
Cloud Systems Engineer
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in Virginia.
• Administer and oversee AWS and Azure environments, encompassing virtual machines, networking, and storage.
• Deploy, maintain, and optimize AWS services such as EC2, RDS, S3, IAM, KMS, Secrets Manager, and CloudTrail.
• Manage AWS VPCs, subnets, routing tables, security groups, and NACLs effectively.
• Administer Azure virtual machines, virtual networks, NSGs, storage accounts, Azure Files, Key Vault, Azure Virtual Desktop, and Site Recovery.
• Create and manage hardened VM images and baseline images.
• Implement and support configurations for high availability, auto-scaling, backup, and disaster recovery.
• Support governance structures for multi-account and multi-subscription environments.
• Own the Microsoft 365 tenant, which includes Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and licensing management.
• Administer Conditional Access, MFA, RBAC, least privilege, privileged access, hybrid identity, application registrations, and role assignments.
• Manage the complete user lifecycle: provisioning, onboarding, role changes, offboarding, and access reviews.
• Oversee endpoint compliance, configuration profiles, patching, and device lifecycle through Intune.
• Administer SAML and SCIM single sign-on and provisioning integrations.
• Support data governance initiatives using Purview, sensitivity labels, and DLP policies.
• Design and maintain Terraform infrastructure across AWS and Azure platforms.
• Develop reusable secure baseline modules for networking, IAM, logging, monitoring, and encryption.
• Automate workflows utilizing PowerShell, Bash, Python, and Microsoft Graph API.
• Integrate provisioning and security controls into CI/CD pipelines while maintaining version-controlled infrastructure repositories.
• Implement drift detection, remediation processes, and policy-as-code guardrails.
• Apply CIS Benchmarks and DISA STIG hardening baselines for Linux, Windows, and cloud tenants.
• Configure and monitor logging for CloudTrail, GuardDuty, Security Hub, Config, Microsoft Defender, and Entra ID.
• Support SIEM integration and incident response activities.
• Maintain vulnerability management through patching, remediation tracking, and reporting.
• Support compliance aligned with NIST SP 800-171, CMMC, and FedRAMP or SOC 2, including the collection of assessment evidence.
• Administer platforms such as Anthropic Claude, ChatGPT, AWS Bedrock, and Microsoft 365 Copilot.
• Enforce standards for data usage within AI tools, particularly concerning CUI or controlled data.
• Collaborate with engineering, security, and operations teams to deliver reliable and scalable services.
• Produce and maintain architecture diagrams, runbooks, SOPs, and audit evidence artifacts.
• Contribute to capacity forecasting, resource planning, and cloud cost management.
• 5+ years of experience in systems administration, cloud operations, or infrastructure engineering.
• 3+ years of hands-on experience administering AWS in a production environment, including virtual machine management, networking, and IAM.
• 2+ years of experience in administering a Microsoft 365 tenant with real admin rights, including Entra ID, Exchange Online, Conditional Access, licensing, and user lifecycle management.
• Proven hands-on experience with Microsoft Azure administration in a production setting.
• Demonstrated ability to automate operational workflows using PowerShell, Bash, or Python, along with working experience in Terraform.
• Strong knowledge of IAM, encryption methods (KMS, TLS), and network segmentation.
• Experience with Linux (RHEL or Amazon Linux) and Windows Server in a cloud context.
• Experience in Department of Defense or Department of War environments, with the ability to apply their security requirements.
• Disciplined documentation practices, ensuring runbooks, SOPs, and configuration records are consistently maintained.
• US Citizenship is required.
• All work must be conducted within the United States.
• Preferred: Experience with Microsoft 365 GCC High tenants.
• Preferred: Depth of knowledge in Terraform, including modular design, state management, and leading IaC migrations from legacy tools.
• Preferred: Experience with container platforms, such as Docker with ECS, EKS, or AKS.
• Preferred: AWS certifications or equivalent Azure certifications, Microsoft 365 Administrator (MS-102), or CompTIA Security+.
• Preferred: Familiarity with AWS Control Tower, Landing Zones, or Azure Landing Zone governance tools.
• Preferred: Experience with SIEM platforms (Splunk, Microsoft Sentinel).
• Preferred: Administration of AI platforms at the tenant or account level.
• Preferred: Background in managed service provider roles, administering across multiple client tenants.
• Preferred: Experience in regulated industries such as defense, healthcare, or financial services.
• Preferred: Active DoD security clearance (Secret or above), or eligibility to obtain and maintain one.
• A fully remote, results-oriented work environment.
• Competitive salary, along with bonus and equity packages.
• Comprehensive health insurance, including medical, dental, and vision, fully covered by the employer for you and your family.
• Unlimited paid time off (PTO), subject to your manager's approval.
• Flexible work environment that allows you to manage your workday.
• 14 weeks of fully-paid parental leave.
LouisianaNOW.Jobs
Nuvei
Salve.Inno
Get handpicked remote jobs straight to your inbox weekly.