Job Requirements
Remote Fort Meade, MD
Top Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$145,000 - $186,500
Job Description
HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, cloud infrastructure, and modernization solutions to federal government agencies.
HyerTek is seeking a Microsoft Azure Senior Cloud Engineer to design, build, implement, secure, and operate Azure environments supporting DoW Impact Levels 5, 6, and 7 or equivalent classification levels and other accredited environments as required by the customer.
A successful candidate will own the solution end to end, working directly with cybersecurity professionals, application teams, and Government stakeholders to translate mission requirements and security controls into sounds technical designs and production-ready solutions. This role uses AI-assisted development tools and code generation to accelerate infrastructure-as-code, control documentation, and runbooks, while applying sounds engineering judgment to review and validate AI-generated output before it is deployed to an accredited environment.
This is a hybrid position. Candidates must reside in the Washington, DC, metropolitan area. Some work will be performed at customer facilities, including accredited Secure Areas and SCIFs at Fort Meade.
Responsibilities
• Build, configure, and maintain secure Microsoft Azure environments supporting IL5, IL6, and IL7, or equivalent workloads in accordance with approved architectures, customer and contract requirements, and applicable security controls and regulations.
• Implement cloud landing zones, subscriptions, resource organization, network boundaries, identity controls, logging, and governance policies.
• Deploy and manage Azure infrastructure using Terraform, Bicep, ARM templates, or comparable Infrastructure as Code tools.
• Configure Azure networking, including virtual networks, subnets, routing, private endpoints, DNS, firewalls, load balancers, network security groups, and hybrid connectivity.
• Implement identity and access controls using Microsoft Entra ID, role-based access control, managed identities, privileged-access controls, and Azure Key Vault.
• Deploy and operate Azure compute, storage, database, and container services in accordance with approved architectures and security requirements.
• Apply Azure Policy, security baselines, DISA STIGs, encryption requirements, and configuration standards in partnership with cybersecurity teams.
• Implement, validate, and maintain applicable DISA STIGs and security configuration baselines, including remediation of configuration findings and support for automated compliance validation.
• Implement monitoring, alerting, audit logging, and operational dashboards using Azure Monitor, Log Analytics, Defender for Cloud, and Microsoft Sentinel, as applicable to the environment.
• Support deployment and operations in disconnected, air-gapped, or classified environments where public-cloud services and external dependencies may be limited.
• Troubleshoot cloud infrastructure, networking, identity, performance, and configuration issues across development, test, and production environments.
• Support backup, recovery, continuity-of-operations, and disaster-recovery planning and testing.
• Produce infrastructure diagrams, configuration documentation, operating procedures, and customer-handoff materials.
• Provide technical evidence and configuration details in support of RMF authorization, assessment, and continuous-monitoring activities.
• Collaborate with cybersecurity and DevSecOps teams to remediate vulnerabilities, security findings, configuration deviations, and compliance deficiencies.
• Support security assessments, authorization activities, audits, and customer reviews by providing accurate infrastructure configurations, technical documentation, and required evidence.
Required Qualifications
• 5+ years of hands-on cloud or infrastructure engineering experience, including responsibility for production environments.
• Strong experience designing, deploying, and operating solutions in Microsoft Azure.
• Hands-on experience with Azure Government or another regulated government-cloud environment.
• Strong knowledge of Azure networking, identity and access management, compute, storage, security, monitoring, and governance.
• Proficiency with Infrastructure as Code using Terraform, Bicep, ARM templates, or a comparable technology.
• Experience implementing secure cloud landing zones, subscription structures, network segmentation, access controls, and centralized logging.
• Experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure Policy, Azure Monitor, and Log Analytics.
• Working knowledge of Windows and Linux administration, including command-line troubleshooting and system hardening.
• Experience using PowerShell, Azure CLI, Python, or another scripting language to automate cloud operations.
• Understanding of cloud security principles, least-privilege access, encryption, vulnerability management, backup, and disaster recovery.
• Familiarity with the DoW Cloud Computing SRG, RMF, NIST SP 800-53, and applicable DISA STIGs.
• Demonstrated experience applying security hardening requirements, DISA STIGs, or comparable federal security configuration baselines in cloud or infrastructure environments.
• Strong proficiency in AI platforms including Open AI, Claude, Gemini, and Microsoft CoPilot.
• Strong troubleshooting, documentation, and stakeholder communication skills.
