Microsoft Azure Senior Cloud Architect

HYERTEK INC.
Fort Meade, MD, United States
4 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$145,000.0 - $186,500.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Audit Trail Microsoft Azure Backup Devices Command-Line Interface Cloud Computing Cloud Computing Security Cloud Engineering Code Generation Cyber Security Databases Disaster Recovery
+32 more
Domain Name System (DNS) Identity and Access Management Subnetting Python (Programming Language) Key Management Network Security Linux System Administration Log Analysis Routing Network Segmentation Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services SAP (Applications) Virtual Machines Software Vulnerability Management Data Logging Scripting Load Balancing Microsoft Power Automate Azure Powershell Firewalls (Computer Science) AI Platforms Infrastructure Automation Frameworks Bicep Microsoft Sentinel Azure AKS CIS Benchmarks Terraform Devsecops Azure Resource Manager

Job description

HyerTek is seeking a Microsoft Azure Senior Cloud Engineer to design, build, implement, secure, and operate Azure environments supporting DoW Impact Levels 5, 6, and 7 or equivalent classification levels and other accredited environments as required by the customer.

A successful candidate will own the solution end to end, working directly with cybersecurity professionals, application teams, and Government stakeholders to translate mission requirements and security controls into sounds technical designs and production-ready solutions. This role uses AI-assisted development tools and code generation to accelerate infrastructure-as-code, control documentation, and runbooks, while applying sounds engineering judgment to review and validate AI-generated output before it is deployed to an accredited environment.

This is a hybrid position. Candidates must reside in the Washington, DC, metropolitan area. Some work will be performed at customer facilities, including accredited Secure Areas and SCIFs at Fort Meade., * Build, configure, and maintain secure Microsoft Azure environments supporting IL5, IL6, and IL7, or equivalent workloads in accordance with approved architectures, customer and contract requirements, and applicable security controls and regulations.

  • Implement cloud landing zones, subscriptions, resource organization, network boundaries, identity controls, logging, and governance policies.
  • Deploy and manage Azure infrastructure using Terraform, Bicep, ARM templates, or comparable Infrastructure as Code tools.
  • Configure Azure networking, including virtual networks, subnets, routing, private endpoints, DNS, firewalls, load balancers, network security groups, and hybrid connectivity.
  • Implement identity and access controls using Microsoft Entra ID, role-based access control, managed identities, privileged-access controls, and Azure Key Vault.
  • Deploy and operate Azure compute, storage, database, and container services in accordance with approved architectures and security requirements.
  • Apply Azure Policy, security baselines, DISA STIGs, encryption requirements, and configuration standards in partnership with cybersecurity teams.
  • Implement, validate, and maintain applicable DISA STIGs and security configuration baselines, including remediation of configuration findings and support for automated compliance validation.
  • Implement monitoring, alerting, audit logging, and operational dashboards using Azure Monitor, Log Analytics, Defender for Cloud, and Microsoft Sentinel, as applicable to the environment.
  • Support deployment and operations in disconnected, air-gapped, or classified environments where public-cloud services and external dependencies may be limited.
  • Troubleshoot cloud infrastructure, networking, identity, performance, and configuration issues across development, test, and production environments.
  • Support backup, recovery, continuity-of-operations, and disaster-recovery planning and testing.
  • Produce infrastructure diagrams, configuration documentation, operating procedures, and customer-handoff materials.
  • Provide technical evidence and configuration details in support of RMF authorization, assessment, and continuous-monitoring activities.
  • Collaborate with cybersecurity and DevSecOps teams to remediate vulnerabilities, security findings, configuration deviations, and compliance deficiencies.
  • Support security assessments, authorization activities, audits, and customer reviews by providing accurate infrastructure configurations, technical documentation, and required evidence.

Requirements

  • 5+ years of hands-on cloud or infrastructure engineering experience, including responsibility for production environments.
  • Strong experience designing, deploying, and operating solutions in Microsoft Azure.
  • Hands-on experience with Azure Government or another regulated government-cloud environment.
  • Strong knowledge of Azure networking, identity and access management, compute, storage, security, monitoring, and governance.
  • Proficiency with Infrastructure as Code using Terraform, Bicep, ARM templates, or a comparable technology.
  • Experience implementing secure cloud landing zones, subscription structures, network segmentation, access controls, and centralized logging.
  • Experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure Policy, Azure Monitor, and Log Analytics.
  • Working knowledge of Windows and Linux administration, including command-line troubleshooting and system hardening.
  • Experience using PowerShell, Azure CLI, Python, or another scripting language to automate cloud operations.
  • Understanding of cloud security principles, least-privilege access, encryption, vulnerability management, backup, and disaster recovery.
  • Familiarity with the DoW Cloud Computing SRG, RMF, NIST SP 800-53, and applicable DISA STIGs.
  • Demonstrated experience applying security hardening requirements, DISA STIGs, or comparable federal security configuration baselines in cloud or infrastructure environments.
  • Strong proficiency in AI platforms including Open AI, Claude, Gemini, and Microsoft CoPilot.
  • Strong troubleshooting, documentation, and stakeholder communication skills.
  • Ability to work independently and collaboratively across multiple concurrent engagements and manage priorities.
  • DoW 8140 aligned IAT Level II certification, with Security+ CE or an approved equivalent.
  • Active Top Secret security clearance required. Candidates must be eligible to obtain and maintain any additional customer-specific access requirements associated with their assigned work., * Active TS/SCI security clearance.
  • Direct experience with Azure Government Secret, Top Secret, or other classified cloud environment.
  • Experience implementing Azure environments supporting DoW IL5, 6, or 7 (or equivalent classifications), ICD 503, JSIG, or SAP workloads.
  • Azure networking experience, including VNets, subnets, private endpoints, NSGs, Aure Firewall, routing, DNS, networking segmentation, disconnected operations, and/or air-gapped deployments on classified networks or cross-domain solutions.
  • Experience with Azure Landing Zones, Secure Azure Computing Architecture, or DoW Secure Cloud
  • Computing Architecture requirements.
  • Experience with hybrid connectivity, ExpressRoute, network virtual appliances, boundary protection, or enterprise DNS.
  • Experience with Azure Kubernetes Service, container registries, virtual machines, or platform services in restricted environments.
  • Experience automating security baselines, STIG validation, configuration compliance, or continuous-monitoring evidence.
  • Experience supporting RMF authorization, assessment, remediation, or continuous ATO activities.
  • Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate, or Azure Network Engineer Associate.
  • CISSP, CASP+, or another advanced security certification.

Benefits & conditions

HyerTek offers a comprehensive benefits package, including:

  • Medical, dental, and vision insurance
  • 401(k) with employer contribution
  • Paid time off (PTO) and company holidays
  • Professional development and certification support
  • Employee assistance program (EAP)
  • Life and disability insurance

Clearance & Work Authorization This position requires U.S. citizenship and an active TS security clearance with the Department of War. The candidate must be able to obtain and maintain SCI eligibility; an active TS/SCI clearance is strongly preferred. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future. HyerTek will not sponsor applicants for a U.S. work visa status for this opportunity.

Salary Range The anticipated salary range for this position is $145,000 - $186,500 annually. Final compensation will be based on relevant experience, technical qualifications, certifications, clearance status, and contract requirements.

Equal Employment Opportunity (EEO) HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other status protected by applicable federal, state, or local law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

2:46 min

Evaluating managed container services and migration strategies

Adam Bien · World Congress 2021

Videos

See all

Related articles

See all