user avatar

Azure Platform Engineering Lead

cb5 Solutions, LLC

Posted today

Job Requirements

Colorado Springs, CO Huntsville, AL
Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
$155,000 - $175,000

Job Description

About the Job 

At cb5, we are on a mission to find exceptional talent. Our tight-knit organization is led by five brothers, each technology leaders in their respective technical fields and driven to foster a culture of excellence through solidarity. We are seeking an Azure Platform Engineering Lead to stand up and own the Azure platform for a greenfield Department of Defense hybrid multi-cloud program. This team is on the front lines, shaping the systems that protect us from advanced threats. We are looking for highly motivated, results-oriented professionals who thrive on solving complex technical challenges in a dynamic environment. 

The Azure Platform Engineering Lead is the technical authority for Azure on the program. You will design and build the Azure foundation, including landing zones, management group and subscription structure, policy and governance, platform networking, and the platform services enterprise workloads run on. Azure is one of three platforms in this environment, alongside AWS and on-premises VMware Cloud Foundation, so much of the work is holding Azure to one program reference architecture rather than letting it become a separate design. The role is the direct engineering counterpart to the platform vendor and to the customer's cloud architecture leadership, and it is hands-on. You will write the infrastructure code that stands the platform up, not only the design that describes it. 

This is a full time position working onsite in either Colorado Springs, CO or Huntsville, AL, requiring less than 10% travel. 

Salary: $155,000 - $175,000

Key Responsibilities 

The candidate will: 

- Serve as the technical authority for Azure, owning the Azure platform architecture, engineering standards and design decisions. 

- Design and build Azure landing zones, including management group hierarchy, subscription strategy, naming and tagging, and separation of platform from workload. 

- Own Azure governance, including Azure Policy and initiatives, role-based access control, cost management, and the guardrails that keep workload teams inside the design. 

- Design Azure platform networking with the Network team, including virtual network topology, hub and spoke or virtual WAN, ExpressRoute and hybrid connectivity, DNS and network security controls.
 
- Integrate Azure with the program identity architecture, including Entra ID, conditional access, managed identities and privileged access for platform administration. 

- Build the Azure platform through Infrastructure as Code using the program automation standards, and contribute Azure modules back to the shared library. 

- Design platform security and compliance, including hardened baselines, key and secret management, logging, and the evidence accreditation depends on. 

- Design monitoring, resilience and recovery for the Azure platform, including telemetry, availability targets, and backup and recovery patterns. 

- Serve as the engineering counterpart to the platform vendor and to customer cloud architecture leadership, and prepare Azure courses of action and design decisions for architecture review. 

- Keep Azure aligned to the program reference architecture so identity, network, security and data patterns match what is delivered on AWS and on-premises. 

- Support migration by designing the target Azure landing zones and the platform capabilities each migration wave depends on. 

The successful candidate will: 

- Be a strong innovator in process improvement and system design. 

- Be able to quickly learn challenging concepts, decompose difficult service problems and provide resolution. 

- Be able to create and follow standard processes and clearly document results. 

- Effectively function as self-starter and identify risks, issues, and opportunities to leadership. 

- Have excellent presentation, oral and written skills to facilitate effective and efficient interchanges with senior customer management and customers. 

- This role offers the opportunity to stand up the Azure foundation for a greenfield hybrid multi-cloud environment in support of defense, intelligence and enterprise modernization programs. 

Qualifications 

- Must have 10, or more, years of enterprise infrastructure or cloud engineering experience, with 6, or more, years focused on Azure architecture and engineering.

- Must have 2, or more, years serving as the technical lead or design authority for an enterprise Azure environment.

- Hands-on experience designing and building Azure landing zones, management groups, subscription structure and policy-based governance. 

- Experience with Azure platform networking, including virtual networks, hub and spoke topology, ExpressRoute or equivalent hybrid connectivity, DNS and network security controls. 

- Experience with Azure identity integration, including Entra ID, role-based access control and managed identities. 

- Experience deploying Azure through Infrastructure as Code (Terraform, Bicep or ARM) and CI/CD pipelines. 

- Experience with Azure platform security, including hardened baselines, key and secret management, logging and monitoring. 

- Experience integrating Azure with on-premises infrastructure in a hybrid environment. 

- Experience with Azure Government or another sovereign, regulated or restricted cloud environment.
 
- Understanding of how Azure platform decisions affect identity, network, cybersecurity and migration teams.
 
- Excellent written and verbal communication skills, including presenting design decisions to senior government leadership and platform vendors. 

- Must meet DoD 8570 certification requirements (e.g. Sec+) within 60 days of hire. 

- Must have an active DoD Secret Security Clearance, or be eligible to obtain one.  

Preferred Qualifications 

- Have an active DoD Secret Security Clearance or Top-Secret Security Clearance with SCI eligibility. 

- Have a Bachelor’s degree (or higher) in Computer Science, Engineering, Information Systems, or related field.
 
- Have 1, or more, Azure certifications (e.g, Microsoft Certified: Azure Solutions Architect Expert, Azure Administrator Associate, Azure Network Engineer Associate). 

- Have experience supporting Department of Defense (DoD) or Federal cloud initiatives. 

- Have experience with DoD Impact Level environments and cloud accreditation requirements. 

- Have experience with Azure Kubernetes Service, Azure Arc or Azure Virtual Desktop. 

- Have experience designing multi-cloud environments that also include AWS. 

- Have experience applying Zero Trust conditional access and enforcement within a cloud platform. 

- Have experience working in an agile environment. 


cb5 Solutions LLC is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, disability, veteran status, or any other protected characteristic.
group id: RTX17258f