Job Requirements
Remote Fort Meade, MD Columbia, MD Rockville, MD
Top Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$160,000 - $180,000
Job Description
HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, cloud infrastructure, and modernization services to federal government agencies.
We are seeking a Microsoft Azure Cloud Engineer to design, implement, secure, and operate Azure environments supporting DoD Impact Level 5 through classified and Top Secret mission workloads. This position will support Azure Government, Azure Government Secret, Azure Government Top Secret, and other accredited environments as required by the customer.
The successful candidate will work with cloud architects, DevSecOps engineers, cybersecurity professionals, application teams, and Government stakeholders to translate approved designs and security requirements into reliable cloud infrastructure. This is a hands-on engineering role focused on implementation, automation, troubleshooting, and operational readiness.
Candidates must be located in the Washington, DC, metropolitan area. Some work will be performed in accredited or SCIF facilities.
Responsibilities
Build, configure, and maintain secure Microsoft Azure environments supporting IL5, IL6, and Top Secret or IL7-equivalent workloads.
Implement cloud landing zones, subscriptions, resource organization, network boundaries, identity controls, logging, and governance policies.
Deploy and manage Azure infrastructure using Terraform, Bicep, ARM templates, or comparable Infrastructure as Code tools.
Configure Azure networking, including virtual networks, subnets, routing, private endpoints, DNS, firewalls, load balancers, network security groups, and hybrid connectivity.
Implement identity and access controls using Microsoft Entra ID, role-based access control, managed identities, privileged-access controls, and Azure Key Vault.
Deploy and operate Azure compute, storage, database, and container services in accordance with approved architectures and security requirements.
Apply Azure Policy, security baselines, DISA STIGs, encryption requirements, and configuration standards in partnership with cybersecurity teams.
Implement monitoring, alerting, audit logging, and operational dashboards using Azure Monitor, Log Analytics, Defender for Cloud, and Microsoft Sentinel.
Support deployment and operations in disconnected, air-gapped, or classified environments where public-cloud services and external dependencies may be limited.
Troubleshoot cloud infrastructure, networking, identity, performance, and configuration issues across development, test, and production environments.
Support backup, recovery, continuity-of-operations, and disaster-recovery planning and testing.
Produce infrastructure diagrams, configuration documentation, operating procedures, and customer-handoff materials.
Provide technical evidence and configuration details in support of RMF authorization, assessment, and continuous-monitoring activities.
Required Qualifications
5+ years of hands-on cloud or infrastructure engineering experience, including responsibility for production environments.
Strong experience designing, deploying, and operating solutions in Microsoft Azure.
Hands-on experience with Azure Government or another regulated government-cloud environment.
Strong knowledge of Azure networking, identity and access management, compute, storage, security, monitoring, and governance.
Proficiency with Infrastructure as Code using Terraform, Bicep, ARM templates, or a comparable technology.
Experience implementing secure cloud landing zones, subscription structures, network segmentation, access controls, and centralized logging.
Experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure Policy, Azure Monitor, and Log Analytics.
Working knowledge of Windows and Linux administration, including command-line troubleshooting and system hardening.
Experience using PowerShell, Azure CLI, Python, or another scripting language to automate cloud operations.
Understanding of cloud security principles, least-privilege access, encryption, vulnerability management, backup, and disaster recovery.
Familiarity with the DoD Cloud Computing SRG, RMF, NIST SP 800-53, and applicable DISA STIGs.
Strong troubleshooting, documentation, and stakeholder communication skills.
Ability to work independently and manage priorities across multiple concurrent engagements.
DoD 8570/8140 IAT Level II certification, with Security+ CE or an accepted equivalent.
Active Department of Defense Top Secret clearance. Candidates must maintain their clearance and be SCI-eligible and willing to be read in.
*** Preferred Qualifications***
Active TS/SCI clearance.
Direct experience with Azure Government Secret, Azure Government Top Secret, or another classified cloud environment.
Experience implementing Azure environments supporting DoD IL5, IL6, ICD 503, JSIG, SAP, or Top Secret workloads.
Experience with disconnected operations, air-gapped deployments, classified networks, or cross-domain solutions.
Experience with Azure Landing Zones, Secure Azure Computing Architecture, or DoD Secure Cloud
Computing Architecture requirements.
Experience with hybrid connectivity, ExpressRoute, network virtual appliances, boundary protection, or enterprise DNS.
Experience with Azure Kubernetes Service, container registries, virtual machines, or platform services in restricted environments.
Experience automating security baselines, STIG validation, configuration compliance, or continuous-monitoring evidence.
Experience supporting RMF authorization, assessment, remediation, or continuous ATO activities.
Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate, or Azure Network Engineer Associate.
CISSP, CASP+, or another advanced security certification.
HyerTek offers a comprehensive benefits package, including:
- Medical, dental, and vision insurance
- 401(k) with employer contribution
- Paid time off (PTO) and company holidays
- Professional development and certification support
- Employee assistance program (EAP)
- Life and disability insurance
Clearance & Work Authorization
This position requires U.S. citizenship and an active TS clearance with the Department of Defense. TS/SCI is strongly preferred, and candidates holding TS must be SCI-eligible; the work is expected to require SCI access, and HyerTek will sponsor the read-in for an otherwise qualified candidate. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future.
Salary Range
$160,000 – $180,000 annually, depending on experience and clearance status.
