Leonardo Helicopters is a multinational company, producing helicopters deployed in more than 150 countries across the globe. Leonardo Helicopters’ U.S. headquarters has been in Philadelphia since 1980 and is home to a world-class production facility, maintenance center, training academy and stellar engineering team.
We offer competitive compensation, exceptional benefits, 401k match, generous paid time off and much more.
Summary of Position
The Cyber Security Compliance Engineer is responsible for implementing, validating, and operationalizing cybersecurity controls required to achieve and maintain compliance with the NIST Cybersecurity Framework (CSF), NIST SP 800-171, and Cybersecurity Maturity Model Certification (CMMC) Level 2. Working in close partnership with the Cybersecurity team—which retains ownership of compliance policy, risk assessment, and audit governance—this role translates compliance requirements into technical solutions across Microsoft 365, Azure, endpoint management, identity services, networking, and on-premises infrastructure.
This is an execution role, not an advisory one. The Cybersecurity team defines what compliance looks like; this engineer builds and sustains it. The ideal candidate is a hands-on practitioner who can read a NIST control, understand what it requires technically, implement the solution, and produce the evidence to prove it works—all without requiring direction at each step.
Reporting directly to the Head of Digital Solutions, this Individual Contributor will be a high-visibility contributor whose output directly supports CMMC Level 2 certification staging and the organization’s long-term security posture hardening objectives across the US region.
Responsibilities
Microsoft Security Platform Ownership
- Administer and secure the Microsoft 365, Entra ID, Intune, Defender, and Purview environments as the primary technical owner of security configuration and policy enforcement
- Implement and maintain core identity and access controls
- Build and maintain Microsoft Purview data governance and protection controls
- Manage Intune device compliance policies, configuration profiles, and enrollment workflows across Windows endpoints
- Operate and tune the Microsoft Defender suite (Defender for Endpoint, Office 365, Identity, and Cloud Apps)—including alert triage, policy configuration, and integration with incident response processes
- Document CUI data flows through M365 and Azure services in support of System Security Plan (SSP) development
Infrastructure Security Engineering
- Implement and maintain security controls across the full on-premises and hybrid infrastructure stack
- Drive vulnerability remediation activities—prioritize, assign, track, and validate closure of findings from scan results, audit reports, and assessor reviews
- Implement CIS benchmark configurations and DISA STIG settings across applicable platforms and document deviations through formal change management
- Partner with the Manager of Security & Infrastructure on patching discipline, MDM lifecycle, and endpoint compliance enforcement
- Contribute to the network and infrastructure hardening roadmap, prioritized against NIST 800-171 control families SC (System & Communications Protection), AC (Access Control), AU (Audit & Accountability), and CM (Configuration Management)
NIST Control Implementation & Remediation
- Implement technical safeguards required by NIST SP 800-171 and CMMC Level 2 across all applicable control families
- Remediate security control gaps identified through internal assessments, audits, POA&M entries, and compliance reviews—owning technical resolution from identification through evidence-confirmed closure
- Partner with the Cybersecurity and Risk teams to translate NIST requirements into specific, operational controls with clear, auditable evidence paths
- Validate effectiveness of implemented controls through testing, configuration review, and evidence collection—producing artifacts sufficient for C3PAO assessor review
- Support SPRS (Supplier Performance Risk System) score improvement by systematically addressing scored deficiencies
- Contribute technical implementation details to System Security Plans (SSPs) in coordination with the Cybersecurity Compliance team
- Maintain a personal remediation queue aligned to the organizational Plan of Action & Milestones (POA&M), with regular status reporting to the Head of Digital Solutions
CMMC Technical Readiness
- Implement technical safeguards supporting CMMC Level 2 certification across all 110 practices derived from NIST SP 800-171
- Support SSP development by contributing architecture diagrams, data flow documentation, and system boundary definitions
- Produce and maintain technical evidence artifacts for each assessed practice—configuration exports, screenshots, audit logs, and policy documentation
- Validate security control effectiveness through technical testing prior to formal C3PAO assessment engagement
- Participate in pre-assessment walkthroughs and respond to assessor technical inquiries with demonstrated, working controls
- Coordinate with the Cybersecurity Compliance team on CUI environment scoping, boundary documentation, and formal assessment scheduling
- Sustain CMMC technical readiness posture post-certification through ongoing monitoring, quarterly self-assessment, and control validation
Qualifications for Position
A. Education
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related discipline required
- An equivalent combination of formal education and demonstrated, hands-on technical experience will be considered in lieu of degree.
B. Experience
- 3–6 years of progressive experience in cybersecurity engineering, security administration, or infrastructure security roles
- Demonstrated hands-on experience implementing NIST SP 800-171 controls in enterprise environments—not solely assessing or documenting them
- Proven experience securing Microsoft 365 and Azure environments at a technical configuration level, including Entra ID, Intune, Purview, and the Defender suite
- Practical experience implementing controls supporting CMMC Level 2 certification or equivalent federal compliance requirements (DFARS, FedRAMP, FISMA)
- Track record of remediating audit findings and compliance gaps through direct technical implementation—not documentation management alone
- Hands-on experience with Windows Server hardening, Active Directory security, endpoint protection, and infrastructure vulnerability management
- Ability to produce technical evidence artifacts—configuration exports, audit logs, test results, and screenshots—suitable for formal assessor review
- Experience interfacing across multiple business functions (IT, Legal, Procurement, Operations) to gather evidence and drive compliance outcomes