Systems Engineer Azure Identity with Security Clearance

Sarela Technology Solutions

Fort Belvoir (VA)

On-site

USD 160,000 - 210,000

Full time

26 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

SarelaTech seeks a Hybrid Multi-Cloud Engineer SME to support DoD cloud modernization at Fort Belvoir, VA or Albuquerque, NM. You will design, engineer, and sustain secure Microsoft Azure cloud solutions within classified environments.

You will translate mission requirements into scalable cloud architectures, maintain hands-on engineering through the lifecycle, and ensure RMF/STIG compliance while collaborating across cybersecurity, systems, and applications teams.

Qualifications

  • Bachelor's degree in a technical discipline with extensive DoD cloud exp.
  • Active TS security clearance with SCI eligibility.
  • DoD 8570/8140 IAT Level II certification and Azure Solutions Architect Expert.
  • 5+ years designing Azure enterprise cloud solutions; hybrid Azure envs.

Responsibilities

  • Architect, design, engineer secure Azure cloud solutions for DoD missions.
  • Design and deploy hybrid cloud environments linking on-prem to Azure.
  • Manage Entra ID governance, including AAD, CA, PIM, and lifecycle workflows.
  • Implement Zero Trust, PAM, JIT access, and identity governance across environments.
  • Produce engineering diagrams, implementation guides, and SOPs.
  • Collaborate with cybersecurity, networks, and apps teams; support ATO activities.

Skills

Azure architecture
Hybrid cloud engineering
Zero Trust
DoD cybersecurity
RMF/STIGs
Identity management
IaC (Terraform/Bicep)
Entra ID

Education

Bachelor's in CS/IS/Engineering
Master's degree in technical domain

Tools

Azure
Terraform
Bicep
ARM Templates
PowerShell
Azure CLI
Entra ID
Entra Connect
Active Directory
AWS IAM

Job description

SarelaTech is seeking a highly skilled Hybrid Multi-Cloud Engineer SME to support mission-critical Department of Defense (DoD) cloud modernization initiatives in Fort Belvoir, VA or Albuquerque, New Mexico. This position will serve as a senior technical contributor responsible for designing, engineering, implementing, and sustaining secure Microsoft Azure cloud solutions within classified enterprise environments. The successful candidate will possess deep expertise in Microsoft Azure architecture, hybrid cloud engineering, and enterprise identity management. This role requires an experienced engineer capable of translating complex mission requirements into secure, scalable cloud solutions while maintaining a hands-on engineering role throughout the solution lifecycle. The ideal candidate will have experience supporting DoD cloud initiatives, implementing hybrid identity solutions, and engineering cloud environments that align with Zero Trust principles and Department of Defense cybersecurity requirements.

Primary Responsibilities:

Architect, design, engineer, and implement secure Microsoft Azure cloud solutions supporting DoD mission requirements.

Design and deploy green-field Azure environments and hybrid cloud architectures integrating on-premises infrastructure with Azure services.

Design, implement, and maintain enterprise hybrid identity solutions utilizing Microsoft Entra ID, Microsoft Entra Connect, Active Directory, and related identity technologies.

Engineer secure authentication, authorization, identity governance, and privileged access management (PAM) solutions supporting just-in-time (JIT) access, attribute- and role- based access controls (ABAC/RBAC) and similar Zero Trust principles and objectives.

Design Azure Landing Zones, governance frameworks, subscription architectures, and management group strategies following Microsoft Cloud Adoption Framework (CAF) and Azure Well-Architected Framework guidance.

Engineer Infrastructure as Code (IaC) solutions using Bicep, ARM Templates, Terraform, or comparable automation technologies.

Design secure Azure networking solutions utilizing Virtual Networks, ExpressRoute, VPN Gateway, Azure Firewall, Virtual WAN, and private connectivity services.

Implement Azure-native monitoring, backup, disaster recovery, governance, and security capabilities.

Configure and administer Microsoft Entra ID Governance capabilities, including Access Reviews, Entitlement Management, Lifecycle Workflows, Conditional Access, and Privileged Identity Management (PIM).

Collaborate with cybersecurity, systems engineering, networking, and application development teams to deliver integrated cloud solutions.

Support Authority to Operate (ATO) activities and ensure compliance with DoD cybersecurity policies, Risk Management Framework (RMF), and applicable Security Technical Implementation Guides (STIGs).

Produce architecture documentation, engineering diagrams, implementation guides, standard operating procedures, and technical documentation.

Troubleshoot and resolve complex cloud infrastructure, networking, identity, and security issues.

Evaluate emerging Microsoft cloud technologies and recommend technical solutions supporting customer mission objectives.

Required Qualifications:

Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical discipline and 12-15 years of prior relevant experience or Masters with 10-13 years of prior relevant experience. May possess a Doctorate in technical domain. Specific experience, education and training may be considered in lieu of degree.

