Hybrid Multi-Cloud Engineer SME (Azure/Identity)
On-siteFort Belvoir, Virginia, United States
Job Summary
Architect, design, and implement secure Microsoft Azure cloud solutions supporting DoD mission requirements, including green-field environments and hybrid architectures integrating on-premises infrastructure. Engineer enterprise hybrid identity solutions using Microsoft Entra ID and Active Directory, while configuring authentication, authorization, and privileged access management aligned with Zero Trust principles. Design Azure Landing Zones, governance frameworks, and IaC solutions using Terraform or Bicep, alongside secure networking and monitoring capabilities. Collaborate with cybersecurity and systems engineering teams to deliver integrated cloud solutions, support Authority to Operate activities, and produce comprehensive architecture documentation. Maintain Active Top Secret clearance with SCI eligibility and hold Microsoft Certified: Azure Solutions Architect Expert certification. Located in Fort Belvoir, VA or Albuquerque, NM.
Required Qualifications
- Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical discipline and 12 – 15 years of prior relevant experience or Masters with 10 – 13 years of prior relevant experience. May possess a Doctorate in technical domain. Specific experience, education and training may be considered in lieu of degree.
- Active Top Secret security clearance with eligibility for access to Sensitive Compartmented Information (SCI).
- Current DoD 8570/8140 IAT Level II certification.
- Microsoft Certified: Azure Solutions Architect Expert certification.
- Minimum of five years of experience designing and implementing Microsoft Azure enterprise cloud solutions.
- Demonstrated experience architecting hybrid Azure environments integrating enterprise on-premises infrastructure with Azure cloud services.
- Advanced experience with Microsoft Entra ID, Microsoft Entra Connect, Active Directory, AWS IAM, hybrid identity synchronization, federation, and enterprise identity management with enterprise Identity, Credential, and Access Management (E-ICAM) solutions.
- Entra Conditional Access
- Policy Information Points and Policy Engines
- Access Reviews
- Entitlement Management
- Lifecycle Workflows
- Identity lifecycle automation
- Experience implementing Azure Landing Zones and enterprise governance models.
- Strong understanding of Azure networking, storage, compute, governance, and security services.
- Experience with Infrastructure as Code utilizing Terraform, Azure Bicep, ARM Templates, or similar technologies.
- Experience with Azure CLI, PowerShell, and scripting using Python or comparable automation languages.
- Strong understanding of Zero Trust architecture, identity-centric security, and cloud security best practices.
- Excellent written and verbal communication skills.
Desired Qualifications
- AWS Certified Solutions Architect – Professional certification.
- Experience integrating Azure and AWS within hybrid multi-cloud enterprise environments.
- Familiarity with the Department of Defense Joint Warfighting Cloud Capability (JWCC) and DoD Joint Tenant cloud environments.
- Understanding of the DoD Enterprise Cloud Strategy and cloud modernization initiatives.
- Familiarity with the Department of Defense Enterprise Identity, Credential, and Access Management (E-ICAM) architecture and its role in enterprise identity federation, identity governance, Zero Trust implementation, and secure access to DoD cloud environments.
- Experience with Azure Arc, Azure Stack HCI, Azure Local, and hybrid cloud management technologies.
- Experience with Azure Kubernetes Service (AKS) and cloud-native container platforms.
- Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Intune, and Microsoft Purview.
- Experience implementing DevSecOps pipelines using Azure DevOps and/or GitHub Enterprise.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.