Azure Cloud Infrastructure & Security Architect (Top Secret clearance)

Washington, DC
Full Time
Experienced
The Opportunity

We are seeking an experienced Azure Cloud Infrastructure & Security Architect to lead the modernization of mission-critical infrastructure for a federal government customer. This is a fully onsite role in Washington, D.C. or Bethesda, MD.

This is a senior, hands-on technical role for an architect who can both design the target-state Azure environment and help drive its implementation. You will serve as a technical authority for Microsoft Azure Government, leading cloud architecture, migration, security, and operational efforts while working closely with government stakeholders and engineering teams.

The ideal candidate brings deep Azure expertise, a strong understanding of secure federal cloud environments, and the ability to translate mission and security requirements into scalable, production-ready architecture.

What You'll Do

As an Azure Cloud Infrastructure & Security Architect, you will:
 
  • Serve as a technical authority for Microsoft Azure Government, leading cloud architecture, design, implementation, and modernization efforts.
  • Architect and support the migration of on-premises and legacy workloads into Azure Government environments, including GCC High and/or Azure Government Secret, based on program accreditation requirements.
  • Design secure, scalable, resilient, and highly available Azure infrastructure aligned with federal security and compliance requirements, including FedRAMP, NIST SP 800-53, and RMF.
  • Partner with ISSOs, ISSMs, security teams, and government stakeholders to support Authorization to Operate (ATO) activities and ensure architecture aligns with applicable security controls.
  • Architect identity and access management solutions using Microsoft Entra ID, including Conditional Access, Privileged Identity Management (PIM), role-based access controls, and integration with on-premises identity systems.
  • Design and implement Azure networking solutions spanning VNets, routing, private connectivity, firewalls, VPNs, and hybrid connectivity.
  • Develop and maintain Infrastructure-as-Code (IaC) using Terraform, Bicep, ARM templates, or similar technologies.
  • Establish monitoring, logging, security, and operational visibility using technologies such as Azure Monitor, Log Analytics, Microsoft Sentinel, and Defender for Cloud.
  • Support priority mission initiatives, including cloud infrastructure supporting large-scale ETL and data ingestion across distributed data sources.
  • Troubleshoot complex cloud infrastructure, networking, identity, security, and performance issues.
  • Provide technical leadership and mentorship to engineers while collaborating with program leadership and cross-functional technical teams.
  • Translate mission, operational, and security requirements into practical cloud architecture and engineering solutions.
  • Produce and maintain architecture diagrams, technical designs, runbooks, implementation documentation, and standard operating procedures.

What You Bring
 
  • Active Top Secret clearance with SCI eligibility.
  • U.S. citizenship.
  • Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical field, or equivalent professional experience.
  • 8+ years of overall IT/infrastructure engineering experience.
  • 5+ years of hands-on experience architecting, engineering, and supporting Microsoft Azure environments.
  • Strong hands-on knowledge of Azure infrastructure, including networking, compute, storage, identity, security, monitoring, and hybrid connectivity.
  • Experience designing and implementing secure, production-grade cloud environments.
  • Current Microsoft Azure certification at the Associate level or higher.
  • Ability to communicate complex technical concepts effectively with engineers, program leadership, security teams, and government stakeholders.

Preferred Qualifications
 
  • The strongest candidates will also bring experience in several of the following areas:
  • Hands-on experience designing, deploying, or operating Azure Government, GCC High, Azure Government Secret, or other restricted government cloud environments.
  • Experience with federal cloud security and compliance frameworks, including FedRAMP, NIST SP 800-53, RMF, and DoD Impact Levels.
  • Experience supporting or contributing to ATO packages, security control implementation, and accreditation activities.
  • Deep Azure networking expertise, including VNets, ExpressRoute, Azure Firewall, Private Link, VPN Gateway, and Virtual WAN.
  • Advanced experience with Microsoft Entra ID, Conditional Access, PIM, RBAC, federation, and hybrid identity.
  • Experience building cloud infrastructure through Terraform, Bicep, ARM templates, and CI/CD pipelines.
  • Experience with Microsoft Sentinel, Defender for Cloud, Azure Policy, and Microsoft Purview.
  • Azure Solutions Architect Expert, Azure Security Engineer Associate, or other advanced Microsoft cloud/security certifications.
  • Prior experience supporting federal civilian, Department of Defense, or Intelligence Community customers.
  • Familiarity with AWS and AWS GovCloud in support of hybrid or multi-cloud environments.
  • Current SCI indoctrination or previous SCI access.

Compensation

The estimated salary range for this position is $195,000 – $225,000 annually, based on market benchmarks within the Washington, D.C. metropolitan area. This range represents a good faith estimate and may vary depending on several factors, including the scope of the role, geographic location, education, certifications, technical skills, and overall relevant experience.
 
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*