Systems Engineer Azure Identity
Sarela Technology Solutions · Fort Belvoir, VA · 2 wk ago
On-siteInformation TechnologyFull-time
About the role
SarelaTech is seeking a highly skilled Hybrid Multi-Cloud Engineer SME to support mission-critical Department of Defense (DoD) cloud modernization initiatives in Fort Belvoir, VA or Albuquerque, New Mexico. This position will serve as a senior technical contributor responsible for designing, engineering, implementing, and sustaining secure Microsoft Azure cloud solutions within classified enterprise environments.
Responsibilities
- Architect, design, engineer, and implement secure Microsoft Azure cloud solutions supporting DoD mission requirements.
- Design and deploy green-field Azure environments and hybrid cloud architectures integrating on-premises infrastructure with Azure services.
- Design, implement, and maintain enterprise hybrid identity solutions utilizing Microsoft Entra ID, Microsoft Entra Connect, Active Directory, and related identity technologies.
- Engineer secure authentication, authorization, identity governance, and privileged access management (PAM) solutions supporting just-in-time (JIT) access, attribute- and role- based access controls (ABAC/RBAC) and similar Zero Trust principles and objectives.
- Design Azure Landing Zones, governance frameworks, subscription architectures, and management group strategies following Microsoft Cloud Adoption Framework (CAF) and Azure Well-Architected Framework guidance.
- Engineer Infrastructure as Code (IaC) solutions using Bicep, ARM Templates, Terraform, or comparable automation technologies.
- Design secure Azure networking solutions utilizing Virtual Networks, ExpressRoute, VPN Gateway, Azure Firewall, Virtual WAN, and private connectivity services.
- Implement Azure-native monitoring, backup, disaster recovery, governance, and security capabilities.
- Configure and administer Microsoft Entra ID Governance capabilities, including Access Reviews, Entitlement Management, Lifecycle Workflows, Conditional Access, and Privileged Identity Management (PIM).
- Collaborate with cybersecurity, systems engineering, networking, and application development teams to deliver integrated cloud solutions.
- Support Authority to Operate (ATO) activities and ensure compliance with DoD cybersecurity policies, Risk Management Framework (RMF), and applicable Security Technical Implementation Guides (STIGs).
- Produce architecture documentation, engineering diagrams, implementation guides, standard operating procedures, and technical documentation.
- Troubleshoot and resolve complex cloud infrastructure, networking, identity, and security issues.
- Evaluate emerging Microsoft cloud technologies and recommend technical solutions supporting customer mission objectives.
Qualifications
- Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical discipline and 12 – 15 years of prior relevant experience or Masters with 10 – 13 years of prior relevant experience.
- Active Top Secret security clearance with eligibility for access to Sensitive Compartmented Information (SCI).
- Current DoD 8570/8140 IAT Level II certification.
- Microsoft Certified: Azure Solutions Architect Expert certification.
- Minimum of five years of experience designing and implementing Microsoft Azure enterprise cloud solutions.
- Demonstrated experience architecting hybrid Azure environments integrating enterprise on-premises infrastructure with Azure cloud services.
- Advanced experience with Microsoft Entra ID, Microsoft Entra Connect, Active Directory, AWS IAM, hybrid identity synchronization, federation, and enterprise identity management with enterprise Identity, Credential, and Access Management (E-ICAM) solutions.
- Experience implementing Microsoft Entra ID Governance capabilities, including Entra Conditional Access, Policy Information Points and Policy Engines, Access Reviews, Entitlement Management, Lifecycle Workflows, and identity lifecycle automation.
- Experience implementing Azure Landing Zones and enterprise governance models.
- Strong understanding of Azure networking, storage, compute, governance, and security services.
- Experience with Infrastructure as Code utilizing Terraform, Azure Bicep, ARM Templates, or similar technologies.
- Experience with Azure CLI, PowerShell, and scripting using Python or comparable automation languages.
- Strong understanding of Zero Trust architecture, identity-centric security, and cloud security best practices.
- Excellent written and verbal communication skills.
Desired Qualifications
- AWS Certified Solutions Architect – Professional certification.
- Experience integrating Azure and AWS within hybrid multi-cloud enterprise environments.
- Familiarity with the Department of Defense Joint Warfighting Cloud Capability (JWCC) and DoD Joint Tenant cloud environments.
- Understanding of the DoD Enterprise Cloud Strategy and cloud modernization initiatives.
- Familiarity with the Department of Defense Enterprise Identity, Credential, and Access Management (E-ICAM) architecture and its role in enterprise identity federation, identity governance, Zero Trust implementation, and secure access to DoD cloud environments.
- Experience with Azure Arc, Azure Stack HCI, Azure Local, and hybrid cloud management technologies.
- Experience with Azure Kubernetes Service (AKS) and cloud-native container platforms.
- Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Intune, and Microsoft Purview.
- Experience implementing DevSecOps pipelines using Azure DevOps and/or GitHub Enterprise.
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Profit sharing
- Training & development
- Tuition assistance
- Vision insurance