Azure Enclave Engineer

Zachary Piper
Springfield, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$170,000.0 - $210,000.0
Working hours
Regular working hours

Tech stack

Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Domain Name System (DNS) Identity and Access Management Virtual Private Networks (VPN) Network Security Networking Basics Windows PowerShell Azure Active Directory
+12 more
Zero Trust Network Access Runbook Systems Integration TCP/IP Virtual Machines Azure Powershell Information Technology Bicep 3-tier Architectures Firewall Services Module Terraform Azure Resource Manager

Job description

  • Design and architect enclave infrastructure to meet strict security and operational requirements.

  • Develop and maintain technical documentation, runbooks, SOPs, and security implementation guides for Tier 3 and Tier 2 teams.

  • Implement and enforce security controls and best practices within enclave environments.

  • Collaborate closely with networking, security, and compliance teams to enhance infrastructure security and resilience.

  • Conduct infrastructure and security risk assessments and recommend architectural, configuration, and operational improvements.

  • Provide strategic IT support and guidance for secure enclave operations.

  • Develop Azure architecture diagrams and maintain infrastructure-as-code artifacts.

Requirements

  • Active Top Secret clearance with SCI eligibility required.

  • Bachelor’s or Master’s degree in Cybersecurity, Information Technology, or a related field (preferred).

  • 8+ years of experience in enclave architecture, security engineering, or IT infrastructure management.

  • At least six months of hands-on experience managing production Azure services, including compute, networking, storage, and identity.

  • Strong experience with Azure subscriptions, resource groups, and Azure Active Directory (Entra ID).

  • Understanding of networking fundamentals including TCP/IP, DNS, VPNs, and firewall configurations.

  • Experience creating and managing virtual machines, containers, and Azure storage accounts.

  • Proficiency in PowerShell scripting and familiarity with Azure CLI for resource management.

  • 5+ years of technical writing experience supporting cloud-based or security-focused systems.

  • Working knowledge of Azure Resource Manager, Bicep, and/or Terraform templates.

  • Experience supporting hybrid or government cloud environments, including Azure Government and on-premises integrations.

  • Strong understanding of cloud security principles such as IAM, network security, encryption, and Zero Trust architectures.

  • Ability to clearly communicate complex security concepts to both technical teams and non-technical stakeholders, including leadership and auditors.

  • Required certifications: CompTIA Security+ and AZ-104 (Microsoft Azure Administrator), or a higher-level Microsoft certification in lieu of AZ-104. Candidates not currently certified must obtain required certifications within six months of hire.

Benefits & conditions

  • Salary range: $170,000 - $210,000 (depending on experience)

  • Full benefits including medical, dental, vision, 401(k), PTO, paid holidays, and sick leave as required by law

About the company

Zachary Piper Solutions is seeking an Azure Enclave Engineer to support a client in the government and defense technology sector by designing, securing, and maintaining highly controlled enclave environments. The Cloud/Systems Architect role is ideal for a senior infrastructure and security professional with deep experience in Azure, enclave architecture, and secure government or hybrid cloud environments. This position is located in Springfield, VA and is 100% on site.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

Videos

See all

Related articles

See all