
Senior Cloud Engineer, Azure Government
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Design and construct the Azure Government environment for M-Files’ federal solutions.
• Develop and manage infrastructure as code and deployment pipelines, ensuring every environmental change is versioned, reviewed, and redeployed.
• Implement the security architecture, which includes Microsoft Sentinel integration and log routing, Defender for Cloud, and enforcing hardened STIG/CIS node and container baselines, along with FIPS-mode configuration across both Windows and Linux systems.
• Collaborate with the product team to establish customer-managed key infrastructure.
• Create the machine-readable evidence pipeline necessary for FedRAMP 20x compliance.
• Engage daily with advisory partner engineers to deploy endpoint security measures.
• Define operational runbooks that cover federal-timeframe patching, monthly authenticated scanning, backup and restore testing, break-glass access, and the on-call rotation.
• Take the lead on the on-call rotation as the team develops.
• Demonstrate controls during third-party assessments, provide evidence upon request, and address any findings.
• Deploy the environment from code in Azure Government in alignment with the approved reference architecture.
• Establish steady-state operations with well-documented runbooks and an effective on-call rotation.
• 7+ years of experience in cloud infrastructure or platform engineering, with a minimum of 3 years spent working hands-on in Azure at a production scale.
• Azure Government experience is highly preferred.
• Extensive experience with Terraform and a strong belief in infrastructure as code, emphasizing that it should be reviewed and redeployed rather than hand-edited.
• Production experience with Kubernetes (preferably AKS), including Windows node pools and containerized .NET workloads.
• Familiarity with Azure security services: Sentinel, Defender for Cloud, Key Vault, Azure Policy, Private Link, Entra ID, and managed identities.
• Experience in building or managing environments under FedRAMP, DoD CC SRG, StateRAMP/GovRAMP, or a comparable regulated framework (e.g., PCI, ISO 27001, SOC 2).
• Knowledge of FIPS 140 and STIG hardening practices.
• Ability to clearly explain a technical control to a non-engineer assessor without ambiguity.
• U.S. person status (U.S. citizen or lawful permanent resident) and capacity to work from within the United States; visa sponsorship is not available.
• Completion of pre-employment background checks and identity verification compliant with NIST SP 800-63A Identity Assurance Level 2.
• Annual acknowledgment of federal environment Rules of Behavior and completion of role-based security training.
• Involvement in the annual incident-response exercise.
• Willingness to participate in an on-call rotation or provide coverage during U.S. business hours.
• Preferably, experience with FedRAMP 20x or OSCAL/machine-readable compliance.
• Azure Security Engineer (AZ-500) or Azure Solutions Architect certification is preferred.
• Experience in migrating commercial SaaS into a sovereign or government cloud is preferred.
• Flexible work/life balance through remote work options.
• 10 paid holidays each year.
• Unlimited PTO.
• Matching 401K Plan (25% of employee's contribution up to the IRS maximum).
• Health insurance (options for PPO and HDHP/HSA plans).
• Dental insurance.
• Vision insurance.
• Life insurance (equivalent to 1x employee salary).
• Short-term disability coverage (paid by employer).
• Long-term disability coverage (paid by employer).
• Flexible Spending Plan (for medical and dependent expenses).
ComPsych
Robert Half
adconova GmbH
Airbnb
Get handpicked remote jobs straight to your inbox weekly.