Cloud Administrator

Knox Systems

Arlington (VA)

On-site

USD 95,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision
Life & Disability Insurance
Unlimited PTO
401k plan

Job summary

Knox Systems is seeking a Cloud Administrator to secure, build, and operate multi-cloud infrastructure across AWS, Azure, and GCP, including government regions. The role covers IAM, network segmentation, encryption, and policy-driven hardening to IL5, with scripting and IaC to ensure repeatable environments and audit-ready documentation.

You will also support on-prem employee infrastructure, manage collaboration tools, and serve as the final escalation point for the help desk. U.S.

Qualifications

  • 5+ years hands-on experience administering cloud infrastructure in at least two of AWS, Azure, and GCP
  • Experience operating in government cloud environments (e.g., AWS GovCloud, Azure Government, Google Cloud Assured Workloads)
  • Expertise in cloud IAM (SSO, MFA, least privilege, access reviews)
  • Experience designing secure cloud networks (VPCs/VNets, private connectivity) and managing encryption with FIPS 140 services
  • Experience hardening systems to DISA STIGs and CIS Benchmarks; drift monitoring with AWS Config/Azure Policy/GCP Security Command Center
  • Knowledge of FedRAMP, NIST SP 800-53/171, CMMC, and DoD Cloud SRG IL5 requirements
  • Scripting (PowerShell Bash Python) and IaC (Terraform CloudFormation Bicep) experience
  • Experience integrating cloud logs with SIEM and supporting incident response
  • Ability to produce audit-ready documentation (SSP, runbooks, diagrams)
  • US citizenship with ability to obtain Secret clearance

Responsibilities

  • Manage IAM across AWS, Entra ID for Azure, and GCP IAM with SSO and MFA
  • Design secure networks with VPCs/VNets and private connections; manage encryption keys
  • Harden systems to DISA STIGs and CIS Benchmarks; monitor config drift
  • Operate within FedRAMP, NIST SP 800-53/171, CMMC, and DoD IL5 requirements
  • Build and run multi-provider infrastructure including government regions
  • Automate with PowerShell Bash Python and IaC tools (Terraform/CloudFormation/Bicep)
  • Forward cloud logs to SIEM; support incident response
  • Provide audit-ready documentation (SSP, runbooks, diagrams) during audits
  • Support on-prem employee infrastructure and office collaboration apps
  • Manage user provisioning, licensing, security settings, and end-user support
  • Resolve cross-system and cross-provider issues; act as escalation point

Skills

Cloud platforms
IAM / IdP
Infrastructure as Code
Networking security
Scripting (PowerShell Bash Python)
Compliance & audit
Incident response
Documentation
DoD/FedRAMP knowledge
Troubleshooting

Education

Security+ or equivalent (DoD8140)
Bachelor's degree in CS/IS/Cybersecurity or equivalent

Tools

AWS IAM
Azure Entra ID
GCP IAM
Terraform
AWS CloudFormation
Azure Bicep

Job description

About Knox

Knox runs the largest Federal & DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

The Role

Knox is seeking a Cloud Administrator which secures, builds, and operates multi-cloud infrastructure across AWS, Microsoft Azure, and Google Cloud Platform, including their government regions (AWS GovCloud (US), Azure Government, and Google Cloud Assured Workloads). The role manages identity and access, designs segmented and encrypted networks, and keeps systems hardened to DISA STIGs and CIS Benchmarks within FedRAMP, NIST SP 800-53 and SP 800-171, CMMC, and DoD Impact Level requirements up to IL5. Using scripting and Infrastructure as Code, the Cloud Administrator makes environments repeatable and changes reviewable, feeds cloud logs to the SIEM, and supports incident response. As the final escalation point for the help desk, this person troubleshoots complex cross-platform problems and maintains audit-ready documentation that supports continuous monitoring and POA&M evidence.