• Ability to work independently and collaboratively across multiple concurrent engagements and manage priorities.
• DoW 8140 aligned IAT Level II certification, with Security+ CE or an approved equivalent.
• Active Top Secret security clearance required. Candidates must be eligible to obtain and maintain any additional customer-specific access requirements associated with their assigned work.
Preferred Qualifications
• Active TS/SCI security clearance.
• Direct experience with Azure Government Secret, Top Secret, or other classified cloud environment.
• Experience implementing Azure environments supporting DoW IL5, 6, or 7 (or equivalent classifications), ICD 503, JSIG, or SAP workloads.
• Azure networking experience, including VNets, subnets, private endpoints, NSGs, Aure Firewall, routing, DNS, networking segmentation, disconnected operations, and/or air-gapped deployments on classified networks or cross-domain solutions.
• Experience with Azure Landing Zones, Secure Azure Computing Architecture, or DoW Secure Cloud
• Computing Architecture requirements.
• Experience with hybrid connectivity, ExpressRoute, network virtual appliances, boundary protection, or enterprise DNS.
• Experience with Azure Kubernetes Service, container registries, virtual machines, or platform services in restricted environments.
• Experience automating security baselines, STIG validation, configuration compliance, or continuous-monitoring evidence.
• Experience supporting RMF authorization, assessment, remediation, or continuous ATO activities.
• Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate, or Azure Network Engineer Associate.
• CISSP, CASP+, or another advanced security certification.
Benefits
HyerTek offers a comprehensive benefits package, including:
• Medical, dental, and vision insurance
• 401(k) with employer contribution
• Paid time off (PTO) and company holidays
• Professional development and certification support
• Employee assistance program (EAP)
• Life and disability insurance
Clearance & Work Authorization
This position requires U.S. citizenship and an active TS security clearance with the Department of War. The candidate must be able to obtain and maintain SCI eligibility; an active TS/SCI clearance is strongly preferred. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future. HyerTek will not sponsor applicants for a U.S. work visa status for this opportunity.
Salary Range
The anticipated salary range for this position is $145,000 – $186,500 annually. Final compensation will be based on relevant experience, technical qualifications, certifications, clearance status, and contract requirements.
Equal Employment Opportunity (EEO)
HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other status protected by applicable federal, state, or local law.
HyerTek is seeking a Microsoft Azure Senior Cloud Engineer to design, build, implement, secure, and operate Azure environments supporting DoW Impact Levels 5, 6, and 7 or equivalent classification levels and other accredited environments as required by the customer.
A successful candidate will own the solution end to end, working directly with cybersecurity professionals, application teams, and Government stakeholders to translate mission requirements and security controls into sounds technical designs and production-ready solutions. This role uses AI-assisted development tools and code generation to accelerate infrastructure-as-code, control documentation, and runbooks, while applying sounds engineering judgment to review and validate AI-generated output before it is deployed to an accredited environment.
This is a hybrid position. Candidates must reside in the Washington, DC, metropolitan area. Some work will be performed at customer facilities, including accredited Secure Areas and SCIFs at Fort Meade.
Responsibilities
• Build, configure, and maintain secure Microsoft Azure environments supporting IL5, IL6, and IL7, or equivalent workloads in accordance with approved architectures, customer and contract requirements, and applicable security controls and regulations.
• Implement cloud landing zones, subscriptions, resource organization, network boundaries, identity controls, logging, and governance policies.
• Deploy and manage Azure infrastructure using Terraform, Bicep, ARM templates, or comparable Infrastructure as Code tools.
• Configure Azure networking, including virtual networks, subnets, routing, private endpoints, DNS, firewalls, load balancers, network security groups, and hybrid connectivity.
• Implement identity and access controls using Microsoft Entra ID, role-based access control, managed identities, privileged-access controls, and Azure Key Vault.
• Deploy and operate Azure compute, storage, database, and container services in accordance with approved architectures and security requirements.
• Apply Azure Policy, security baselines, DISA STIGs, encryption requirements, and configuration standards in partnership with cybersecurity teams.
• Implement, validate, and maintain applicable DISA STIGs and security configuration baselines, including remediation of configuration findings and support for automated compliance validation.
• Implement monitoring, alerting, audit logging, and operational dashboards using Azure Monitor, Log Analytics, Defender for Cloud, and Microsoft Sentinel, as applicable to the environment.
