Cloud Platform Engineer

ICF Incorporated, L.L.C.
Annapolis, MD, United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$108,006.0 - $183,610.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cloud Engineering Desktop Virtualization Domain Name System (DNS) Github IP Addressing Virtual Private Networks (VPN) Network Security Virtual Desktops
+14 more
Remote Access Technology Zero Trust Network Access Security Information and Event Management Policy as Code Data Logging Google Cloud Cloud Platform System Multi-Cloud Cloudformation Bicep CIS Benchmarks Terraform Webhooks Devsecops

Job description

ICF is seeking a Cloud Platform Engineer to deploy, configure, and maintain cloud infrastructure for a federal technology program. Reporting to the Cloud / Enterprise Architecture Lead, this role is responsible for building and operating the multi-cloud landing zone environment using infrastructure-as-code and DevSecOps practices. Where the EA Lead sets architecture standards and policy, this role executes and maintains them in production.

The ideal candidate is a hands-on cloud infrastructure engineer who writes automation before clicking buttons and treats configuration as code. The right candidate has deployed and operated cloud landing zones in federal environments and is comfortable working across Azure, AWS, and GCP with consistent tooling and governance discipline.

Job Location: This is a remote-friendly position with occasional onsite requirements in the Washington, DC Metro area.

This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections.

What You’ll Be Doing

  • Deploy and manage cloud landing zone architectures across Azure, AWS, and Google Cloud Platform using repeatable, automated provisioning with identity-first controls, guardrails, network security, and policy enforcement.
  • Implement infrastructure and policy as code usingIaCtemplates, GitHub Actions, and CI/CD pipelines so environments can be created, updated, and audited consistently and without manual intervention.
  • Build andmaintainsystem integrations using APIs, SDKs, webhooks, and event streams, with propersecretsmanagement, least-privilege scoping, error handling, and logging.
  • Deploy and manage Azure Virtual Desktop for remote access scenarios and specific user personas.
  • Manage DNS-as-code for all agency platforms and services, including certificates and related configurations.
  • Integrate platform logs, alerts, and risk signals into central monitoring tools, and use automation to flag misconfigurations, risky behavior, and suspicious activity.
  • Perform quarterly reviews of cloud environment configurations against security baselines and compliance requirements, using compliance-as-code tooling where available.
  • Coordinate with identity, device, and cybersecurity teams to ensure cloud access policies, device compliance rules, and conditional access work together as part of a consistent Zero Trust model.
  • Maintain documentation of cloud architectures, configuration baselines, runbooks, and operational procedures so others can safelyoperateand extend the environment.
  • Resolve complex cloud platform issues escalated from operations and service desk teams.

Requirements

  • Bachelor’s degree or equivalent
  • 5+ years of experience in cloud engineering or platform operations
  • 3+ years deploying and managing cloud landing zones in Azure, AWS, or GCP in production environments
  • 2+ years implementing infrastructure as code using tools such as Terraform, Bicep, CloudFormation, or equivalent
  • 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies
  • U.S. Citizenship required due to federal contract requirements
  • Ability to obtain andmaintaina Public Trust background investigation
  • Candidate mustresidein the US,be authorized towork in the US, and work must be performed in the US

Preferred Qualifications

  • Experience managing Azure Virtual Desktop or equivalent virtual desktop infrastructure
  • Familiarity with NIST 800-53, FedRAMP, CIS benchmarks, and CISA Zero Trust guidelines as they apply to cloud infrastructure
  • Experience integrating platform telemetry with SIEM or SOAR tools for automated alerting and remediation
  • Relevant certifications such as Microsoft Azure Administrator, AWSSysOpsAdministrator, or Google Cloud Professional Cloud Engineer
  • Experience withDevSecOpsdelivery practices including automated security testing in CI/CD pipelines

About the company

ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.

We can only solve the world’s toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO (https://www.icf.com/legal/equal-employment-opportunity) policy.

We will consider for employment qualified applicants with arrest and conviction records., At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:28 min

Synchronizing database webhook triggers with pipeline webhooks

Bobur Umurzokov · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

2:30 min

Consumer challenges in ingesting and verifying webhooks

Phil Leggetter Phil Leggetter · WWC Europe 2026

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all