Staff Security & Compliance Engineer- M365 GCCH CMMC

ServiceNow

Not Interested
Bookmark
Report This Job

profile Job Location:

Boston, NH - USA

profile Monthly Salary: Not Disclosed
Posted on: 5 hours ago
Vacancies: 1 Vacancy

Job Summary

About the team:


We are the backbone of Microsoft-powered collaboration at ServiceNow. Our team owns and manages the organizations Microsoft infrastructure spanning Outlook SharePoint OneDrive Microsoft Teams and the broader collaboration ecosystem ensuring employees have the tools access and experience they need to work seamlessly. 

Beyond keeping the lights on we take a strong stance on security and governance within the Microsoft environment. From access controls and data policies to compliance frameworks we ensure our collaboration platforms are not just productive but safe compliant and built to scale. 

Whether its enabling the workforce through modern collaboration tools or safeguarding the integrity of our Microsoft ecosystem the DT Collaboration team sits at the intersection of productivity and trust. 

About the role: 


We are seeking a senior individual contributor to lead the technical design implementation and ongoing security operations of a Microsoft 365 GCC High environment supporting Controlled Unclassified Information (CUI). This role is accountable for implementing and evidencing compliance with CMMC Level 2 DFARS 7012 and NIST 800-171 controls. 

The engineer will act as the technical owner of the GCC High enclave partnering with Security Legal and IT to ensure audit readiness and successful certification by May 2026. 

This role requires independent execution deep security expertise and the ability to translate regulatory requirements into enforceable technical controls. 

The impact youll make:

Architecture & Tenant Build 

  • Lead GCC High tenant design and deployment 
  • Define secure architecture for: 
  • Entra ID (Azure AD) 
  • Exchange Online 
  • SharePoint/OneDrive 
  • Teams 
  • Intune 
  • Defender Suite 
  • Purview Compliance 
  • Establish Zero Trust and least-privilege administrative model 
  • Design CUI boundary protections and data segmentation 

Compliance Implementation (CMMC/NIST 800-171) 

  • Map CMMC practices to technical controls and configurations 
  • Develop and maintain: 
    • System Security Plan (SSP) 
    • Control narratives 
    • Evidence repository 
    • POA&M 
  • Implement: 
    • MFA/Conditional Access 
    • Device compliance & endpoint hardening 
    • Logging/monitoring/SIEM integration 
    • DLP & data classification 
    • Incident response workflows 
  • Lead readiness reviews and assessment preparation with C3PAOs 

Security Operations 

  • Own security baselines and tenant hardening 
  • Manage vulnerability remediation lifecycle 
  • Oversee incident investigations and root cause analysis 
  • Establish monitoring alerting and audit logging standards 
  • Drive continuous improvement of controls 

Cross-Functional Leadership (IC4 Scope) 

  • Serve as technical authority for GCC High security decisions 
  • Provide guidance to operations engineers and offshore support 
  • Partner with Legal/Compliance on regulatory interpretation 
  • Present risk posture and compliance metrics to leadership 
  • Mentor junior engineers (without direct management responsibility) 

Qualifications :

  • U.S. Person (citizen or permanent resident)  required for GCC High/CUI access.
  • 610 years Microsoft 365/Azure security engineering experience. 
  • Hands-on implementation of GCC High or FedRAMP/DoD environments. 
  • Direct experience with: 
    • CMMC or NIST 800-171 control implementation 
    • Intune & endpoint security 
    • Entra ID Conditional Access/PIM 
    • Defender suite 
    • Purview (DLP/eDiscovery/Insider Risk) 
  • Experience preparing for security audits or assessments. 
  • Strong technical documentation skills. 

Extras:

  • CISSP CISM or Security 
  • Microsoft SC-100 SC-200 SC-300 MS-102 
  • Gov/DoD contracting environment experience 

Additional Information :

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible remote or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.

Equal Opportunity Employer

ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color creed religion sex sexual orientation national origin or nationality ancestry age disability gender identity or expression marital status veteran status or any other category protected by addition all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. 

Accommodations

We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process or are unable to use this online application and need an alternative method to apply please contact for assistance. 

Export Control Regulations

For positions requiring access to controlled technology subject to export control regulations including the U.S. Export Administration Regulations (EAR) ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. 

From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license. 


Remote Work :

No


Employment Type :

Full-time

About the team:We are the backbone of Microsoft-powered collaboration at ServiceNow. Our team owns and manages the organizations Microsoft infrastructure spanning Outlook SharePoint OneDrive Microsoft Teams and the broader collaboration ecosystem ensuring employees have the tools access and experi...
View more view more

Key Skills

  • Anti Money Laundering
  • Accounting Tally
  • Android
  • Council
  • Downstream
  • Bakery

About Company

Company Logo

Learn here. Grow here. Make a difference here. At ServiceNow, our cloud?based platform and solutions deliver digital workflows that create great experiences and unlock productivity for employees and enterprises. We’re growing fast, innovating even faster, and making an impact on our c ... View more

View Profile View Profile