Support the company’s CMMC Level 2 program and protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Maintain security documentation, audit evidence, policies, system security plans, POA&Ms, risk records, and remediation tracking.
Monitor and investigate security events using SIEM and EDR tools; support incident response, threat monitoring, endpoint protection, and vulnerability management.
Administer identity and access controls across Active Directory, Microsoft Entra ID, Microsoft 365, SSO, MFA, privileged access, and employee onboarding/offboarding.
Maintain Windows servers and backend systems; assist with upgrades, patching, software updates, secure configurations, backups, and general infrastructure maintenance.
Support firewall and VPN administration, network security, segmentation, and remote access for employees.
Resolve user-facing issues involving accounts and access, VPN, printers, devices, and other IT needs. Assist with a CAT/CAC badge project.
Coordinate with internal teams, outside providers, and assessors; support supplier reviews, security awareness, disaster recovery, and business continuity work.
Participate in an on-call rotation and provide occasional after-hours support when needed.
Qualifications
At least three years of relevant IT operations or information security experience; five to seven years is preferred.
Hands-on experience spanning both cybersecurity and Windows-based IT infrastructure.
Practical knowledge of CMMC, CUI protection, and NIST 800-171; familiarity with DFARS, ITAR, or other export-control requirements is valuable.
Experience with Windows Server, Active Directory/Entra ID, Microsoft 365, networking, firewalls, VPNs, endpoint management, and security tools.
Familiarity with SIEM, EDR, and vulnerability scanning. CrowdStrike Falcon, Tanium, and ThreatLocker are examples of tools listed in the client’s JD; equivalent experience is welcome.
Strong communication, documentation, ownership, and ability to work independently in a small-team setting.