Home › Companies › Xcimer › Cybersecurity & Compliance Administrator
Cybersecurity & Compliance Administrator
Xcimer · Denver, CO · On Site · Active · $140,000–$175,000 / year · Lever
Job facts
| Field | Value |
|---|---|
| Company | Xcimer |
| Title | Cybersecurity & Compliance Administrator |
| Normalized title | - |
| Department / team | Operations / IT |
| Location | Denver, CO, United States |
| Work model | On Site |
| Employment type | Full Time |
| Salary | $140,000–$175,000 / year |
| Status | active |
| ATS provider | Lever |
| Posted / first seen | 2026-05-19 / 2026-05-29 |
| Changed / last seen | 2026-06-03 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Xcimer. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Lever. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Denver. | Open |
| Department jobs | Active postings in Operations. | Open |
| Work model jobs | Active On Site postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Xcimer |
| Source | 34ba15eb-dcf2-4de1-ba3f-96f8793ede64 |
| ATS provider | Lever |
Description
Responsibilities
Microsoft Purview Administration (Compliance & Data Governance)
Configure and manage Purview capabilities to support compliance objectives, including data classification and labeling, data loss prevention (DLP), retention and deletion policies, eDiscovery workflows, and compliance reporting.
Develop and maintain Purview‑derived compliance artifacts and evidence outputs to support assessments, audits, due diligence, and continuous monitoring aligned to CMMC 2.0 Level 2 and NIST SP 800‑171.
Define and operate data retention and deletion procedures, integrating with Purview retention controls where appropriate
Microsoft Defender Administration (Threat Protection & Security Operations)
Configure, tune, and operate Microsoft Defender security controls across identity, endpoints, email/collaboration, and cloud applications, consistent with licensing and compliance scope.
Monitor alerts, investigate suspicious activity, and drive remediation actions; reducing noise through continuous tuning and improvements.
Establish and maintain detection and response playbooks, including alert triage, escalation paths, documentation requirements, and post-incident follow-up.
Incident Response & Threat Prevention
Own and maintain the Security Incident Response Plan, including severity definitions, roles and responsibilities, evidence handling, escalation paths, and internal/external communication procedures.
Lead security incident response from identification through containment, eradication, recovery, and lessons learned.
Perform root-cause analysis and coordinate corrective actions with IT administrative staff and relevant stakeholders.
Proactively implement threat prevention measures: hardening, secure configuration baselines, conditional access/MFA enforcement support, and policy-driven risk reduction.
Maintain an incident register covering actual, attempted, and suspected security incidents (including phishing attempts), investigations performed, and outcomes.
Compliance Enablement (CMMC L2 / NIST Controls)
Maintain the System Security Plan (SSP) and Plan of Actions & Milestones (POA&M) for in‑scope systems, ensuring clear implementation statements, ownership, and evidence references.
Support definition and maintenance of the CUI boundary, including systems, users, endpoints, networks, and data flows.
Translate CMMC and NIST control requirements into concrete configurations, procedures, and ongoing monitoring activities across Microsoft 365, on‑prem infrastructure, and restricted or air‑gapped environments.
Collect, organize, and maintain audit‑ready evidence to support internal assessments, customer diligence, and third‑party assessments.
Define and maintain a centralized logging strategy (SIEM) spanning cloud and on‑prem environments, including ingestion of logs from identity systems, endpoints, email, servers, firewalls, VPNs, and IDS/IPS platforms.
On‑Prem & Air‑Gapped Security
Establish and operate secure data transfer procedures for air‑gapped and restricted environments, including removable media governance, integrity validation, malware scanning, and chain‑of‑custody documentation.
Partner with Network Architecture to design and maintain secure monitoring architectures for restricted and air‑gapped environments, including TAP/SPAN placement, IDS deployment, and segmentation alignment with OT/ICS security best practices
Security Engineering & Integrations
Support integrations between cloud-based services and the Microsoft security/compliance ecosystem (e.g., log sources, alerting, ticketing workflows, SSO/identity integrations).
Contribute to automation where appropriate (e.g., scheduled scripts, workflows, or playbook-style response actions).
Cross-Functional Collaboration & Communication
Work closely with IT and engineering teams to ensure smooth operations and secure-by-default practices.
