
Cloud Infrastructure, Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design, implement, manage, and enhance secure, scalable, resilient, and supportable Microsoft Azure infrastructure across both corporate and program-specific environments.
• Oversee Azure computing resources, including virtual machines, virtual networks, storage, cloud identity services, firewalls, VPN connectivity, load balancing, backup services, and monitoring solutions.
• Configure and maintain Azure subscriptions, resource groups, networking, identity integration, access controls, and platform services.
• Administer and integrate Microsoft Entra ID, Microsoft 365, endpoint management, and other enterprise services into the Azure infrastructure.
• Implement and sustain Infrastructure as Code solutions utilizing Terraform, Azure Bicep, or ARM templates.
• Execute cloud resource provisioning, configuration management, patching, upgrading, monitoring, troubleshooting, backup validation, and capacity planning.
• Create scripts, automation, and repeatable processes using PowerShell, Python, or similar technologies.
• Establish and maintain cloud backup, disaster recovery, business continuity, and Continuity of Operations capabilities.
• Configure and oversee Azure monitoring, logging, and alerting solutions.
• Assess Azure resource utilization, performance, security, reliability, and costs, and propose enhancements.
• Maintain documentation for cloud architecture, system inventories, network and data-flow diagrams, configuration records, operating procedures, and infrastructure deployment.
• Design, implement, manage, evaluate, and document cybersecurity controls across Microsoft Azure infrastructure and hosted environments.
• Lead and support technical RMF activities throughout the system lifecycle, including the implementation, assessment, authorization, and continuous monitoring of security controls.
• Develop, maintain, and coordinate ATO packages and supporting cybersecurity documentation, including SSPs, control implementation statements, diagrams, configuration evidence, POA&Ms, and related security artifacts.
• Collaborate with cybersecurity personnel, system owners, government stakeholders, and assessors to prepare systems for authorization and address assessment findings.
• Implement and document security controls in accordance with NIST SP 800-53, NIST SP 800-171, DoD RMF, and other relevant federal cybersecurity frameworks.
• Establish and maintain Azure security configurations, identity and access controls, multifactor authentication, RBAC, least-privilege access, network segmentation, encryption, and secure configuration baselines.
• Configure and manage Microsoft Entra ID, Microsoft Defender for Cloud, Azure Policy, and similar security technologies.
• Conduct system hardening and manage vulnerability identification, prioritization, remediation, validation, and reporting.
• Review security scans, alerts, logs, and configuration findings; investigate potential security issues and assist in incident response and remediation.
• Maintain audit-ready technical documentation and continuous monitoring evidence.
• Coordinate security assessments, penetration testing, tabletop exercises, internal audits, and customer or third-party reviews.
• Support secure storage, processing, and transmission of CUI, PII, and other sensitive data.
• Evaluate proposed Azure services, infrastructure changes, and integrations for their security, compliance, operational, and architectural implications.
• Collaborate with software engineering, DevOps, and cybersecurity teams to design and sustain Azure environments that support application development, testing, deployment, and production operations.
• Assist in integrating infrastructure provisioning, configuration management, security validation, and monitoring into CI/CD pipelines and automated deployment workflows.
• Gather and analyze operational, business, cybersecurity, and technical requirements, translating them into Azure infrastructure and security solutions.
• Coordinate with cybersecurity personnel and program stakeholders to align infrastructure designs, deployments, and system changes with RMF and ATO requirements.
• Assess Azure technologies, platform services, and architectural strategies to enhance reliability, scalability, security, maintainability, and cost-effectiveness.
• Collaborate with internal departments, government customers, vendors, and external service providers regarding cloud infrastructure needs, system changes, technical challenges, and compliance activities.
• Communicate technical risks, operational constraints, architectural suggestions, and alternative solutions to both technical and non-technical stakeholders.
• Extensive knowledge of Microsoft Azure infrastructure, cloud computing, systems administration, cloud networking, identity and access management, vulnerability management, and cybersecurity principles.
• Proficient understanding of Azure compute, networking, storage, identity services, logging and monitoring, backup, virtualization, firewalls, VPN technologies, and endpoint security.
• Strong grasp of federal cybersecurity requirements, particularly DoD RMF, NIST security controls, and the ATO lifecycle.
• Capability to develop, maintain, and organize accurate, complete, and audit-ready ATO documentation and technical security evidence.
• Experience with PowerShell, Python, or similar scripting and automation technologies.
• Familiarity with Infrastructure as Code, configuration management, and DevSecOps practices.
• Bachelor’s degree in computer science, information technology, cybersecurity, engineering, or a related field.
• Seven or more years of progressively responsible experience in cloud infrastructure, systems engineering, cloud administration, cybersecurity engineering, or a closely related domain.
• Significant hands-on experience in deploying and managing Microsoft Azure environments.
• Proven experience in designing, implementing, administering, and securing production infrastructure within Microsoft Azure.
• Strong working knowledge of Azure infrastructure services, including virtual machines, virtual networking, storage, identity and access management, network security, monitoring, backup, and disaster recovery.
• Hands-on experience with Microsoft Entra ID, including identity management, authentication, access controls, and integration with Azure infrastructure.
• Experience implementing and maintaining infrastructure through automated deployment or Infrastructure as Code technologies, such as Terraform, Azure Bicep, or ARM templates.
• Experience in developing scripts or automated workflows using PowerShell, Python, or similar technologies.
• Experience in implementing or assessing technical security controls under NIST SP 800-53, NIST SP 800-171, RMF, CMMC, FedRAMP, FISMA, or comparable federal cybersecurity standards.
• Proven experience directly supporting RMF and ATO activities, including developing or maintaining security documentation, technical control implementation statements, assessment evidence, POA&Ms, and other authorization-related artifacts.
• Strong troubleshooting, technical documentation, communication, and stakeholder engagement skills.
• United States citizenship.
• Current CompTIA Security+ (or higher) certification at the time of hire.
• Ability to obtain and maintain a government security clearance and meet applicable DoD 8140 qualification requirements.
• Willingness to support occasional maintenance, incident response, or system restoration activities beyond normal business hours.
• 100% employee ownership through our ESOP.
• Comprehensive medical, dental, and vision coverage.
• Generous PTO policy with 11 paid holidays each year.
• Paid family leave.
• 401(k) retirement plan.
• Monthly reimbursement for high-speed internet.
• Fully remote work with flexible scheduling.
• Sponsored professional development and training opportunities.
• A fun and inclusive culture with regular virtual team events.
LouisianaNOW.Jobs
Nuvei
Salve.Inno
Get handpicked remote jobs straight to your inbox weekly.