Cloud Security Architect (GCC High)

Two Five Solutions, LLC.

Washington, Northern (District of Columbia, KY)

Hybrid

USD 140,000 - 185,000

Full time

35 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Two Five Solutions LLC is seeking a Cloud Security Architect (GCC High) in Washington, DC to own GCC High and Azure Government environments for defense clients. You translate controls into configurations, defend POA&M findings, and stand up new tenants and landing zones as clients are onboarded or acquired.

You will be the senior technical authority across the DIB client base, handling escalations, remediation, and architecture decisions that shape our security posture and client deliverables.

Qualifications

  • 5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT role.
  • Hands-on Microsoft GCC High experience and knowledge of GCC High vs Commercial differences.
  • Entra ID: Conditional Access, Privileged Identity Management, identity lifecycle.
  • Intune/Autopilot: device enrollment, config, compliance, Windows hardening.
  • Defender/Sentinel: data connectors, analytics, alert triage, KQL familiarity.

Responsibilities

  • Own GCC High, Intune, Entra ID, Defender, Sentinel work across DIB clients.
  • Remediate POA&M findings against NIST SP 800-171 with evidence artifacts.
  • Lead environment buildouts and acquisitions integrations (GCC High tenants, landing zones).
  • Produce runbooks and implementation statements for each environment.

Skills

Cloud security design
NIST SP 800-171 fluency
Problem solving
Written communication
Escalation handling

Tools

Microsoft 365
Azure
Entra ID
Intune
Autopilot
Defender
Sentinel
KQL
Cisco Meraki

Job description

Two Five Solutions LLC Cloud Security Architect (GCC High) Washington, DC·Full time Company website Apply for Cloud Security Architect (GCC High)

Two Five Solutions is hiring a Cloud Security Architect to own the Microsoft GCC High and Azure Government environments we run for defense industrial base contractors — designing CUI boundaries, taking the escalations no one else can close, clearing POA&M findings against NIST SP 800-171 ahead of C3PAO assessments, and standing up new tenants and landing zones as clients are onboarded or acquired. This isn't a helpdesk role, a policy-writing role, or a whiteboard role: you translate controls into configurations and produce the evidence that proves it, which means you're in the console the same week you're in the design document. What matters most is real GCC High depth and 800-171 fluency at the control level — given a requirement, you can name the configuration that satisfies it, say what's missing, and write the implementation statement. You'd be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters.

About Two Five Solutions LLC

Two Five is a cybersecurity and automation solutions firm that helps organizations operate smarter, scale faster, and grow securely. We deliver expert solutions across Governance, Risk & Compliance (GRC), Managed Services, Strategic Consulting, and Innovation & Automation. By combining deep technical knowledge with business-first thinking, we empower our clients to reduce risk, streamline operations, and unlock the full potential of AI and automation. Whether you're building secure infrastructure, navigating compliance, or accelerating transformation, Two Five is your trusted partner for resilient growth.

Description
The role

Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3PAOs during their CMMC Level 2 certification.

We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.

This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.

It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.

What you'll own

Final technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra ID, Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.

POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3PAO interview.

Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI boundary. These are scoped, billable projects with delivery dates.

Runbooks and documentation (~10%). Every environment you touch gets a runbook. Every control you configure gets an implementation statement someone else can read.

What you need
  • 5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering role
  • Hands-on Microsoft GCC High experience, including working knowledge of where GCC High diverges from Commercial in feature availability, licensing, tenant configuration, and external collaboration
  • Entra ID: Conditional Access policy design, Privileged Identity Management, identity lifecycle
  • Intune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment, Windows endpoint hardening against a recognized benchmark (CIS or DISA STIG)
  • Microsoft Defender suite and Microsoft Sentinel: data connectors, analytics rules, alert triage, and enough KQL to write a query rather than copy one
  • Azure infrastructure: subscriptions and management groups, Azure Policy, RBAC, virtual networks, network security groups, site-to-site VPN
  • Working fluency in NIST SP 800-171 at the control level. Given a specific requirement, you can name the configuration that satisfies it, identify what's missing, and write the implementation statement. This is the requirement that distinguishes candidates for us.
  • Clear written communication. You'll write for clients, for assessors, and for teammates who inherit your work.
Helpful, not required
  • Cisco Meraki: MX firewall policy, VLAN segmentation, wireless
  • Experience supporting or sitting for a CMMC Level 2 or DFARS 7012 assessment
  • GRC platform administration (Drata, Vanta, or similar) with an emphasis on evidence automation
  • Azure Arc, Defender for Cloud, backup and DR design in a Gov cloud region
  • AZ-500, SC-200, AZ-104, CCP, or CCA
  • Prior work at an MSP, MSSP, or defense contractor
First 90 days

By day 30, you're taking escalations independently across at least two client environments. By day 60, you own the open POA&M queue for one client and have closed findings with evidence attached. By day 90, you're leading a buildout or integration workstream end to end and your design decisions are shaping how we scope the next one.

Why this is worth your time

You'll be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters. Our clients are building real defense capability and cannot bid without the compliance posture we help them hold. The environments are technically constrained in ways commercial cloud work isn't, which means the expertise you build here is scarce and it compounds.

We are also automating the parts of compliance delivery that should never have been manual. If you have opinions about what should be a script instead of a screenshot, you'll be listened to.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Microsoft Cloud Engineer
Microsoft Cloud Engineer

Two Five • Washington

On-site
USD 120,000 - 155,000
Microsoft Cloud Engineer
Microsoft Cloud Engineer

Two Five Solutions, LLC. • Washington, Northern (KY)

Hybrid
USD 120,000 - 150,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
IT Systems Engineer
IT Systems Engineer

LegalSight LLC • United States

Hybrid
USD 110,000 - 150,000
Senior Microsoft GCCH Engineer
Senior Microsoft GCCH Engineer

PeopleForce Ltd. • Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

On-site
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Security Engineer
Security Engineer

qualityworksconsulting • Los Angeles (CA)

On-site
USD 120,000 - 150,000
Senior IT Engineer - US West Coast
Senior IT Engineer - US West Coast

Workman Labs • Northern (KY)

Hybrid
USD 110,000 - 170,000
IT Director
IT Director

Continuum Powders • Houston (TX), Northern (KY)

On-site
USD 180,000 - 260,000
Information Technology Manager
Information Technology Manager

MACH Ai8 Corporation • Irvine (CA)

On-site
USD 120,000 - 180,000