Document, categorize, and prioritize security issues to ensure efficient escalation and resolution.
Enforce approved security, compliance, and privacy policies and contribute to ongoing policy development and improvement.
Collaborate with Network Architecture on secure network design, segmentation strategy, and enforcement controls including firewall policy, IDS/IPS, and Zero Trust network principles.
Collaborate with Network Architecture on secure network design, segmentation strategy, and enforcement controls including firewall policy, IDS/IPS, and Zero Trust network principles
Implement privacy impact assessments (PIAs) for new systems or processes involving personal data.
Partner with Legal and HR to document the company’s GDPR and CCPA applicability position, including the basis where such laws do not apply.
Support inclusion of appropriate data privacy and security terms in third‑party contracts and service agreements.
Qualifications
Education: Bachelor’s degree (or equivalent practical experience) in information technology, cybersecurity, information systems, or a related field.
Experienece: 7+ years of experience in security administration, security operations, compliance operations, or adjacent IT roles with direct security responsibility.
Demonstrated hands‑on experience administering Microsoft 365 security and compliance services, including Microsoft Purview and Microsoft Defender in an enterprise environment.
Proven background in security incident response, investigation, and documentation in regulated or high‑risk environments.
Working knowledge of system security best practices, access control, secure configuration, and audit logging.
Strong written and verbal communication skills; able to translate technical security risk into clear, actionable steps and documentation.
Comfortable operating as a self‑directed individual contributor in a fast‑paced and evolving environment.
Excellent technical and interpersonal communication skills; able to translate security risk into actionable steps.
Comfortable in a fast-paced, dynamic, and ambiguous environment.
Positive attitude, strong ownership mindset, strong professional judgement and ability to earn trust and maintain professional relationships.
Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee of granted asylum
Desired
Direct experience implementing or operating CMMC Level 2 and/or NIST SP 800‑171 controls, including evidence collection and assessment preparation.
Experience with centralized logging or SIEM platforms and detection playbook development.
Experience with cloud-based service integrations (webhooks/REST APIs) and security-relevant automation.
Experience with security-related scripting/automation practices and languages (Python, JavaScript, Ansible, SOAR‑style workflows etc.).
Familiarity with hybrid cloud and on‑prem infrastructure in regulated environments, including air‑gapped networks.
Full job record
| Job ID | 6e81b078b5e185f9e61cf653d6d23121fb76b08b |
| Org ID | 92a4410e-e89a-46fd-b77b-9d85b9bbfdaf |
| Source ID | 34ba15eb-dcf2-4de1-ba3f-96f8793ede64 |
| Board ID | 34ba15eb-dcf2-4de1-ba3f-96f8793ede64 |
| Provider | lever |
| Provider Job Key | 12a8808f-853e-4ca4-a2cf-d9400345c47c |
| Title | Cybersecurity & Compliance Administrator |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Denver, CO |
| Department | Operations |
| Team | IT |
| Employment Type | Full-Time |
| Workplace Type | on_site |
| Remote Policy | — |
| Country | United States |
| Region | CO |
| City | Denver |
| Salary Raw | USD 140000-175000 per-year-salary |
| Salary Min | 140,000 |
| Salary Max | 175,000 |
| Salary Currency | USD |
| Salary Period | year |
| Source URL | https://jobs.lever.co/xcimer/12a8808f-853e-4ca4-a2cf-d9400345c47c |
| Apply URL | https://jobs.lever.co/xcimer/12a8808f-853e-4ca4-a2cf-d9400345c47c/apply |
| First Seen At | 2026-05-29 07:08:24Z |
| Last Seen At | 2026-06-06 19:52:20Z |
| Last Checked At | 2026-06-06 19:52:20Z |
| Last Changed At | 2026-06-03 12:24:48Z |
| Inactive At | — |
| Source Posted At | 2026-05-19 23:32:12Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=lever/board=xcimer/date=2026-06-06/2026-06-06T19-52-19-180Z-31cc789cd738c8b1fb8a28e511fc7c301eff24e05df730895eaae921bbdbfe33.json |
Event Fields
{
"content_hash": "a74794b4bc711fedefd5161ae6bc9eb4df0f2ca238e3509b2d8fae99908b9722",
"source_hash": "4cdb55451c900c8398db70cbe221fe6d1a7198c725f01b19f5be0ba445d9fade",
