Design and implement secure, scalable Azure cloud environments aligned with NIST SP 800-171 and CMMC Level 2 standards. This position plays a critical role in building and managing cloud infrastructure across compute, networking, storage, and identity systems within a GCC High-compliant ecosystem.
Key Responsibilities
- Architect and manage Azure virtual networks, including VNets, NSGs, ExpressRoute, and private endpoints to ensure secure connectivity
- Configure and maintain hybrid Office 365 environments integrated with Azure AD, AD Connect, and Duo for seamless identity management
- Develop automation scripts using PowerShell to streamline deployment, monitoring, and maintenance tasks
- Support and enhance Windows Virtual Desktop environments, focusing on performance, cost optimization, and security configuration
- Implement and manage data protection measures, including Data Loss Prevention (DLP) and Azure Information Protection (AIP) policies
- Deploy and monitor security tools such as Azure Sentinel, CrowdStrike, and Qualys to support SIEM operations and threat detection
- Generate and maintain technical documentation, architecture diagrams, and compliance evidence for audits and assessments
- Participate in risk evaluation, change management, and stakeholder discussions to guide infrastructure decisions
- Ensure continuous alignment with CMMC requirements, particularly in handling controlled unclassified information (CUI)
- Provide expert troubleshooting for network and system issues, supporting secure and reliable operations
Qualifications
Seven or more years of hands-on experience administering Azure cloud platforms is required. Candidates must demonstrate proven work within environments governed by NIST 800-171 and CMMC Level 2. A Microsoft certification in either Azure Administration or Azure Security Engineering is mandatory. U.S. citizenship is required for access to government-compliant systems.
Preferred Background
- Bachelor’s degree in information technology or a related field
- Active or recently held security clearance
- Industry-recognized certifications such as Security+, Network+, or CMMC Certified Professional
- Experience with federation and single sign-on solutions, including user provisioning workflows
- Working knowledge of Windows Terminal Services or remote desktop configuration