Multi Cloud Engineer Architect SME

Leidos, Inc.
Fort Belvoir, VA, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$131,300.0 - $237,350.0
Working hours
Regular working hours

Tech stack

Active Directory Amazon Web Services Microsoft Azure Cloud Computing Cloud Engineering Cyber Security Federated Identity Management Identity and Access Management Information Management OpenID Role-Based Access Control Azure Active Directory
+15 more
Zero Trust Network Access Security Assertion Markup Language (SAML) Systems Integration Multi-Cloud Azure Powershell HybridCloud Cloudformation Containerization Kubernetes Infrastructure Automation Frameworks Information Technology Bicep Cloud Migration Terraform Devsecops

Job description

Leidos Digital Modernization is seeking an experienced Multi Cloud Engineer Architect SME to support large-scale migration and operations on a large, high-profile DOD contract. The I3TS program provides enterprise-wide IT support to enable DTRA’s Information Management & Technology Directorate (ITD) to consolidate, modernize, and continuously innovate the delivery of IT services and mission capabilities to DTRA’s internal and external mission partners operating in CONUS and OCONUS locations.

The Multi-Cloud Engineer/Architect SME will lead the design and deployment of secure, scalable, and compliant cloud environments spanning Microsoft Azure, AWS, and hybrid on-premises systems.. This role will be responsible for tech requirement definition, feasibility studies, pilot projects and implementations plans, as well as diagnosing and troubleshooting outages, monitoring networks, infrastructure and systems, and proving proactive mitigation strategies.

This role is part of a highly skilled technical team responsible for designing and deploying secure, scalable, and compliant hybrid- and multi-cloud architectures that enable mission success across complex defense environments.

The ideal candidate will bring deep expertise in cloud architecture, identity and access management (IAM), zero-trust frameworks, and multi-cloud governance, with proven experience implementing solutions within DoD IL4/IL5-accredited environments. This role directly supports the modernization goals DTRA’s mission-critical cloud transformation efforts. The selected candidate will design and implement Zero Trust-aligned, IL4/IL5-accredited solutions integrating Azure, AWS, and on-premises systems in accordance with DoD cybersecurity requirements., * Architect, design, and implement multi-cloud (Azure, AWS, hybrid) solutions that meet DoD mission objectives and cybersecurity requirements.

  • Lead the configuration, integration, and optimization of Microsoft Entra ID (Azure AD) and AWS Identity Center (formerly AWS SSO) for federated identity and centralized access control.
  • Develop and enforce IAM governance, Zero Trust Architecture (ZTA) principles, and role-based access controls (RBAC) across cloud and on-premises systems.
  • Design and implement cross-cloud identity federation and SSO solutions using SAML 2.0, OIDC, and SCIM protocols.
  • Integrate Azure Policy, AWS Service Control Policies (SCPs), and Terraform/Bicep automation for compliance enforcement and least-privilege security.
  • Collaborate with cybersecurity and compliance teams to align architectures with DISA STIGs, DoD Cloud Computing SRG (IL4/IL5), NIST 800-53, and FedRAMP High baselines.
  • Provide architectural leadership for hybrid cloud connectivity, data protection, and cross-domain security.
  • Guide cloud adoption and migration strategies that enhance operational agility while maintaining security posture.
  • Create and maintain architectural documentation, diagrams, and compliance traceability artifacts. Develop and maintain architectural documentation, identity diagrams, and compliance traceability.
  • Stay current on Azure and multi-cloud capabilities relevant to DoD, federal, and intelligence mission systems.

Requirements

  • Active DoD Top Secret clearance with SCI Eligibility.
  • DoD 8570 IAT Level II certification.
  • BS degree and 12+ years of prior relevant experience or a Masters degree with 10+ years of prior relevant experience, additional years of experience may be considered in lieu of a degree.
  • 7+ years of experience designing and implementing secure Azure-based solutions in enterprise or government environments.
  • Active AWS Certified Solutions Architect - Professional and/or Microsoft Certified: Azure Solutions Architect Expert certification and or AWS Certified Cloud Practitioner - Foundational - Amazon Web Services (AWS).
  • Proven expertise with IAM, federated identity, and multi-cloud access management.
  • Demonstrated experience integrating Microsoft Entra ID (Azure AD), AWS Identity Center, and on-premises Active Directory.
  • Strong understanding of federated identity, SAML/OIDC protocols, and cross-cloud authentication mechanisms.
  • Hands-on experience with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, and Bicep.
  • Familiarity with DoD cybersecurity frameworks including DISA STIGs, CMMC, and Zero Trust Architecture guidance.
  • Strong communication skills and ability to collaborate effectively with government stakeholders, security teams, and engineering personnel.
  • Familiarity with Azure Government (DoD), FedRAMP, and DISA STIG compliance frameworks.
  • Hands-on experience with Terraform, Bicep, Azure CLI, and CI/CD automation.
  • Must be able to work as part of a team to troubleshoot and resolve complex issues.
  • Excellent written and verbal communication skills. This includes drafting SOPs, architectural plans and drawings, and technical documentation as well as communication with senior program and customer leadership.

Preferred Qualifications:

  • Experience with Zero Trust implementation in DoD or federal mission systems.
  • Familiarity with AWS GovCloud (US), Azure Government, and hybrid integrations.
  • Knowledge of multi-cloud networking, enclave isolation, and cross-domain solution (CDS) patterns.
  • Experience with Kubernetes (EKS/AKS), containerized workloads, and DevSecOps pipelines.
  • Advanced certifications such as CISSP, CCSP, or Microsoft Cybersecurity Architect Expert.
  • Prior experience supporting DISA, USCYBERCOM, or similar Joint Cloud modernization programs (JADC2, DEOS).
  • Experience providing technical leadership and oversight of teams of junior, intermediate, and senior Engineers.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

2:57 min

Securing sensitive defense infrastructure with dual-vendor cloud strategies

Boris Hecker Boris Hecker +3 · WWC 2025

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all