In addition to the cloud environment, this role supports Knox's on-premises employee infrastructure across multiple office sites, including employee workstations, local networks, printers, and conference room equipment. The administrator manages the office collaboration software that employees use every day, including email, calendars, file sharing, chat, and video meetings, and handles account setup, licensing, security settings, and user support. They keep workstations patched, hardened, and enrolled in endpoint management and protection tools at every site, and they resolve problems that reach them from the help desk.

Key Responsibilities
  • Manages identity and access in AWS (Amazon Web Services) IAM (Identity and Access Management), Microsoft Entra ID for Azure, and GCP (Google Cloud Platform) IAM: single sign-on, multi-factor authentication, least privilege, privileged account control, and regular access reviews.
  • Designs secure networks and manages encryption: segmentation with AWS and GCP Virtual Private Clouds and Azure Virtual Networks, private connections such as AWS Direct Connect and Azure ExpressRoute, boundary controls, and encryption keys in AWS KMS (Key Management Service), Azure Key Vault, and Google Cloud KMS using FIPS (Federal Information Processing Standards) 140 validated modules.
  • Keeps systems at a known secure baseline: hardens to DISA STIGs (Defense Information Systems Agency Security Technical Implementation Guides) and CIS (Center for Internet Security) Benchmarks, catches drift with AWS Config, Azure Policy, and GCP Security Command Center, and patches by risk with evidence of what was fixed and what was accepted as an exception.
  • Operates within FedRAMP (Federal Risk and Authorization Management Program), NIST (National Institute of Standards and Technology) SP 800-53 and SP 800-171, CMMC (Cybersecurity Maturity Model Certification), and the DoD (Department of Defense) Cloud Computing Security Requirements Guide Impact Levels, including IL5.
  • Builds and runs infrastructure across all three providers, including the government regions: AWS GovCloud (US), Azure Government, and Google Cloud Assured Workloads.
  • Automates with scripting (PowerShell, Bash, Python) and Infrastructure as Code tools such as Terraform, AWS CloudFormation, and Azure Bicep, so environments are repeatable and changes are reviewed.
  • Sends logs from AWS CloudTrail, Azure Monitor, and GCP Cloud Logging to the SIEM (Security Information and Event Management) system, and supports security during incident response.
  • Troubleshoots hard problems that cross systems and providers, works methodically under pressure, and serves as the final escalation point for the help desk.
  • Keeps documentation that holds up in audits: System Security Plans, runbooks, diagrams, and change records that serve as continuous monitoring and POA&M (Plan of Action and Milestones) evidence.
  • Supports Knox’s on premises employee infrastructure across multiple office sites, including employee workstations, local networks, printers, and conference room equipment.
  • Manages the office collaboration software employees use every day, including email, calendars, file sharing, chat, and video meetings and handles account set-up, licensing, security settings, and user support.
  • Keeps workstations at every site patched, hardened, and enrolled in endpoint management and protection tools.
  • Resolves on-premises and collaboration issues escalated from the help desk. Troubleshoots hard problems that cross systems, providers and office sites. Works methodically under pressure, and serves as the final escalation point for the help desk.
Qualifications
  • 5+ years of hands‑on experience administering cloud infrastructure, with production experience in at least two of AWS, Azure, and GCP and working knowledge of the third.
  • Experience operating in government cloud environments such as AWS GovCloud (US), Azure Government, or Google Cloud Assured Workloads.
  • Demonstrated expertise in cloud identity and access management (AWS IAM, Microsoft Entra ID, GCP IAM), including SSO, MFA, least privilege, privileged access controls, and access reviews.
  • Experience designing and securing cloud networks (VPCs, VNets, segmentation, private connectivity like Direct Connect or ExpressRoute) and managing encryption keys with FIPS 140 validated services.
  • Practical experience hardening systems to DISA STIGs and CIS Benchmarks and monitoring configuration drift with AWS Config, Azure Policy, or GCP Security Command Center.
  • Working knowledge of FedRAMP, NIST SP 800‑53, NIST SP 800‑171, CMMC, and the DoD Cloud Computing SRG, including the requirements of IL5.
  • Proficiency in scripting with PowerShell, Bash, and Python, and in Infrastructure as Code using Terraform, CloudFormation, or Bicep.
  • Experience integrating cloud logging (CloudTrail, Azure Monitor, Cloud Logging) with a SIEM and supporting incident response activities.
  • Strong troubleshooting skills across systems and providers, with the ability to work methodically under pressure as a senior escalation point.
  • Ability to produce clear, audit‑ready documentation, including System Security Plans, runbooks, network diagrams, and change records.
  • DoD 8140 (formerly 8570) compliant baseline certification, such as CompTIA Security+ or equivalent.
  • U.S. citizenship and an active Secret clearance, or the ability to obtain one.
Preferred Qualifications
  • Cloud certifications such as AWS Certified Security – Specialty or SysOps Administrator, Microsoft Certified: Azure Administrator Associate (AZ‑104) or Azure Security Engineer (AZ‑500), and Google Professional Cloud Security Engineer.
  • Advanced security certifications such as CISSP or CCSP.
  • Experience supporting a FedRAMP authorization, CMMC assessment, or DoD ATO (Authority to Operate) from preparation through continuous monitoring.
  • Experience with CI/CD pipelines and policy‑as‑code tools for automated compliance checks.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent experience.
Compensation Range: $95k-110k, variable annual bonus, and equity
Benefits & Perks

Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PTO, and an employee funded 401k plan. Please note, benefits are subject to change.

We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.

Knox is proud to support veteran hiring — we encourage veterans and transitioning service members to apply and welcome the unique skills and experience you bring.

Hiring Requirement:

Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Any offer of employment is contingent upon the successful completion of all required pre‑employment screenings, including a background check, in accordance with applicable laws and government contract requirements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sec Dev Ops Engineer - Level 3
Sec Dev Ops Engineer - Level 3

Knox Systems • Arlington (VA)

On-site
USD 155,000 - 185,000
Medical insurance
Dental Insurance
Vision Insurance
+4
Sec Dev Ops Engineer - Level 3
Sec Dev Ops Engineer - Level 3

Benchstrength • Arlington (VA)

On-site
USD 155,000 - 185,000
Medical, Dental, Vision
Unlimited PTO
401k plan
Sec Dev Ops Engineer - Level 3
Sec Dev Ops Engineer - Level 3

Knox Systems • United States

On-site
USD 155,000 - 185,000
Medical Insurance
Dental Insurance
Vision Insurance
+3
Compliance Analyst - Cloud Security
Compliance Analyst - Cloud Security

Knox Systems • Arlington (VA)

On-site
USD 100,000 - 115,000
Medical benefits
Dental benefits
Vision benefits
+3
Senior Compliance Analyst - Cloud Security
Senior Compliance Analyst - Cloud Security

Knox Systems • Arlington (VA)

On-site
USD 135,000 - 165,000
Medical Insurance
Dental Insurance
Vision Insurance
+3
Senior Compliance Analyst - Cloud Security
Senior Compliance Analyst - Cloud Security

Knox Systems • United States

On-site
USD 135,000 - 165,000
Medical
Dental
Vision
+3
Technical Account Manager II (Fed Ramp)
Technical Account Manager II (Fed Ramp)

Knox Systems • United States

Hybrid
USD 130,000 - 150,000
Medical
Dental
Vision
+3
Technical Account Manager II (Fed Ramp)
Technical Account Manager II (Fed Ramp)

Knox Systems • Arlington (VA)

Hybrid
USD 130,000 - 150,000
Medical, Dental, Vision
Life & Disability
Unlimited PTO
+2
Technical Account Manager I (Fed Ramp)
Technical Account Manager I (Fed Ramp)

Knox Systems • Arlington (VA)

On-site
USD 110,000 - 130,000
Medical, Dental, Vision
Life & Disability
Unlimited PTO
+1
Technical Account Manager I (Fed Ramp)
Technical Account Manager I (Fed Ramp)

Benchstrength • Arlington (VA)

Hybrid
USD 110,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+4