Jobs and Careers
PR

Senior Microsoft Cloud Engineer

Proven IT
Tinley Park, United Statesfull_timeVerifiedPosted 10 Jun 2026
💰 $140,000/yr($125,000/yr$140,000/yr)

About the role

Description

About Atom Security

Atom Security LLC is a specialized cybersecurity brand purpose-built on the foundation of Proven IT, a trusted managed services provider with a proven track record of delivering technology solutions to clients across the Midwest. Built to extend Proven IT’s continued success into a dedicated security practice, Atom Security delivers exceptional Managed Security Services (MSSP), professional security consulting, and fractional Chief Information Security Officer (vCISO) services to organizations that require specialized expertise beyond the scope of a generalist technology provider.


Atom Security’s launch focus is the Defense Industrial Base (DIB), serving defense contractors pursuing CMMC Level 2 certification through a purpose-built Microsoft GCC High sovereign platform. In parallel, Atom’s commercial practice serves clients in regulated industries including healthcare, finance, and manufacturing. This is a ground-floor opportunity to help build and define a specialized security brand from inception, with direct impact on the architecture, culture, and client experience of a growing practice.


About This Role

This role owns end-to-end engineering delivery of Atom Security’s GCC High and Azure Commercial operations infrastructure — from tenant provisioning through security toolchain deployment and legacy tool migration — against an active, near-term go-live target. The platform supports a dual-track service model: a Microsoft GCC High sovereign track for CMMC-scoped DIB clients, and an Azure Commercial track for the broader managed security practice.


This is a build role with a clear growth trajectory. The initial phase is a structured engineering sprint with defined deliverables and milestones. As the platform becomes operational and Atom Security scales, this position is designed to flex based on organizational needs and individual strengths — evolving toward either deep infrastructure ownership and ongoing platform administration, or toward client-facing technical roles including vCISO support, client onboarding, and technical advisory engagements with DIB and commercial clients. The right candidate will have both the technical depth to build the platform and the professional presence to engage with clients as the practice grows.


Candidates must have hands-on experience provisioning and administering Microsoft GCC High environments. Azure Commercial experience alone is insufficient — the build schedule has no capacity to absorb a GCC High learning curve.


 
Key Responsibilities
Infrastructure Build

  • Provision Atom’s GCC High Operations Tenant through an AOS-G authorized partner and build the parallel Azure Commercial Operations Tenant as isolated sovereign tracks
  • Establish Entra ID baseline across both tenants: admin account structure, security group naming conventions, and identity governance configuration
  • Deploy Azure Virtual Desktop host pool in Azure Government for SOC analyst and vCISO secure access
  • Configure Microsoft Lighthouse delegation framework across both tracks to support multi-client MSSP management
  • Implement FIDO2/phish-resistant MFA and Conditional Access policies across all administrative accounts on both tenants

Identity and Access Governance

  • Configure Privileged Identity Management (PIM) for all privileged roles across both tenants
  • Enroll all analyst devices, vCISO devices, and AVD session hosts into GCC High and Commercial Intune respectively
  • Document the separate Entra identity model (distinct UPNs per track) as a formal access control artifact

Security Toolchain Deployment

  • Stand up Microsoft Sentinel MSSP workspaces on both tracks with baseline analytics rules, alert routing, and cross-workspace KQL queries
  • Apply Defender XDR P2 baseline policy across the GCC High tenant
  • Deploy CrowdStrike Gov endpoint agents to CMMC client environments; deploy CrowdStrike Commercial Falcon for non-CMMC clients
  • Activate Azure Arc and Intune management on Atom operations devices
  • Verify track separation end-to-end and reflect findings in finalized network diagrams

Legacy Tool Migration

  • Build SharePoint GCC High site structure to receive runbooks, SOPs, and client documentation migrated from legacy documentation platforms
  • Configure Azure DevOps Boards (GCC High) as the ticketing and work management replacement
  • Provision Azure Key Vault and execute controlled credential migration with documented access policy review
  • Update Atom’s System Security Plan (SSP) to remove transitional tool entries upon retirement confirmation

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Proven IT

View company profile →