Active Top Secret security clearance with eligibility for access to Sensitive Compartmented Information (SCI).

Current DoD 8570/8140 IAT Level II certification.

Microsoft Certified: Azure Solutions Architect Expert certification.

Minimum of five years of experience designing and implementing Microsoft Azure enterprise cloud solutions.

Demonstrated experience architecting hybrid Azure environments integrating enterprise on-premises infrastructure with Azure cloud services.

Advanced experience with Microsoft Entra ID, Microsoft Entra Connect, Active Directory, AWS IAM, hybrid identity synchronization, federation, and enterprise identity management with enterprise Identity, Credential, and Access Management (E-ICAM) solutions.

Experience Implementing Microsoft Entra ID Governance Capabilities, Including
  • Entra Conditional Access* Policy Information Points and Policy Engines* Access Reviews* Entitlement Management* Lifecycle Workflows* Identity lifecycle automation

Experience implementing Azure Landing Zones and enterprise governance models.

Strong understanding of Azure networking, storage, compute, governance, and security services.

Experience with Infrastructure as Code utilizing Terraform, Azure Bicep, ARM Templates, or similar technologies.

Experience with Azure CLI, PowerShell, and scripting using Python or comparable automation languages.

Strong understanding of Zero Trust architecture, identity-centric security, and cloud security best practices.

Excellent Written And Verbal Communication Skills Desired Qualifications

AWS Certified Solutions Architect - Professional certification.

Experience integrating Azure and AWS within hybrid multi-cloud enterprise environments.

Familiarity with the Department of Defense Joint Warfighting Cloud Capability (JWCC) and DoD Joint Tenant cloud environments.

Understanding of the DoD Enterprise Cloud Strategy and cloud modernization initiatives.

Familiarity with the Department of Defense Enterprise Identity, Credential, and Access Management (E-ICAM) architecture and its role in enterprise identity federation, identity governance, Zero Trust implementation, and secure access to DoD cloud environments.

Experience with Azure Arc, Azure Stack HCI, Azure Local, and hybrid cloud management technologies.

Experience with Azure Kubernetes Service (AKS) and cloud-native container platforms.

Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Intune, and Microsoft Purview.

Experience implementing DevSecOps pipelines using Azure DevOps and/or GitHub Enterprise

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Systems Engineer Azure Identity
Systems Engineer Azure Identity

Career Listings • Fort Belvoir (VA)

Hybrid
USD 140,000 - 190,000
401(k)
401(k) matching
Dental insurance
+6
Hybrid Multi-Cloud Engineer SME (Azure/Identity)
Hybrid Multi-Cloud Engineer SME (Azure/Identity)

Nowges • Albuquerque (NM), Northern (KY)

Hybrid
USD 150,000 - 190,000
Systems Engineer Azure Endpoint Management
Systems Engineer Azure Endpoint Management

Career Listings • Fort Belvoir (VA)

On-site
USD 150,000 - 190,000
401(k)
401(k) matching
Dental insurance
+6
Systems Engineer Azure Endpoint Management
Systems Engineer Azure Endpoint Management

Sarela Technology Solutions • Fort Belvoir (VA)

Hybrid
USD 140,000 - 210,000
401(k)
401(k) matching
Dental insurance
+6
Systems Engineer/Architect (Cloud Engineer - Azure)
Systems Engineer/Architect (Cloud Engineer - Azure)

Sarela Technology Solutions LLC • Mission (KS)

On-site
USD 120,000 - 150,000
Systems Engineer/Architect (Multi-Cloud Engineer)
Systems Engineer/Architect (Multi-Cloud Engineer)

Sarela Technology Solutions LLC • Mission (KS)

On-site
USD 120,000 - 150,000
Collaborative environment
Opportunities for technical growth
Comprehensive benefits package
Senior Azure Identity & Hybrid Cloud Engineer (DoD)
Senior Azure Identity & Hybrid Cloud Engineer (DoD)

Career Listings • Fort Belvoir (VA)

Hybrid
USD 140,000 - 190,000
401(k)
401(k) matching
Dental insurance
+6
Azure Security Engineer
Azure Security Engineer

Zeektek • Sacramento (CA)

On-site
USD 140,000 - 170,000
Hybrid Multi-Cloud Engineer SME (Azure/Identity)
Hybrid Multi-Cloud Engineer SME (Azure/Identity)

Leidos • Albuquerque (NM)

On-site
USD 131,000 - 237,000
Hybrid Multi-Cloud Engineer SME (Azure/Identity)
Hybrid Multi-Cloud Engineer SME (Azure/Identity)

Koitecc Solutions • Fort Belvoir (VA)

On-site
USD 131,000 - 238,000