CMMC Level 2 Compliance Specialist

mindline Greater Seattle Area
Remote
Apply
AI Summary

Join Mindline as a part-time 1099 CMMC Level 2 Compliance Specialist to help Defense Industrial Base companies achieve and maintain CMMC Level 2 compliance in Microsoft 365 GCC High environments. Work directly with clients to implement security architectures and ensure compliance. US citizenship and experience with Microsoft security tools required.

Key Highlights
Implement CMMC Level 2 compliance in Microsoft 365 GCC High environments
Work directly with Defense Industrial Base clients
Design and implement defensible security architectures
Key Responsibilities
Implement the Microsoft security stack end-to-end
Design and implement defensible security architectures
Work directly with client IT teams
Document security architectures for C3PAO assessors and client IT teams
Technical Skills Required
Conditional Access policy design FIDO2/WHfB PIM identity governance Device compliance Open Intune Baseline deployment ASR rules GPO-to-Intune migration Sensitivity labels DLP policies auto-labeling compliance posture management SIEM deployment in Azure Government KQL alert rules continuous monitoring evidence Secure enclave architecture managed identities session host hardening
Benefits & Perks
1099 part-time engagement
Flexible hours
Project-based work
Direct access to a mature, documented methodology
Real client impact
Opportunity to work with a small, technical team
Nice to Have
Experience in GCC High or Azure Government
Familiarity with NIST SP 800-171 or CMMC Level 2 assessment requirements
Microsoft security certifications (SC-300, SC-400, AZ-500, MS-102)

Job Description


Mindline is looking for a US Citizen based in the Greater Seattle area to join our practice on a part-time 1099 basis, helping Defense Industrial Base companies achieve and maintain CMMC Level 2 compliance in Microsoft 365 GCC High environments.


What you'd be doing:

You'd work directly with DIB clients — manufacturers, defense contractors, engineering firms — implementing the Microsoft security stack end-to-end:

  • Entra ID — Conditional Access policy design, phishing-resistant authentication (FIDO2/WHfB), PIM, identity governance
  • Intune — Device compliance, Open Intune Baseline deployment, ASR rules, GPO-to-Intune migration
  • Purview — Sensitivity labels, DLP policies, auto-labeling, compliance posture management
  • Sentinel — SIEM deployment in Azure Government, KQL alert rules, continuous monitoring evidence
  • Azure Virtual Desktop — Secure enclave architecture, managed identities, session host hardening

This isn't checkbox compliance work. You'd be designing and implementing defensible security architectures — then documenting them clearly enough that a C3PAO assessor can validate the controls and a client IT team can operate them.


What we're looking for:

  • US Citizenship (required — GCC High tenant access)
  • Based in the Greater Seattle area — client work is fully remote, but I want someone who can periodically come to my home office in the area for whiteboarding, knowledge sharing, and working sessions. This isn't a daily commute — it's an occasional in-person collaboration with someone I trust to represent me to my clients well.
  • Hands-on experience with at least two of the five areas above — depth in one matters more than surface knowledge of all five
  • Comfort working directly with client IT teams who range from 5-person shops to 200-person departments
  • Reliability. You'd be taking on my clients. I need someone who delivers what they commit to, communicates proactively when things shift, and treats client deadlines like their own.


Nice to have, not required:

  • Experience in GCC High or Azure Government (vs. Commercial cloud)
  • Familiarity with NIST SP 800-171 or CMMC Level 2 assessment requirements
  • Any Microsoft security certifications (SC-300, SC-400, AZ-500, MS-102)


What we offer:

  • 1099 part-time engagement — flexible hours, project-based work
  • Direct access to a mature, documented methodology — you can see the depth of our approach at docs.mindline.com
  • Real client impact — the work you do directly enables companies to win and retain DoD contracts
  • A small, technical team where your judgment shapes the approach, not just the execution


Interested? DM me or comment below. Happy to have a conversation about fit before anything formal.


Similar Jobs

Explore other opportunities that match your interests

OT Security Engineer

Cyber Security
3h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

SPX Technologies

United State

Cybersecurity Analyst

Cyber Security
6h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Sentara Health

United State

Security Analyst

Cyber Security
6h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Entry level

sanfilippo itc

Mexico

Subscribe our newsletter

New Things Will Always Update Regularly