Azure Cloud Engineer
Hybrid Remote Washington DMV Area
Job Type
Full-time
Description

HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, cloud infrastructure, and modernization solutions to federal government agencies.


HyerTek is seeking a mid-level Microsoft Azure Cloud Engineer to build, configure, secure, and support Microsoft Azure environments supporting Department of War (DoW) Customers, including Azure Government and environments supporting Impact Level (IL) 5 and classified workloads. 


A successful candidate will work alongside senior cloud engineers, cybersecurity professionals, DevSecOps teams, application developers, and Government stakeholders to implement approved cloud architecture and maintain secure, reliable Azure environments. The role will be a hands-on Azure engineer who is comfortable deploying infrastructure, troubleshooting cloud services, implementing security controls, and automating repeatable cloud operations. 


Candidates must reside in the Washington, DC, metropolitan area and be able to support hybrid work at customer facilities, including Fort Meade and other locations, as required. 


  

Responsibilities

  • Build, configure, maintain, and troubleshoot secure Microsoft Azure environments supporting Government and mission workloads. 
  • Deploy and manage Azure infrastructure in accordance with approved architectures, security requirements and engineering standards. 
  • Support Azure landing zones, subscriptions, resource groups, networking, identity, logging, monitoring, and governance.
  • Deploy infrastructure using Terraform, Bicep, ARM templates, or comparable Infrastructure as Code (IaC) technologies.
  • Configure Azure networking components including VNets, subnets, routing, private endpoints, DNS, network security groups, firewalls, and load balancers.
  • Implement identity and access controls using Microsoft Entra ID, Azure RBAC, managed identities, and Azure Key Vault.
  • Deploy and support Azure virtual machines, storage, databases, container services, and other platform services.
  • Apply Azure Policy, security baselines, DISA STIGs, encryption requirements, and configuration standards in coordination with cybersecurity personnel.
  • Assist with remediation of vulnerabilities, configuration findings, and security-control deficiencies.
  • Configure and maintain monitoring, logging, and alerting using Azure Monitor, Log Analytics, Defender for Cloud, and related services.
  • Troubleshoot Azure infrastructure, networking, identity, connectivity, performance, and configuration issues.
  • Develop and maintain infrastructure diagrams, configuration documentation, operating procedures, and technical runbooks.
  • Support backup, recovery, continuity-of-operations, and disaster-recovery planning and testing.
  • Provide infrastructure configuration information and technical evidence in support of RMF, security assessment, and continuous-monitoring activities.
  • Collaborate with cloud architects, cybersecurity engineers, DevSecOps engineers, developers, and Government stakeholders.  
  • Use approved AI-assisted engineering tools, where appropriate, to accelerate scripting, Infrastructure as Code, documentation, and troubleshooting while validating generated output before implementation.
Requirements

Required Qualifications

  • 3+ years of hands-on cloud, systems, or infrastructure engineering experience, including supporting production environments.
  • Hands-on experience deploying and supporting solutions in Microsoft Azure. 
  • Experience with Azure Government, Government cloud environments, or similarly regulated enterprise environments.
  • Working knowledge of Azure networking, compute, storage, identity, security, monitoring, and governance.
  • Experience with Infrastructure as Code using Terraform, Bicep, ARM templates, or a comparable technology.
  • Experience with Azure networking concepts including VNets, subnets, routing, NSGs, private endpoints, DNS, and firewalls.
  • Experience with Microsoft Entra ID, Azure RBAC, managed identities, Azure Key Vault, Azure Policy, Azure Monitor, and Log Analytics.
  • Working knowledge of Windows and/or Linux administration. 
  • Experience with PowerShell, Azure CLI, Python, or another scripting language. 
  • Understanding of cloud security principles including least-privilege, encryption, vulnerability management, system hardening, backup, and recovery.
  • Familiarity with RMF, NIST SP 800-53, and applicable DISA STIGs, or comparable federal cybersecurity requirements.
  • Ability to troubleshoot technical issues and clearly document solutions.
  • Strong written and verbal communication skills.  
  • Ability to work independently or collaboratively with technical and nontechnical stakeholders.
  • DoW 8140 aligned IAT Level II certification, such as Security+ CE or an approved equivalent.
  • Active Secret security clearance required. Candidates must be eligible to obtain and maintain any additional customer-specific access requirements associated with their assigned work.

Preferred Qualifications.

  • Experience supporting DoW IL5 or classified cloud environments. 
  • Experience with Azure Government Secret, classified networks, or other restricted Government environments. 
  • Familiarity with DoW Cloud Computing SRG requirements.
  • Experience implementing or supporting Azure Landing Zones or Secure Azure Computing Architecture patterns.  
  • Experience with hybrid connectivity, ExpressRoute, network virtual appliances, enterprise DNS, or network segmentation.
  • Experience with Azure Kubernetes Service, Azure Container Registry, virtual machines, or Azure platform services.
  • Experience implementing or remediating DISA STIGs and security configuration baselines. 
  • Experience supporting RMF authorization, assessment, remediation, or continuous-monitoring activities.
  • Experience with DevSecOps pipelines and automated Azure infrastructure deployment. 
  • Familiarity with AI-assisted engineering tools such as Microsoft Copilot, ChatGPT/OpenAI, Claude, or comparable programs. 
  • Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, Azure Security Engineer Associate, or Azure Network Engineer Associate.
  • CISSP, CASP+, or another advanced security certification.

Clearance & Work Authorization

This position requires U.S. citizenship and an active Secret security clearance with the Department of War. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future. HyerTek will not sponsor applicants for a U.S. work visa status for this opportunity.


Salary Range

The anticipated salary range for this position is $125,000 – $161,000 annually. Final compensation will be based on relevant experience, technical qualifications, certifications, clearance status, and contract requirements.


HyerTek offers a comprehensive benefits package, including:

  • Medical, dental, and vision insurance
  • 401(k) with employer contribution
  • Paid time off (PTO) and company holidays
  • Professional development and certification support
  • Employee assistance program (EAP)
  • Life and disability insurance

Equal Employment Opportunity (EEO)

HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other status protected by applicable federal, state, or local law.

Salary Description
125,000 – $161,000 annually