documentation for all Intune and Microsoft environment configurations.
  • Identify and communicate any gaps, risks, or incomplete items in the implementation prior to formal handoff.


Varonis Data Security Administration

  • Serve as the operational point of contact for Varonis within the Microsoft 365 environment, including monitoring data access activity, managing alerts, and reviewing user behavior analytics across SharePoint, OneDrive, Exchange, and Teams.
  • Leverage Varonis to identify and remediate overexposed or misconfigured data permissions across M365 workloads, working in close coordination with the security and compliance teams.
  • Utilize Varonis dashboards and reporting to support government compliance requirements including CMMC, FISMA, and NIST 800-171 — producing audit-ready evidence of data access controls and governance posture.
  • Monitor Varonis threat detection alerts for anomalous user behavior, unauthorized access attempts, and potential insider threats, escalating confirmed incidents to the security team per program procedures.
  • Maintain and tune Varonis classification policies to ensure accurate discovery and labeling of Controlled Unclassified Information (CUI) and other sensitive data categories across the environment.


Ongoing Operations & Tier 2/3 Support

  • Provide Tier 2/3 escalation support for Microsoft and Intune-related issues, working in coordination with the program’s help desk and IT staff.
  • Collaborate with the security team to maintain endpoint compliance posture, device health reporting, and vulnerability remediation tracking.
  • Participate in the change management process including CAB submissions, testing, and deployment coordination for Microsoft environment changes.
  • Provide informal training and guidance to adjacent IT staff on Intune, Microsoft 365, and Varonis best practices.


WHAT YOU BRING

Required

  • 5+ years of hands-on experience administering Microsoft technologies in an enterprise environment, with demonstrated breadth across the Microsoft stack.
  • Strong expertise with Microsoft Intune including device enrollment (Windows, iOS, Android), compliance policies, configuration profiles, app deployment, and Windows Autopilot.
  • Hands-on experience with Microsoft Defender for Endpoint — including onboarding, policy configuration, alert triage, and incident response coordination.
  • Strong working knowledge of Azure Active Directory / Microsoft Entra ID including Conditional Access, MFA, and hybrid identity scenarios.
  • Proficient in Microsoft 365 administration across Exchange Online, SharePoint, Teams, and OneDrive.
  • Solid understanding of Windows 10/11 endpoint management, Group Policy, and enterprise patching strategies.
  • Hands-on experience with Varonis including data access governance, alert monitoring, user behavior analytics, and compliance reporting within a Microsoft 365 environment.
  • Ability to produce high-quality technical documentation, runbooks, and SOPs.
  • Strong communication and collaboration skills suited for a remote, cross-functional program environment.
  • Must be a U.S. citizen and able to obtain or maintain a government security clearance.


Preferred

  • Microsoft certifications: MD-102 (Endpoint Administrator), MS-101, SC-300, AZ-104, or equivalent.
  • Varonis certification or formal Varonis training (DatAdvantage, Data Classification Engine, or equivalent).
  • Prior experience using Varonis to support CMMC, FISMA, NIST 800-171, or DISA STIG compliance in a government or defense contractor environment.
  • Experience integrating Varonis with Microsoft Sentinel or Microsoft Purview for unified data security visibility.
  • Prior experience supporting federal government programs or working within compliance frameworks such as FedRAMP, FISMA, CMMC, or DISA STIGs.
  • Familiarity with Microsoft Defender for Endpoint, Defender for Identity, or Microsoft Sentinel.
  • Experience transitioning a Microsoft environment from a third-party implementation partner.
  • PowerShell scripting proficiency for Microsoft 365 and Intune automation tasks.
  • Experience with SCCM/MECM co-management in hybrid Intune environments.


WORK ENVIRONMENT

  • Fully remote — must have a secure, reliable home office setup.
  • Core working hours aligned to program time zone requirements; flexibility needed for change windows and overlap sessions with the implementation partner.
  • This is a contract role with the potential to convert to a permanent position based on performance and program fit.
  • U.S. citizenship required; clearance eligibility is a condition of employment for this program.



Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

TEKsystems

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Swooped

United State
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

ConsultNet Technology Services...

United State

Subscribe our newsletter

New Things Will Always Update Regularly