
Cloud Systems Engineer
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in United States.
• Oversee and sustain AWS and Azure environments, which encompass virtual machines, networking, and storage.
• Deploy, maintain, and enhance AWS EC2, RDS, S3, IAM, KMS, Secrets Manager, CloudTrail, VPCs, subnets, routing tables, security groups, and NACLs.
• Manage Azure virtual machines, virtual networks and NSGs, storage accounts, Azure Files, Key Vault, Azure Virtual Desktop, and Site Recovery.
• Create and oversee hardened VM images and golden images.
• Implement and support configurations for high availability, auto-scaling, backup, and disaster recovery.
• Support governance structures involving multiple accounts and subscriptions.
• Take ownership of the Microsoft 365 tenant, comprising Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and licensing.
• Administer Conditional Access, MFA, RBAC, least privilege, privileged access, hybrid identity, application registrations, and role assignments.
• Manage user provisioning, onboarding, role changes, offboarding, and access reviews.
• Oversee endpoint compliance, configuration profiles, patching, and device lifecycle management through Intune.
• Administer SAML and SCIM integrations between Entra ID and SaaS platforms.
• Facilitate data governance utilizing Purview, sensitivity labels, and DLP policies.
• Design and maintain Terraform infrastructure across both AWS and Azure.
• Construct reusable baseline modules for networking, IAM, logging, monitoring, and encryption.
• Automate workflows through PowerShell, Bash, Python, and Microsoft Graph API.
• Integrate provisioning and security controls into CI/CD pipelines while maintaining version-controlled repositories.
• Implement drift detection, remediation, and policy-as-code guardrails.
• Apply CIS Benchmarks and DISA STIGs across Linux, Windows, and cloud tenants.
• Configure and monitor CloudTrail, GuardDuty, Security Hub, Config, Microsoft Defender, and Entra ID logging.
• Assist with SIEM integration and incident response support.
• Maintain vulnerability management through patching, remediation tracking, and reporting.
• Support compliance with NIST SP 800-171, CMMC, FedRAMP, or SOC 2, including evidence collection for assessments.
• Administer Anthropic Claude, ChatGPT, AWS Bedrock, and Microsoft 365 Copilot platforms.
• Enforce standards for data utilized in AI tools, especially concerning CUI or controlled data.
• Collaborate with engineering, security, and operations teams.
• Maintain architecture diagrams, runbooks, SOPs, and audit evidence.
• Contribute to capacity forecasting, resource planning, and cloud cost management.
• 5+ years of experience in systems administration, cloud operations, or infrastructure engineering.
• 3+ years of hands-on experience administering AWS in a production setting, including virtual machine management, networking, and IAM.
• 2+ years of administering a Microsoft 365 tenant with actual admin rights — Entra ID, Exchange Online, Conditional Access, licensing, and user lifecycle management.
• Practical experience with Microsoft Azure administration in a production environment.
• Proven ability to automate operational workflows using PowerShell, Bash, or Python; experience with Terraform.
• Strong understanding of IAM, encryption (KMS, TLS), and network segmentation.
• Experience with Linux (RHEL or Amazon Linux) and Windows Server in a cloud context.
• Familiarity with working in Department of Defense or Department of War environments and applying their security requirements.
• Systematic documentation practices — maintaining runbooks, SOPs, and configuration records as standard procedure.
• US Citizenship Required. All work must be performed within the United States.
• Preferred: Experience with Microsoft 365 GCC High tenant.
• Preferred: In-depth knowledge of Terraform including modular design, state management, and leading IaC migrations from legacy tools.
• Preferred: Experience with container platforms — Docker using ECS, EKS, or AKS.
• Preferred: AWS certifications or Azure equivalents, Microsoft 365 Administrator (MS-102), and CompTIA Security+.
• Preferred: Familiarity with AWS Control Tower, Landing Zones, or Azure Landing Zone governance tools.
• Preferred: Experience with SIEM platforms (Splunk, Microsoft Sentinel).
• Preferred: Administration of AI platforms at the tenant or account level.
• Preferred: Background in managed service providers managing multiple client tenants.
• Preferred: Experience in regulated industries.
• Preferred: Active DoD security clearance (Secret or above), or eligibility to obtain and maintain one.
• Competitive salary, along with bonus and equity package.
• 100% employer-covered, comprehensive health insurance that includes medical, dental, and vision for you and your family.
• Unlimited PTO, subject to manager's approval.
• Flexible work environment that allows you to manage your workday.
• 14 weeks of fully-paid parental leave.
• Career track opportunities with the potential for rapid advancement based on strong performance as the firm grows.
• Opportunities for professional development and ongoing learning.
• Optional 401K, FSA, and equity incentives available.
• Mental health benefits provided through Tara Mind.
• Cost-effective GLP-1 solutions available through Crux.
Salve.Inno
General Dynamics Information Technology
Seismic
Get handpicked remote jobs straight to your inbox weekly.