Responsibilities
- Lead the design, continuous monitoring, implementation, and security operations of Azure cloud solutions, ensuring they meet industry best practices and comply with FedRAMP High, IL4 requirements.
- Lead team in developing modular Infrastructure-as-Code utilizing Terraform, PowerShell, ARM, Bicep, and YAML languages.
- Lead projects of moderate complexity to completion.
- Sustain a high level of reliability for key automated systems.
- Leads teams to define, estimate, and implement requirements for new automations or services of moderate complexity needing development.
- Stay up to date with the latest Azure and FedRAMP regulatory changes and industry trends, advising teams on potential impacts and necessary adjustments.
- Update technical documentation, workflows, and knowledge base articles.
- Provide feedback in pull requests and peer coding reviews.
- Solid knowledge in focused areas of OneStream Software.
- Participate in on-call rotation to support production systems.
- Assist in efforts to debug the problems which arise in production.
- Ability to mentor others in several technical areas.
- Understanding practical use of FedRAMP/SOC controls to assist Compliance and Security teams.
Requirements
- BS/BA in computer science, engineering, or technology-related field (or equivalent work experience).
- 8+ years of cloud infrastructure experience.
- 2+ years of compliance programs and security control sets such as NIST SP 800-53, FedRAMP High, IL4, as applied to cloud SaaS, PaaS, and IaaS environments.
- Expert knowledge of: VNets/vWAN, subnets, UDRs, routing, peering.
- Expert knowledge of: ExpressRoute, VPN Gateway, Private Link/Endpoint.
- Expert knowledge of: Azure Firewall, NSG/ASG, WAF, Application Gateway, Web Application Firewalls.
- Hands-on experience implementing network design and firewall configurations, as it pertains to connecting to government networks (BCAP) utilizing Azure Firewall and/or Palo Alto.
- Hands on experience implementing IPv6 routing and strict egress filtering strategies.
- Ability to translate DISA STIGs and NIST controls into enforceable network guardrails and evidence artifacts.
- Advanced understanding of Infrastructure-As-Code concepts and tooling (Terraform, CloudFormation templates, Bicep or ARM templates) on Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform (GCP).
- Deep knowledge of Configuration Management/Orchestration utilities such as Ansible, PowerShell DSC, Chef, and Puppet.
- Advanced understanding of cloud concepts including elasticity, security, and identity management.
- Well versed familiarity with Agile Development methodologies utilizing Jira or Azure DevOps Boards.
- Strong understanding of Azure Kubernetes Services (AKS) with container-based deployment skills or other platforms such as OpenShift, GKS, EKS.
- Proficient knowledge in Software Development Lifecycles.
- 8+ years of hands-on experience with the following technologies, tools, and concepts: Automating processes using PowerShell, Bash, CLI, REST APIs, python, ARM Templates or other scripting languages.
- Comfortable leveraging source control tools such as Git, BitBucket, or GitHub.
- Microsoft Azure, Amazon Web Services (AWS) or Google Cloud (GCP).
- Microsoft Windows 11, Windows Server, IIS, Microsoft SQL Server, Active Directory.
Nice to Have
- Experience working for a cloud service provider (CSP), managed service provider (MSP), or SaaS provider.
- 8+ years of relevant Azure experience deploying and managing leveraging Infrastructure-as-Code (IAC) concepts.
- Microsoft Windows Server 2016-2022, IIS, Microsoft SQL Server, Azure Active Directory.
- Debian, Ubuntu, or other flavors of the Linux operating systems.
- Any certifications such as Microsoft Certified: Azure Administrator Associate (AZ-103, AZ-104), Azure Solutions Architect Expert (AZ-300, AZ-301), CCNP, CCIE, CISSP, Azure DevOps Engineer Expert (AZ-400), Certified Kubernetes Administrator (CKE), CISSP, Information Technology Infrastructure Library (ITIL) Foundation, Microsoft Certified Professional (MCP), CompTIA Security+/Network+ is a plus.
Benefits
- Vision
- Medical
- Life
- Dental
- 401K
- Excellent Medical Plan
- Dental & Vision Insurance
- Life Insurance
- Short & Long Term Disability
- Vacation Time
- Paid Holidays
- Professional Development
- Retirement Plan
Additional Information
- No travel is required.
- All candidates must be legally authorized to work for any company in the country where this position is located without sponsorship.
- OneStream is an Equal Opportunity Employer.