> Markdown version of [/jobs/ext/1312127-senior-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/1312127-senior-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Engineer - **Company:** HYERTEK INC. - **Location:** Columbia, MD, United States - **Experience:** Expert - **Salary:** $140,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** .NET Framework, Audit Trail, Microsoft Azure, C Sharp (Programming Language), Cloud Computing, Cloud Engineering, Cyber Security, Databases, Continuous Integration, Data as a Services, Relational Databases, Federal Information Processing Standards (FIPS), Python (Programming Language), Key Management, Log Analysis, SQL Azure, Network Planning and Design, Role-Based Access Control, Zero Trust Network Access, Data Logging, Azure Data Factory, Cloud Monitoring, Firewalls (Computer Science), Backend, Infrastructure Automation Frameworks, Bicep, Microsoft Sentinel, Terraform, Key Vault, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9033929/senior-cloud-engineer ## About the Role 7+ years of hands-on cloud engineering experience across architecture, security hardening, and infrastructure automation. 5+ years hands-on Azure Government (or demonstrable IL4/IL5 delivery), including workloads meeting DoD Cloud SRG IL5 controls. Expert in Infrastructure as Code (Bicep/ARM or Terraform for Azure Gov) and CI/CD with embedded security scanning. Demonstrated DISA STIG hardening, NIST SP 800-53, and RMF/ATO artifact production - not just deploying resources, but making them accreditable. Strong Azure networking: VNets, private endpoints, firewalls, and disconnected/air-gapped deployment concepts. Identity engineering with Entra ID (Government) and CAC/PIV authentication. Production experience with managed data services (Azure SQL / relational databases, Key Vault, secure storage), including migrating relational workloads to managed Azure data tiers. Proficiency in a backend language for the service and automation layer - C# / .NET or strong Python; comfort re-platforming existing applications without regressing security invariants (PII masking, audit logging, role scoping). Working knowledge of zero-trust design, data-access/security controls (row-level and role-based), and encryption/key management. DoD 8570/8140 IAT Level II baseline - Security+ CE minimum (CISSP or CASP+ preferred for IL6/IL7). Excellent troubleshooting, documentation, and stakeholder communication skills. Comfort working independently across multiple concurrent engagements. Candidates must have and maintain an active TS/SCI clearance with the Department of Defense. ## Description Design and own Azure Government landing zones across development, test, and production tiers, treating the environment. Re-platform existing applications into scalable, resilient Azure designs - managed database, secrets in Key Vault, private networking - without loss of role-scoped behavior or audit fidelity. Build and maintain CI/CD pipelines with embedded security gates (SAST/DAST, dependency and container scanning, policy-as-code via Azure Policy) that operate in both connected and disconnected modes. Implement DISA STIG and CIS-hardened baselines, with automated application, drift detection, and continuous configuration-compliance evidence rather than point-in-time scans. Engineer controls to satisfy the DoD Cloud SRG (IL5/IL6), NIST SP 800-53 control families, and the RMF lifecycle; produce artifacts supporting ATO/cATO packages (SSP inputs, control implementation statements, POA&Ms). Implement data-protection controls for sensitive workloads - FIPS-validated encryption at rest and in transit, PII masking with logged least-privilege reveal, and enclave-appropriate data boundaries by CUI/classification marking. Design network isolation (VNets, private endpoints, NSGs, Azure Firewall) appropriate to each Impact Level, including disconnected/air-gapped topologies. Integrate CAC/PIV smartcard authentication and Entra ID (Government) with conditional access and PIM; map application roles to least-privilege RBAC and zero-trust segmentation. Partner with security engineers to apply hardening, de-identification, and governed-release controls; remediate findings and support audit and assessment activities. Design the reusable IaC baseline so environments promote cleanly. Instrument centralized logging and monitoring (Azure Monitor, Log Analytics, Microsoft Sentinel for Gov) with audit-log retention meeting DoD requirements. Document architectures, control implementations, and as-built records suitable for customer handoff. Support operational monitoring, incident root-cause analysis, backup/DR, and continuous improvement across managed environments. Stay current on the Azure Government ecosystem and bring relevant capabilities into delivery patterns. ## Related Videos - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Building Well-Architected applications](https://www.wearedevelopers.com/videos/691-building-well-architected-applications) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers)