user avatar
Posted today

Job Requirements

Huntsville, AL
Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
$140,000 - $152,000

Job Description

Vanguard Defense Solutions is seeking a senior Cloud Engineer to own the architecture of the hybrid-cloud environment supporting the Missile Defense Agency Information Management and Software Services (AIMSS) program at Redstone Arsenal, where we serve as a subcontractor to Integration Innovation, Inc. (i3).


Position Summary

This is the senior-most cloud seat on our team. You will set the reference architectures the software, DevSecOps, and cyber teams build against, drive technical design with leads and product owners, and keep the environment secure, performant, and accreditation-ready as it scales.


We are a small, team-focused defense contractor. There is no layer of program bureaucracy between an engineer and a decision, and the patterns you set here will hold for the life of the contract. This role is on-site at Redstone Arsenal in Huntsville, AL.


Key Responsibilities

  • Own the architecture of the government-provided hybrid cloud environment, designing for security, performance, operability, and scale as program requirements evolve

  • Develop and maintain cloud reference architectures and documented baselines that development and engineering teams build against

  • Drive technical design with technical leads and product owners, translating solution requirements into architectural patterns the team can execute

  • Design and govern the Terraform baseline for provisioning and managing cloud resources, ensuring consistent, repeatable deployments across environments

  • Architect and oversee Azure Kubernetes Service (AKS) for containerized deployment, scaling, and orchestration, including image hardening in the deployment pipeline

  • Design identity, access, and encryption architecture using Microsoft Entra ID, Azure Key Vault, and RBAC, and set the standards that keep them consistent

  • Establish and maintain DISA STIG compliance and the technical artifacts supporting the RMF and accreditation process, so compliance is a byproduct of how the platform is built

  • Architect virtual networking (virtual networks, subnets, network security groups, hybrid connectivity) for secure and efficient traffic flow

  • Resolve application-to-platform integration issues across PaaS and IaaS offerings, and provide senior technical support to developer and cyber teams

  • Support the machine learning, data analysis, data visualization, and event-driven architecture work the program depends on

  • Create and maintain comprehensive documentation for system architecture, configurations, and operational procedures


Required Qualifications

  • Bachelor's degree in a relevant technical field and a minimum of 12 years of relevant experience (a government labor category minimum; see the application note below)

  • Demonstrated experience designing, not only administering, hybrid cloud environments, including migration of on-premise applications and infrastructure to the cloud

  • Hands-on Terraform experience at scale, including module structure, state management, and drift control

  • Hands-on experience with Azure Kubernetes Service (AKS) or equivalent container orchestration, and with CI/CD pipelines using Azure DevOps, GitLab, or Jenkins

  • Advanced knowledge of Microsoft Entra ID and RBAC, and experience with Azure Key Vault, Azure Monitor, Log Analytics, and Microsoft Defender for Cloud

  • Experience hardening systems to DISA STIGs and supporting RMF or ATO documentation

  • Strong understanding of Azure networking, including VNet peering, VPN Gateway, and ExpressRoute

  • Linux and Windows server administration, including patching, configuration, and troubleshooting

  • Active Secret security clearance, and the ability to maintain the clearance required for this position

  • U.S. citizenship

  • Residence within a 75-mile radius of Redstone Arsenal, or willingness to relocate before the start date, with the ability to reliably commute to the customer site as business needs dictate


Certifications (must have, or obtain before starting)

  • CompTIA Security+ CE, or another approved DoD 8570.01M IAT Level II certification

  • One of: Azure Solutions Architect Expert, Azure Administrator Associate, Azure Security Engineer Associate, AWS Certified Solutions Architect, CCSP, or GCSA


Preferred Qualifications

  • Proficiency in scripting with PowerShell, Azure CLI, Python, or Bash

  • Prior experience on an MDA program, or on another large DoD software services contract as part of a prime team

  • Experience with AWS in addition to Azure

  • Machine learning, data pipeline, or data visualization work in a production environment

  • Red Hat or OpenShift administration

  • Experience mentoring engineers and setting technical standards across multiple teams


Compensation and Benefits

The base salary range for this position is $140,000 to $152,000, depending on experience and qualifications against the labor category. Benefits include:



  • 15 days (120 hours) of PTO per calendar year in a single combined bank, accruing each pay period and usable for any purpose

  • 11 paid federal holidays

  • Medical, dental, and vision coverage, and a retirement savings plan

  • Up to $2,000 per year in tuition and certification reimbursement

  • Bereavement and jury duty leave, separate from and without reducing the PTO bank


Why Vanguard

We are deliberately small. Every team member has a visible role in the quality and integrity of what we deliver to our government customers, and engineers here own real scope rather than a slice of someone else's. You get direct access to company leadership, on a team small enough that your work is visible without having to campaign for it.


Application note: your resume must state your degree, graduation year, and dated employment history. The government labor category requires us to verify education and years of experience before an offer can be made.

group id: 91175873