Forge Forward is searching for a Senior Cloud Engineer. This position will be on-site and support a client in Charleston, SC. Position requires US citizenship with a Secret clearance. Those not meeting these requirements cannot be considered. Minimum seven (7) years of experience supporting enterprise IT or C4I systems, with substantial hands-on cloud architecture and engineering experience is required. The Senior Cloud Engineer is responsible for designing, deploying, securing, and sustaining mission-critical cloud and hybrid-cloud infrastructure in regulated DoD and Navy environments.
The preferred candidate brings deep Microsoft Azure experience, particularly Azure Government. Impact Level 5 (IL5) experience is strongly desired, and IL6 experience is ideal. The role requires the ability to design within mission, security, connectivity, and platform constraints while integrating on-premises services with cloud capabilities.
This engineer will serve as a technical authority across Azure architecture, external and internal networking, identity and access management, security services, virtual desktop, virtual machines, containers, and Infrastructure as Code automation. AWS or commercial-cloud experience is relevant, but Azure Government experience is preferred.
Functional Responsibilities and Skills:
- Design, deploy, secure, and sustain Microsoft Azure architectures, with preference for Azure Government over commercial cloud and Azure over AWS.
- Apply experience in DoD Impact Level environments; IL5 experience is strongly desired, and IL6 experience is ideal.
- Design hybrid-cloud solutions that run complementary services on premises and in Azure, including integration and management through Azure Arc.
- Engineer external connectivity and direct-connect solutions, including Azure ExpressRoute, VPN Gateway, routing, and connectivity to on-premises networks.
- Design and manage internal networking, including virtual networks, subnets, network security groups, VLANs, routing, and network segmentation.
- Implement cloud security using Microsoft Defender, Azure Firewall, VPN Gateway, secure baselines, least-privilege access, and Zero Trust principles.
- Design and administer Azure identity, role-based access control, privileged access, and service identities, including integration with program-provided NIS tools.
- Architect and support Azure Virtual Desktop, Windows and Linux virtual machines, and containerized workloads.
- Evaluate technical, cybersecurity, mission, and cost constraints and develop resilient Azure solution architectures and implementation plans.
- Develop repeatable infrastructure provisioning and configuration using Azure Automation integrated with Terraform; PowerShell, Bash, Python, and CI/CD experience is valuable.
- Troubleshoot complex cloud, network, identity, security, compute, and hybrid-integration issues across lab and production environments.
- Produce architecture diagrams, implementation plans, test artifacts, operating procedures, and RMF/ATO compliance evidence; participate in technical reviews and change management.
Requirements:
- Bachelor's degree in Engineering, Computer Science, Information Technology, or a related technical field desired. Relevant technical experience may be considered in lieu of a degree, subject to contract labor category requirements.
- CompTIA Security+ or equivalent certification meeting DoD Cybersecurity Workforce IAT Level II requirements.
- US citizen with a Secret clearance and current SSBI/T5 investigation. TS/SCI desired.
Desired Skills and Certifications:
- Microsoft Certified: Azure Solutions Architect Expert; Microsoft Certified: Azure Administrator Associate (AZ-104); Microsoft Certified: Azure Security Engineer Associate; and HashiCorp Certified: Terraform Associate.
- Experience supporting Navy C4I or comparable DoD mission environments.
- Azure Government and classified-cloud engineering experience at IL6.
- Advanced Azure architecture experience with Azure Virtual Desktop, Azure Arc, ExpressRoute, Azure Firewall, Microsoft Defender, VPN Gateway, virtual machines, containers, and role-based access control.
- Hybrid-cloud architecture spanning on-premises infrastructure and Azure services.
- Terraform integrated with Azure Automation, Git-based version control, and CI/CD pipelines.
- Experience with Azure Kubernetes Service or other Kubernetes/container platforms.
- Familiarity with DISA STIGs, ACAS/SCAP remediation, RMF controls, POA&Ms, and continuous monitoring.
- Strong communication, technical documentation, collaboration, and leadership skills in a multi-disciplinary Agile environment.