Cloud Security Architect (GCC High)

Two Five

Washington (District of Columbia)

On-site

USD 180,000 - 240,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Two Five Solutions seeks a senior cloud security architect to own GCC High and Azure Government environments. You will be the final technical authority for DIB clients, translating controls into configurations and producing assessment evidence.

Role emphasizes hands-on delivery, not policy writing or Tier 1 support, with responsibilities spanning design, implementation, and runbook creation for compliant CUI boundaries.

Qualifications

  • : 5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering role.
  • : Hands-on GCC High experience with feature availability, licensing, tenant configuration, and external collaboration
  • : Entra ID: Conditional Access policy design, Privileged Identity Management, identity lifecycle
  • : Intune/Autopilot: device enrollment, configuration profiles, compliance policies
  • : Defender/Sentinel: data connectors, analytics rules, alert triage, basic KQL
  • : Azure infrastructure: subscriptions, management groups, RBAC, VNet, NSG
  • : Knowledge of NIST SP 800-171 at the control level
  • : Clear written communication for clients and assessors

Responsibilities

  • Provide final technical authority across DIB client base for GCC High environments
  • Lead POA&M remediation and control engineering under NIST SP 800-171
  • Design, implement, and integrate new GCC High/Azure Government environments
  • Produce evidence artifacts for C3PAO interviews and assessments
  • Document runbooks and implementation statements for each environment

Skills

Microsoft 365
Azure
GCC High
Entra ID
Intune/Autopilot
Defender/Sentinel
NIST SP 800-171
Written communication

Tools

Microsoft 365
Azure
Entra ID
Intune
Autopilot
Microsoft Defender
Microsoft Sentinel
Azure Policy

Job description

Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3PAOs during their CMMC Level 2 certification.

We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.

This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.

It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.

The role

Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3PAOs during their CMMC Level 2 certification.

We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.

This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.

It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.

What you’ll own
  • Final technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra ID, Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.
  • POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3PAO interview.
  • Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI boundary. These are scoped, billable projects with delivery dates.
  • Runbooks and documentation (~10%). Every environment you touch gets a runbook. Every control you configure gets an implementation statement someone else can read.
What you need
  • 5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering role
  • Hands‑on Microsoft GCC High experience, including working knowledge of where GCC High diverges from Commercial in feature availability, licensing, tenant configuration, and external collaboration
  • Entra ID: Conditional Access policy design, Privileged Identity Management, identity lifecycle
  • Intune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment, Windows endpoint hardening against a recognized benchmark (CIS or DISA STIG)
  • Microsoft Defender suite and Microsoft Sentinel: data connectors, analytics rules, alert triage, and enough KQL to write a query rather than copy one
  • Azure infrastructure: subscriptions and management groups, Azure Policy, RBAC, virtual networks, network security groups, site‑to‑site VPN
  • Working fluency in NIST SP 800-171 at the control level. Given a specific requirement, you can name the configuration that satisfies it, identify what's missing, and write the implementation statement. This is the requirement that distinguishes candidates for us.
  • Clear written communication. You'll write for clients, for assessors, and for teammates who inherit your work.
Helpful, not required
  • Azure Government or Microsoft 365 DoD experience
  • Cisco Meraki: MX firewall policy, VLAN segmentation, wireless
  • Experience supporting or sitting for a CMMC Level 2 or DFARS 7012 assessment
  • GRC platform administration (Drata, Vanta, or similar) with an emphasis on evidence automation
  • Azure Arc, Defender for Cloud, backup and DR design in a Gov cloud region
  • AZ‑500, SC‑200, AZ‑104, CCP, or CCA
  • Prior work
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft Cloud Engineer
Microsoft Cloud Engineer

Two Five • Washington

On-site
USD 120,000 - 155,000
Azure Government (GCC High) Systems Administrator
Azure Government (GCC High) Systems Administrator

X-Bow Systems • Albuquerque (NM)

On-site
USD 90,000 - 120,000
Security Architect
Security Architect

thyssenkrupp • Southfield (MI)

On-site
USD 130,000 - 185,000
Information Technology Network Administrator
Information Technology Network Administrator

LMK Recruiting Solutions • Hillside (IL)

Hybrid
USD 70,000 - 90,000
Cyber Security Compliance Engineer
Cyber Security Compliance Engineer

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
IT and Security Manager
IT and Security Manager

brightline • Ashburn (VA)

On-site
USD 150,000 - 190,000
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Multi-Cloud Engineer SME – Azure, Endpoint Management
Multi-Cloud Engineer SME – Azure, Endpoint Management

Jobtailor • New Mexico

On-site
USD 140,000 - 200,000
IT Systems Engineer
IT Systems Engineer

LegalSight • United States

Hybrid
USD 90,000 - 130,000
Hybrid work arrangement
Priority for local candidates (Ocean C
Office-based collaboration two days a週
Cyber Security Engineer
Cyber Security Engineer

Daniels Manufacturing Corporation • Orlando (FL)

On-site
USD 80,000 - 110,000