The Cloud Infrastructure & Security Engineer is a hands-on individual contributor responsible for designing, implementing, administering, securing, and continuously improving SOLID's Microsoft Azure cloud infrastructure and technology environments. The position focuses on building scalable, resilient, automated, and secure cloud solutions supporting corporate operations and federal programs.
This role manages Azure cloud computing resources, virtual networks, identity and access management, cloud storage, infrastructure automation, system monitoring, and disaster recovery capabilities. The position also supports integration with Microsoft Entra ID, Microsoft 365, and other enterprise technologies.
A key responsibility of this position is supporting Department of Defense Risk Management Framework (RMF) and Authority to Operate (ATO) activities, including developing and maintaining ATO documentation, implementing and documenting security controls, managing vulnerabilities, maintaining continuous monitoring evidence, and supporting security assessments and authorization activities.
Working closely with internal departments, government customers, cybersecurity personnel, software engineering and DevOps teams, and external service providers, the Cloud Infrastructure & Security Engineer translates operational, technical, and federal cybersecurity requirements into secure, practical, and sustainable cloud solutions.
Cloud Infrastructure Engineering and Operations (50%)
- Design, implement, administer, and optimize secure, scalable, resilient, and supportable Microsoft Azure infrastructure across corporate and program-specific environments.
- Manage Azure computing resources, virtual machines, virtual networks, storage, cloud identity services, firewalls, VPN connectivity, load balancing, backup services, and monitoring solutions.
- Configure and maintain Azure subscriptions, resource groups, networking, identity integration, access controls, and platform services.
- Administer and integrate Microsoft Entra ID, Microsoft 365, endpoint management, and other enterprise services with Azure infrastructure, including identity management, authentication, access control, and secure connectivity.
- Implement and maintain Infrastructure as Code (IaC) solutions using technologies such as Terraform, Azure Bicep, or ARM templates to support consistent and repeatable infrastructure deployments.
- Perform cloud resource provisioning, configuration management, patching, upgrading, monitoring, troubleshooting, backup validation, and capacity planning.
- Develop scripts, automation, and repeatable processes using PowerShell, Python, or comparable technologies to improve infrastructure deployment, configuration, monitoring, evidence collection, and administration.
- Implement and maintain cloud backup, disaster recovery, business continuity, and Continuity of Operations capabilities, including documentation, periodic testing, and corrective actions.
- Configure and maintain Azure monitoring, logging, and alerting solutions to proactively identify performance, availability, security, and operational issues.
- Evaluate Azure resource utilization, performance, security, reliability, and costs; recommend improvements to resource sizing, architecture, availability, and operational efficiency.
- Maintain cloud architecture documentation, system inventories, network and data-flow diagrams, configuration records, operating procedures, and infrastructure deployment documentation.
Cloud Security Engineering and Compliance (30%)
- Design, implement, maintain, assess, and document cybersecurity controls across Microsoft Azure infrastructure and hosted environments in accordance with organizational and applicable federal cybersecurity requirements.
- Lead and support technical RMF activities throughout the system lifecycle, including security control implementation, assessment, authorization, and continuous monitoring.
- Develop, maintain, and coordinate ATO packages and supporting cybersecurity documentation, including System Security Plans (SSPs), control implementation statements, Azure architecture and data-flow diagrams, configuration evidence, Plans of Action and Milestones (POA&Ms), and related security artifacts.
- Work with cybersecurity personnel, system owners, government stakeholders, and assessors to prepare systems for authorization, address assessment findings, support ATO submissions, and maintain documentation throughout the authorization lifecycle.
- Implement and document security controls under NIST SP 800-53, NIST SP 800-171, DoD RMF, and other applicable federal cybersecurity frameworks.
- Implement and maintain Azure security configurations, identity and access controls, multifactor authentication, role-based access control (RBAC), least-privilege access, secure network segmentation, encryption, and secure configuration baselines.
- Configure and maintain cloud security capabilities using Microsoft Entra ID, Microsoft Defender for Cloud, Azure Policy, and comparable security technologies.
- Perform system hardening and manage vulnerability identification, prioritization, remediation, validation, and reporting across Azure infrastructure and hosted environments.
- Review security scans, alerts, logs, and configuration findings; investigate potential security issues, coordinate corrective actions, and support incident response and remediation.
- Maintain audit-ready technical documentation and continuous monitoring evidence, including security control validation, configuration records, vulnerability remediation records, and POA&M updates.
- Coordinate security assessments, penetration testing, tabletop exercises, internal audits, and customer or third-party reviews.
- Support the secure storage, processing, and transmission of Controlled Unclassified Information (CUI), Personally Identifiable Information (PII), and other sensitive data.
- Evaluate proposed Azure services, infrastructure changes, and integrations for security, compliance, operational, and architectural impacts.
Engineering, Automation, and Stakeholder Collaboration (20%)
- Collaborate with software engineering, DevOps, and cybersecurity teams to design and maintain Azure environments supporting application development, testing, deployment, and production operations.
- Support the integration of infrastructure provisioning, configuration management, security validation, and monitoring into CI/CD pipelines and automated deployment workflows.
- Gather and analyze operational, business, cybersecurity, and technical requirements and translate them into practical Azure infrastructure and security solutions.
- Coordinate with cybersecurity personnel and program stakeholders to ensure infrastructure designs, deployments, and system changes align with applicable RMF and ATO requirements.
- Evaluate Azure technologies, platform services, and architectural approaches to improve system reliability, scalability, security, maintainability, and cost effectiveness.
- Coordinate with internal departments, government customers, vendors, and external service providers regarding cloud infrastructure requirements, system changes, technical issues, and compliance activities.
- Communicate technical risks, operational constraints, architectural recommendations, and alternative solutions clearly to technical and nontechnical stakeholders.
- Perform other related duties as organizational and program needs require.