Senior Cloud Engineer
Forge Forward, Inc.
Visa & sponsorship
- US persons only (ITAR / export control): a legal requirement, not employer policy.
- A US security clearance is required, which effectively means citizens only.
Job description
Forge Forward is searching for a Senior Cloud Engineer. This position will be on-site and support a client in Charleston, SC. Position requires US citizenship with a Secret clearance. Those not meeting these requirements cannot be considered. Minimum seven (7) years of experience supporting enterprise IT or C4I systems, with substantial hands-on cloud architecture and engineering experience is required. The Senior Cloud Engineer is responsible for designing, deploying, securing, and sustaining mission-critical cloud and hybrid-cloud infrastructure in regulated DoD and Navy environments.
The preferred candidate brings deep Microsoft Azure experience, particularly Azure Government. Impact Level 5 (IL5) experience is strongly desired, and IL6 experience is ideal. The role requires the ability to design within mission, security, connectivity, and platform constraints while integrating on-premises services with cloud capabilities.
This engineer will serve as a technical authority across Azure architecture, external and internal networking, identity and access management, security services, virtual desktop, virtual machines, containers, and Infrastructure as Code automation. AWS or commercial-cloud experience is relevant, but Azure Government experience is preferred.
Functional Responsibilities and Skills:
-
Design, deploy, secure, and sustain Microsoft Azure architectures, with preference for Azure Government over commercial cloud and Azure over AWS.
-
Apply experience in DoD Impact Level environments; IL5 experience is strongly desired, and IL6 experience is ideal.
-
Design hybrid-cloud solutions that run complementary services on premises and in Azure, including integration and management through Azure Arc.
-
Engineer external connectivity and direct-connect solutions, including Azure ExpressRoute, VPN Gateway, routing, and connectivity to on-premises networks.
-
Design and manage internal networking, including virtual networks, subnets, network security groups, VLANs, routing, and network segmentation.
-
Implement cloud security using Microsoft Defender, Azure Firewall, VPN Gateway, secure baselines, least-privilege access, and Zero Trust principles.
-
Design and administer Azure identity, role-based access control, privileged access, and service identities, including integration with program-provided NIS tools.
-
Architect and support Azure Virtual Desktop, Windows and Linux virtual machines, and containerized workloads.
-
Evaluate technical, cybersecurity, mission, and cost constraints and develop resilient Azure solution architectures and implementation plans.
-
Develop repeatable infrastructure provisioning and configuration using Azure Automation integrated with Terraform; PowerShell, Bash, Python, and CI/CD experience is valuable.
-
Troubleshoot complex cloud, network, identity, security, compute, and hybrid-integration issues across lab and production environments.
-
Produce architecture diagrams, implementation plans, test artifacts, operating procedures, and RMF/ATO compliance evidence; participate in technical reviews and change management.
Requirements:
-
Bachelor’s degree in Engineering, Computer Science, Information Technology, or a related technical field desired. Relevant technical experience may be considered in lieu of a degree, subject to contract labor category requirements.
-
CompTIA Security+ or equivalent certification meeting DoD Cybersecurity Workforce IAT Level II requirements.
-
US citizen with a Secret clearance and current SSBI/T5 investigation. TS/SCI desired.
Desired Skills and Certifications:
-
Microsoft Certified: Azure Solutions Architect Expert; Microsoft Certified: Azure Administrator Associate (AZ-104); Microsoft Certified: Azure Security Engineer Associate; and HashiCorp Certified: Terraform Associate.
-
Experience supporting Navy C4I or comparable DoD mission environments.
-
Azure Government and classified-cloud engineering experience at IL6.
-
Advanced Azure architecture experience with Azure Virtual Desktop, Azure Arc, ExpressRoute, Azure Firewall, Microsoft Defender, VPN Gateway, virtual machines, containers, and role-based access control.
-
Hybrid-cloud architecture spanning on-premises infrastructure and Azure services.
-
Terraform integrated with Azure Automation, Git-based version control, and CI/CD pipelines.
-
Experience with Azure Kubernetes Service or other Kubernetes/container platforms.
-
Familiarity with DISA STIGs, ACAS/SCAP remediation, RMF controls, POA&Ms, and continuous monitoring.
-
Strong communication, technical documentation, collaboration, and leadership skills in a multi-disciplinary Agile environment.
Pay: $125,000.00 - $165,000.00 per year
Benefits:
-
401(k)
-
401(k) matching
-
Dental insurance
-
Employee assistance program
-
Flexible spending account
-
Health insurance
-
Health savings account
-
Life insurance
-
Paid time off
-
Professional development assistance
-
Vision insurance
Work Location: In person