• Support deployment and operations in disconnected, air-gapped, or classified environments where public-cloud services and external dependencies may be limited.
• Troubleshoot cloud infrastructure, networking, identity, performance, and configuration issues across development, test, and production environments.
• Support backup, recovery, continuity-of-operations, and disaster-recovery planning and testing.
• Produce infrastructure diagrams, configuration documentation, operating procedures, and customer-handoff materials.
• Provide technical evidence and configuration details in support of RMF authorization, assessment, and continuous-monitoring activities.
• Collaborate with cybersecurity and DevSecOps teams to remediate vulnerabilities, security findings, configuration deviations, and compliance deficiencies.
• Support security assessments, authorization activities, audits, and customer reviews by providing accurate infrastructure configurations, technical documentation, and required evidence.
Required Qualifications
• 5+ years of hands-on cloud or infrastructure engineering experience, including responsibility for production environments.
• Strong experience designing, deploying, and operating solutions in Microsoft Azure.
• Hands-on experience with Azure Government or another regulated government-cloud environment.
• Strong knowledge of Azure networking, identity and access management, compute, storage, security, monitoring, and governance.
• Proficiency with Infrastructure as Code using Terraform, Bicep, ARM templates, or a comparable technology.
• Experience implementing secure cloud landing zones, subscription structures, network segmentation, access controls, and centralized logging.
• Experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure Policy, Azure Monitor, and Log Analytics.
• Working knowledge of Windows and Linux administration, including command-line troubleshooting and system hardening.
• Experience using PowerShell, Azure CLI, Python, or another scripting language to automate cloud operations.
• Understanding of cloud security principles, least-privilege access, encryption, vulnerability management, backup, and disaster recovery.
• Familiarity with the DoW Cloud Computing SRG, RMF, NIST SP 800-53, and applicable DISA STIGs.
• Demonstrated experience applying security hardening requirements, DISA STIGs, or comparable federal security configuration baselines in cloud or infrastructure environments.
• Strong proficiency in AI platforms including Open AI, Claude, Gemini, and Microsoft CoPilot.
• Strong troubleshooting, documentation, and stakeholder communication skills.
• Ability to work independently and collaboratively across multiple concurrent engagements and manage priorities.
• DoW 8140 aligned IAT Level II certification, with Security+ CE or an approved equivalent.
• Active Top Secret security clearance required. Candidates must be eligible to obtain and maintain any additional customer-specific access requirements associated with their assigned work.
Preferred Qualifications
• Active TS/SCI security clearance.
• Direct experience with Azure Government Secret, Top Secret, or other classified cloud environment.
• Experience implementing Azure environments supporting DoW IL5, 6, or 7 (or equivalent classifications), ICD 503, JSIG, or SAP workloads.
• Azure networking experience, including VNets, subnets, private endpoints, NSGs, Aure Firewall, routing, DNS, networking segmentation, disconnected operations, and/or air-gapped deployments on classified networks or cross-domain solutions.
• Experience with Azure Landing Zones, Secure Azure Computing Architecture, or DoW Secure Cloud
• Computing Architecture requirements.
• Experience with hybrid connectivity, ExpressRoute, network virtual appliances, boundary protection, or enterprise DNS.
• Experience with Azure Kubernetes Service, container registries, virtual machines, or platform services in restricted environments.
• Experience automating security baselines, STIG validation, configuration compliance, or continuous-monitoring evidence.
• Experience supporting RMF authorization, assessment, remediation, or continuous ATO activities.
• Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate, or Azure Network Engineer Associate.
• CISSP, CASP+, or another advanced security certification.
Benefits
HyerTek offers a comprehensive benefits package, including:
• Medical, dental, and vision insurance
• 401(k) with employer contribution
• Paid time off (PTO) and company holidays
• Professional development and certification support
• Employee assistance program (EAP)
• Life and disability insurance
Clearance & Work Authorization
This position requires U.S. citizenship and an active TS security clearance with the Department of War. The candidate must be able to obtain and maintain SCI eligibility; an active TS/SCI clearance is strongly preferred. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future. HyerTek will not sponsor applicants for a U.S. work visa status for this opportunity.
Salary Range
The anticipated salary range for this position is $145,000 – $186,500 annually. Final compensation will be based on relevant experience, technical qualifications, certifications, clearance status, and contract requirements.
Equal Employment Opportunity (EEO)
HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other status protected by applicable federal, state, or local law.
group id: 91125207