Job Description
<p><strong>About the team:</strong></p><p><br>
We are the backbone of Microsoft-powered collaboration at ServiceNow. Our team owns and manages the organization's Microsoft infrastructure — spanning Outlook, SharePoint, OneDrive, Microsoft Teams, and the broader collaboration ecosystem — ensuring employees have the tools, access, and experience they need to work seamlessly. </p><p>Beyond keeping the lights on, we take a strong stance on security and governance within the Microsoft environment. From access controls and data policies to compliance frameworks, we ensure our collaboration platforms are not just productive — but safe, compliant, and built to scale. </p><p>Whether it's enabling the workforce through modern collaboration tools or safeguarding the integrity of our Microsoft ecosystem, the DT Collaboration team sits at the intersection of productivity and trust. </p><p><strong>About the role: </strong></p><p><br>
We are seeking a senior individual contributor to lead the technical design, implementation, and ongoing security operations of a Microsoft 365 GCC High environment supporting Controlled Unclassified Information (CUI). This role is accountable for implementing and evidencing compliance with CMMC Level 2, DFARS 7012, and NIST 800-171 controls. </p><p>The engineer will act as the technical owner of the GCC High enclave, partnering with Security, Legal, and IT to ensure audit readiness and successful certification by May 2026. </p><p>This role requires independent execution, deep security expertise, and the ability to translate regulatory requirements into enforceable technical controls. </p><p><strong>The impact you'll make:</strong></p><p><strong>Architecture & Tenant Build </strong></p><ul><li>Lead GCC High tenant design and deployment </li><li>Define secure architecture for: </li><li>Entra ID (Azure AD) </li><li>Exchange Online </li><li>SharePoint/OneDrive </li><li>Teams </li><li>Intune </li><li>Defender Suite </li><li>Purview Compliance </li><li>Establish Zero Trust and least-privilege administrative model </li><li>Design CUI boundary protections and data segmentation </li></ul><p><strong>Compliance Implementation (CMMC/NIST 800-171) </strong></p><ul><li>Map CMMC practices to technical controls and configurations </li><li>Develop and maintain: <ul><li>System Security Plan (SSP) </li><li>Control narratives </li><li>Evidence repository </li><li>POA&M </li></ul></li><li>Implement: <ul><li>MFA/Conditional Access </li><li>Device compliance & endpoint hardening </li><li>Logging/monitoring/SIEM integration </li><li>DLP & data classification </li><li>Incident response workflows </li></ul></li><li>Lead readiness reviews and assessment preparation with C3PAOs </li></ul><p><strong>Security Operations </strong></p><ul><li>Own security baselines and tenant hardening </li><li>Manage vulnerability remediation lifecycle </li><li>Oversee incident investigations and root cause analysis </li><li>Establish monitoring, alerting, and audit logging standards </li><li>Drive continuous improvement of controls </li></ul><p><strong>Cross-Functional Leadership (IC4 Scope)</strong> </p><ul><li>Serve as technical authority for GCC High security decisions </li><li>Provide guidance to operations engineers and offshore support </li><li>Partner with Legal/Compliance on regulatory interpretation </li><li>Present risk posture and compliance metrics to leadership </li><li>Mentor junior engineers (without direct management responsibility) </li></ul>
<ul><li>U.S. Person (citizen or permanent resident) – required for GCC High/CUI access.</li><li>6–10+ years Microsoft 365/Azure security engineering experience. </li><li>Hands-on imple ... (truncated, view full listing at source)