"last_changed_at": "2026-06-03T12:24:48.555Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Denver, CO",
"city": "Denver",
"region": "CO",
"country": "United States",
"is_remote": false,
"confidence": 0.9
},
"salary_max": 175000,
"salary_min": 140000,
"inferred_at": "2026-06-06T19:52:20.316Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "Denver, CO",
"city": "Denver",
"region": "CO",
"country": "United States",
"is_remote": false,
"confidence": 0.9
},
"countries": [
"United States"
]
},
"remote_policy": null,
"salary_period": "year",
"workplace_type": "on_site",
"salary_currency": "USD"
}Extensions
{}Native Structured
{
"lists": [
{
"text": "Responsibilities",
"content": "<div>\n<p><u>Microsoft Purview Administration (Compliance & Data Governance)</u></p>\n\n<li>Configure and manage Purview capabilities to support compliance objectives, including data classification and labeling, data loss prevention (DLP), retention and deletion policies, eDiscovery workflows, and compliance reporting.</li>\n<li>Develop and maintain Purview‑derived compliance artifacts and evidence outputs to support assessments, audits, due diligence, and continuous monitoring aligned to CMMC 2.0 Level 2 and NIST SP 800‑171.</li>\n<li>Define and operate data retention and deletion procedures, integrating with Purview retention controls where appropriate</li>\n\n<p><u>Microsoft Defender Administration (Threat Protection & Security Operations)</u></p>\n\n<li>Configure, tune, and operate Microsoft Defender security controls across identity, endpoints, email/collaboration, and cloud applications, consistent with licensing and compliance scope.</li>\n<li>Monitor alerts, investigate suspicious activity, and drive remediation actions; reducing noise through continuous tuning and improvements.</li>\n<li>Establish and maintain detection and response playbooks, including alert triage, escalation paths, documentation requirements, and post-incident follow-up.</li>\n\n<p><u>Incident Response & Threat Prevention</u></p>\n\n<li>Own and maintain the Security Incident Response Plan, including severity definitions, roles and responsibilities, evidence handling, escalation paths, and internal/external communication procedures.</li>\n<li>Lead security incident response from identification through containment, eradication, recovery, and lessons learned.</li>\n<li>Perform root-cause analysis and coordinate corrective actions with IT administrative staff and relevant stakeholders.</li>\n<li>Proactively implement threat prevention measures: hardening, secure configuration baselines, conditional access/MFA enforcement support, and policy-driven risk reduction.</li>\n<li>Maintain an incident register covering actual, attempted, and suspected security incidents (including phishing attempts), investigations performed, and outcomes.</li>\n\n<p><u>Compliance Enablement (CMMC L2 / NIST Controls)</u></p>\n\n<li>Maintain the System Security Plan (SSP) and Plan of Actions & Milestones (POA&M) for in‑scope systems, ensuring clear implementation statements, ownership, and evidence references.</li>\n<li>Support definition and maintenance of the CUI boundary, including systems, users, endpoints, networks, and data flows.</li>\n<li>Translate CMMC and NIST control requirements into concrete configurations, procedures, and ongoing monitoring activities across Microsoft 365, on‑prem infrastructure, and restricted or air‑gapped environments.</li>\n<li>Collect, organize, and maintain audit‑ready evidence to support internal assessments, customer diligence, and third‑party assessments.</li>\n<li>Define and maintain a centralized logging strategy (SIEM) spanning cloud and on‑prem environments, including ingestion of logs from identity systems, endpoints, email, servers, firewalls, VPNs, and IDS/IPS platforms.</li>\n\n<p><u>On‑Prem & Air‑Gapped Security</u></p>\n\n<li>Establish and operate secure data transfer procedures for air‑gapped and restricted environments, including removable media governance, integrity validation, malware scanning, and chain‑of‑custody documentation.</li>\n<li>Partner with Network Architecture to design and maintain secure monitoring architectures for restricted and air‑gapped environments, including TAP/SPAN placement, IDS deployment, and segmentation alignment with OT/ICS security best practices</li>\n\n<p><u>Security Engineering & Integrations</u></p>\n\n<li>Support integrations between cloud-based services and the Microsoft security/compliance ecosystem (e.g., log sources, alerting, ticketing workflows, SSO/identity integrations).