TrueTandem is seeking a highly skilled and motivated Senior Azure Infrastructure Cloud Engineer to support the delivery of enterprise-scale cloud infrastructure and platform services for a member of the Intelligence Community (IC). This role is ideal for a seasoned cloud professional with expertise in Azure infrastructure, automation, security, governance, and Infrastructure as Code (IaC) who thrives in mission-driven environments.
The successful candidate will join a team responsible for designing, deploying, securing, and sustaining cloud platforms that support critical mission and business applications. Solutions are engineered in accordance with approved reference architectures, federal security requirements, organizational policies, and cloud engineering best practices.
The environment leverages Azure-native services, Microsoft 365, Power Platform, Terraform, Bicep, and Azure DevOps to deliver secure, scalable, and repeatable cloud capabilities. The team emphasizes automation, policy-driven governance, continuous compliance validation, operational excellence, and efficient platform management to accelerate cloud adoption while maintaining security and regulatory requirements.
As a Senior Azure Infrastructure Cloud Engineer, you will help build and maintain the core Azure infrastructure foundation that enables mission and business workloads across the enterprise. Working within a cross-functional team of architects, engineers, developers, and cybersecurity professionals, you will design, implement, and support Azure governance frameworks, subscriptions, management groups, virtual networking, storage services, Key Vault, monitoring solutions, security controls, identity integration, workload migrations, and operational sustainment activities.
The ideal candidate possesses hands-on experience supporting complex federal cloud environments and demonstrates the ability to troubleshoot and resolve challenging infrastructure issues while balancing security, performance, reliability, and scalability requirements. Success in this role requires a strong commitment to automation, continuous improvement, and delivering secure, resilient cloud solutions that support evolving mission needs.
This position offers the opportunity to contribute to some of the most critical cloud modernization initiatives within the federal government while working with leading technologies and a highly collaborative engineering team.
*This role is a hybrid role with 1 day on site (in bethesda or tysons) and 4 days remote*
Role and Responsibilities:
- Design, develop, and maintain Infrastructure as Code (IaC) solutions using Terraform to deliver secure, scalable, and repeatable Azure infrastructure deployments.
- Build, enhance, and support automated CI/CD pipelines within Azure DevOps to streamline infrastructure provisioning, application delivery, and operational deployments.
- Architect, deploy, and sustain Azure infrastructure services in alignment with the Microsoft Cloud Adoption Framework (CAF), Well-Architected Framework, and organizational standards.
- Implement and administer Azure governance capabilities, including Management Groups, Subscriptions, Resource Groups, Policies, and Role-Based Access Control (RBAC), to enforce security, compliance, and operational consistency.
- Configure and manage Azure Key Vault to safeguard secrets, certificates, encryption keys, and application credentials.
- Design, deploy, and support Azure storage solutions while implementing data protection, backup, recovery, retention, and lifecycle management strategies.
- Architect and maintain enterprise networking solutions, including Virtual WAN, Virtual Networks (VNets), Network Security Groups (NSGs), private connectivity, DNS, and hybrid cloud integrations.
- Implement enterprise monitoring and observability solutions using Azure Monitor, Log Analytics, Application Insights, alerts, dashboards, and automated response capabilities.
- Support the migration, modernization, and optimization of applications and workloads into Azure cloud environments.
- Integrate security controls and compliance requirements throughout the infrastructure lifecycle in accordance with Zero Trust principles, TIC 3.0 guidance, NIST frameworks, and federal security baselines.
- Troubleshoot complex infrastructure, networking, identity, performance, and security issues across cloud environments to ensure platform reliability and operational excellence.
- Collaborate with architects, developers, cybersecurity teams, and stakeholders to design, implement, and continuously improve secure, resilient, and mission-focused cloud solutions.
- Contribute to the development and maintenance of reusable infrastructure modules, engineering standards, reference architectures, and operational procedures.
- Participate in platform sustainment activities, capacity planning, incident response, problem management, and continuous service improvement initiatives.
- Produce and maintain technical documentation, implementation guides, architecture diagrams, and audit artifacts to support operational, security, and compliance requirements.
Required Skills
- Active TS/SCI clearance with Polygraph.
- 5+ years of experience supporting Tier II Azure environments or 3+ years supporting Tier III enterprise Azure cloud infrastructure.
- Demonstrated experience designing, implementing, and sustaining Azure enterprise landing zones and core infrastructure services aligned with the Microsoft Cloud Adoption Framework (CAF) and cloud engineering best practices.
- Deep expertise in Azure governance and platform services, including Management Groups, Subscriptions, Resource Groups, Azure Policy, RBAC, Key Vault, Storage, and networking services.
- Hands-on experience designing and supporting Azure networking solutions, including Virtual WAN, Virtual Networks (VNets), Network Security Groups (NSGs), private connectivity, routing, and hybrid-cloud architectures.
- Experience administering and supporting Azure Virtual Desktop (AVD) environments, including host pools, image management, FSLogix profiles, session hosts, and enterprise user support.
- Strong understanding of Azure security, monitoring, and operational practices, including Azure Monitor, Log Analytics, Application Insights, alerts, diagnostics, and security controls.
- Proficiency in PowerShell scripting and automation to streamline cloud operations, configuration management, and administrative tasks.
- Experience with Infrastructure as Code (IaC) methodologies and tools such as Terraform to deploy and manage Azure resources in a repeatable and auditable manner.
- Knowledge of federal cybersecurity and compliance frameworks, including Zero Trust Architecture, NIST standards, TIC 3.0, and government cloud security requirements.
- Proven ability to diagnose and resolve complex infrastructure, networking, identity, performance, and security issues across enterprise Azure environments.
- Strong verbal and written communication skills with the ability to create technical documentation, operational procedures, and architecture artifacts for both technical and non-technical stakeholders.
- Demonstrated ability to work effectively within cross-functional teams consisting of cloud engineers, architects, cybersecurity personnel, developers, and mission stakeholders.
Preferred Skills
- Microsoft Azure certifications such as Azure Administrator Associate (AZ-104), Azure Security Engineer Associate (AZ-500), Azure Network Engineer Associate (AZ-700), or Azure Solutions Architect Expert (AZ-305).
- Experience supporting IC, DoD, or other classified federal cloud environments.
- Knowledge of Bicep, ARM templates, or additional IaC frameworks.
- Experience supporting cloud migration, modernization, and application transformation initiatives.
- Experience with Power Platform integration in Azure environments.
- Familiarity with AOAI embedded features and Copilot capabilities.
- Knowledge of workload/application migrations and hybrid cloud strategies.
- Understanding of Microsoft licensing models and subscription management.