Equal Employment Opportunity (EEO)
HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected status.
We are seeking a Microsoft Azure Cloud Engineer to design, implement, secure, and operate Azure environments supporting DoD Impact Level 5 through classified and Top Secret mission workloads. This position will support Azure Government, Azure Government Secret, Azure Government Top Secret, and other accredited environments as required by the customer.
The successful candidate will work with cloud architects, DevSecOps engineers, cybersecurity professionals, application teams, and Government stakeholders to translate approved designs and security requirements into reliable cloud infrastructure. This is a hands-on engineering role focused on implementation, automation, troubleshooting, and operational readiness.
Candidates must be located in the Washington, DC, metropolitan area. Some work will be performed in accredited or SCIF facilities.
Responsibilities
Build, configure, and maintain secure Microsoft Azure environments supporting IL5, IL6, and Top Secret or IL7-equivalent workloads.
Implement cloud landing zones, subscriptions, resource organization, network boundaries, identity controls, logging, and governance policies.
Deploy and manage Azure infrastructure using Terraform, Bicep, ARM templates, or comparable Infrastructure as Code tools.
Configure Azure networking, including virtual networks, subnets, routing, private endpoints, DNS, firewalls, load balancers, network security groups, and hybrid connectivity.
Implement identity and access controls using Microsoft Entra ID, role-based access control, managed identities, privileged-access controls, and Azure Key Vault.
Deploy and operate Azure compute, storage, database, and container services in accordance with approved architectures and security requirements.
Apply Azure Policy, security baselines, DISA STIGs, encryption requirements, and configuration standards in partnership with cybersecurity teams.
Implement monitoring, alerting, audit logging, and operational dashboards using Azure Monitor, Log Analytics, Defender for Cloud, and Microsoft Sentinel.
Support deployment and operations in disconnected, air-gapped, or classified environments where public-cloud services and external dependencies may be limited.
Troubleshoot cloud infrastructure, networking, identity, performance, and configuration issues across development, test, and production environments.
Support backup, recovery, continuity-of-operations, and disaster-recovery planning and testing.
Produce infrastructure diagrams, configuration documentation, operating procedures, and customer-handoff materials.
Provide technical evidence and configuration details in support of RMF authorization, assessment, and continuous-monitoring activities.
Required Qualifications
5+ years of hands-on cloud or infrastructure engineering experience, including responsibility for production environments.
Strong experience designing, deploying, and operating solutions in Microsoft Azure.
Hands-on experience with Azure Government or another regulated government-cloud environment.
Strong knowledge of Azure networking, identity and access management, compute, storage, security, monitoring, and governance.
Proficiency with Infrastructure as Code using Terraform, Bicep, ARM templates, or a comparable technology.
Experience implementing secure cloud landing zones, subscription structures, network segmentation, access controls, and centralized logging.
Experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure Policy, Azure Monitor, and Log Analytics.
Working knowledge of Windows and Linux administration, including command-line troubleshooting and system hardening.
Experience using PowerShell, Azure CLI, Python, or another scripting language to automate cloud operations.
Understanding of cloud security principles, least-privilege access, encryption, vulnerability management, backup, and disaster recovery.
Familiarity with the DoD Cloud Computing SRG, RMF, NIST SP 800-53, and applicable DISA STIGs.
Strong troubleshooting, documentation, and stakeholder communication skills.
Ability to work independently and manage priorities across multiple concurrent engagements.
DoD 8570/8140 IAT Level II certification, with Security+ CE or an accepted equivalent.
Active Department of Defense Top Secret clearance. Candidates must maintain their clearance and be SCI-eligible and willing to be read in.
*** Preferred Qualifications***
Active TS/SCI clearance.
Direct experience with Azure Government Secret, Azure Government Top Secret, or another classified cloud environment.
Experience implementing Azure environments supporting DoD IL5, IL6, ICD 503, JSIG, SAP, or Top Secret workloads.
Experience with disconnected operations, air-gapped deployments, classified networks, or cross-domain solutions.
Experience with Azure Landing Zones, Secure Azure Computing Architecture, or DoD Secure Cloud
Computing Architecture requirements.
Experience with hybrid connectivity, ExpressRoute, network virtual appliances, boundary protection, or enterprise DNS.
Experience with Azure Kubernetes Service, container registries, virtual machines, or platform services in restricted environments.
Experience automating security baselines, STIG validation, configuration compliance, or continuous-monitoring evidence.
Experience supporting RMF authorization, assessment, remediation, or continuous ATO activities.
Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate, or Azure Network Engineer Associate.
CISSP, CASP+, or another advanced security certification.
HyerTek offers a comprehensive benefits package, including:
- Medical, dental, and vision insurance
- 401(k) with employer contribution
- Paid time off (PTO) and company holidays
- Professional development and certification support
- Employee assistance program (EAP)
- Life and disability insurance
Clearance & Work Authorization
This position requires U.S. citizenship and an active TS clearance with the Department of Defense. TS/SCI is strongly preferred, and candidates holding TS must be SCI-eligible; the work is expected to require SCI access, and HyerTek will sponsor the read-in for an otherwise qualified candidate. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future.
Salary Range
$160,000 – $180,000 annually, depending on experience and clearance status.
Equal Employment Opportunity (EEO)
HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected status.
group id: 91125207