TechAxia LLC is hiring a Cybersecurity Compliance Analyst in Colorado Springs, CO (onsite) to help keep Microsoft 365 GCC High environments secure and audit-ready. This role combines recurring compliance execution, remediation documentation, and security operations support, with additional responsibility as a backup Microsoft 365 administrator for the GCC High managed services team. Salary range: USD 55,000 - 70,000 per year.
Responsibilities
- Run recurring cybersecurity maintenance checklists (weekly through annual) across TechAxia and client environments, documenting each task accurately.
- Monitor threat intelligence sources including CISA / US-CERT bulletins and Microsoft Defender Vulnerability Management; assess impact and open or track remediation tickets.
- Review audit logs, alerts, and incidents across Microsoft Sentinel, Microsoft Defender, and Intune, following established incident response procedures.
- Verify endpoint log ingestion and SIEM health, and reconcile device inventory in Entra ID against authorized hardware.
- Manage account lifecycle activities, including least-privilege reviews, disabling or deleting stale accounts, and maintaining up-to-date account-management records.
- Support CMMC / NIST SP 800-171 assessments, Change Advisory Board (CAB) meetings, and periodic reviews of policies, procedures, and risk assessments.
- Maintain accurate compliance documentation, including hardware/software inventories, System Security Plan, and POA&M inputs.
- Serve as a backup Microsoft 365 administrator for the GCC High managed services team.
Requirements
- Due to federal contract requirements, applicants must be U.S. citizens.
- 2+ years of experience in IT security operations, systems administration, or IT compliance.
- Hands-on Microsoft 365 administration experience with Entra ID / Azure AD, Microsoft Defender, and Intune / Endpoint Manager.
- Working familiarity with NIST SP 800-171 and/or CMMC.
- Exceptional attention to detail and disciplined documentation habits.
- Comfort working through ticketing or service-request systems and following written procedures.
- Self-directed, dependable, and able to manage recurring workload without close supervision.
Benefits
- Health insurance
- Dental insurance
- Vision insurance
- 401(k)
- Paid time off
- Professional development assistance
- Certification support for Microsoft and CMMC
Growth opportunity
Support professional development, including CMMC Certified Professional (CCP) training and certification. Over time, the role may expand to increased client-facing responsibilities, potentially including guiding clients through the path from initial gap assessment through certification and ongoing maintenance.
Preferred qualifications
- Experience with Microsoft 365 GCC High or GCC (government cloud).
- Microsoft Sentinel or other SIEM experience.
- Relevant certifications such as CompTIA Security+, SC-200, SC-300, MS-102, AZ-500, or CISSP.
- Prior experience at an MSP or MSSP.
- Eligible to obtain a U.S. security clearance.
- Familiarity with the Defense Industrial Base and DFARS/CMMC requirements.
Key technologies
Microsoft 365 GCC High, Microsoft 365 GCC, Microsoft Defender Vulnerability Management, Microsoft Sentinel, Microsoft Defender, Intune, Endpoint Manager, Entra ID, Azure AD, System Security Plan, POA&M, CISA / US-CERT bulletins, Change Advisory Board (CAB), NIST SP 800-171, and CMMC.