</li>\n<li>Contribute to automation where appropriate (e.g., scheduled scripts, workflows, or playbook-style response actions).</li>\n\n<p><u>Cross-Functional Collaboration & Communication</u></p>\n\n<li>Work closely with IT and engineering teams to ensure smooth operations and secure-by-default practices.</li>\n<li>Document, categorize, and prioritize security issues to ensure efficient escalation and resolution.</li>\n<li>Enforce approved security, compliance, and privacy policies and contribute to ongoing policy development and improvement.</li>\n<li>Collaborate with Network Architecture on secure network design, segmentation strategy, and enforcement controls including firewall policy, IDS/IPS, and Zero Trust network principles.</li>\n<li>Collaborate with Network Architecture on secure network design, segmentation strategy, and enforcement controls including firewall policy, IDS/IPS, and Zero Trust network principles</li>\n<li>Implement privacy impact assessments (PIAs) for new systems or processes involving personal data.</li>\n<li>Partner with Legal and HR to document the company’s GDPR and CCPA applicability position, including the basis where such laws do not apply. </li>\n<li>Support inclusion of appropriate data privacy and security terms in third‑party contracts and service agreements.</li>\n\n</div>"
},
{
"text": "Qualifications",
"content": "<div>\n\n<li><strong>Education: </strong>Bachelor’s degree (or equivalent practical experience) in information technology, cybersecurity, information systems, or a related field. </li>\n<li><strong>Experienece: </strong>7+ years of experience in security administration, security operations, compliance operations, or adjacent IT roles with direct security responsibility.</li>\n<li>Demonstrated hands‑on experience administering Microsoft 365 security and compliance services, including Microsoft Purview and Microsoft Defender in an enterprise environment. </li>\n<li>Proven background in security incident response, investigation, and documentation in regulated or high‑risk environments. </li>\n<li>Working knowledge of system security best practices, access control, secure configuration, and audit logging. </li>\n<li>Strong written and verbal communication skills; able to translate technical security risk into clear, actionable steps and documentation. </li>\n<li>Comfortable operating as a self‑directed individual contributor in a fast‑paced and evolving environment.</li>\n<li>Excellent technical and interpersonal communication skills; able to translate security risk into actionable steps.</li>\n<li>Comfortable in a fast-paced, dynamic, and ambiguous environment.</li>\n<li>Positive attitude, strong ownership mindset, strong professional judgement and ability to earn trust and maintain professional relationships.</li>\n<li>Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee of granted asylum </li>\n\n</div>"
},
{
"text": "Desired",
"content": "<div>\n\n<li>Direct experience implementing or operating CMMC Level 2 and/or NIST SP 800‑171 controls, including evidence collection and assessment preparation. </li>\n<li>Experience with centralized logging or SIEM platforms and detection playbook development. </li>\n<li>Experience with cloud-based service integrations (webhooks/REST APIs) and security-relevant automation.</li>\n<li>Experience with security-related scripting/automation practices and languages (Python, JavaScript, Ansible, SOAR‑style workflows etc.).</li>\n<li>Familiarity with hybrid cloud and on‑prem infrastructure in regulated environments, including air‑gapped networks.</li>\n\n</div>"
}
],
"country": "US",
"createdAt": 1779233532622,
"updatedAt": null,
"categories": {
"team": "IT",
"location": "Denver, CO",
"commitment": "Full-Time",
"department": "Operations",
"allLocations": [
"Denver, CO"
]
},
"salaryRange": {
"max": 175000,
"min": 140000,
"currency": "USD",
"interval": "per-year-salary"
},
"workplaceType": "onsite"
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/6e81b078b5e185f9e61cf653d6d23121fb76b08b?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/92a4410e-e89a-46fd-b77b-9d85b9bbfdafJSONGET https://api.bluedoor.sh/job-postings/v1/sources/34ba15eb-dcf2-4de1-ba3f-96f8793ede64JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/6e81b078b5e185f9e61cf653d6d23121fb76b08b/eventsJSON