Job Number: R0247685 Cloud Computing Infrastructure Architect
The Opportunity: Everyone is trying to modernize in the cloud, but not everyone knows how to secure, monitor, and operate Azure environments in a way that reduces risk, improves visibility, and supports mission-critical operations. As an Azure cloud security engineer, you know how to work across cloud infrastructure, identity and access management, monitoring, migration, and security controls to help clients move from findings to implementation. As an Azure cloud security engineer on our team, you'll support the design, assessment, implementation, and improvement of secure Azure cloud capabilities for a highly regulated enterprise environment. You'll help review current -state Azure environments, identify security and operational gaps, support remediation planning, and implement Azure-native capabilities that improve access control, logging, monitoring, detection, and cloud governance.
You'll work with Micro sof t Azure, Micro sof t Entra ID, Azure Monitor, Log Analytics, Micro sof t Sentinel, Azure Migrate, Azure Policy , Defender for Cloud, and Azure DevOps to help clients strengthen their cloud security posture. You'll support hands-on activities such as Azure migration readiness, diagnostic setting review, Sentinel connector validation, Log Analytics workspace analysis, privileged access workflow support, and cloud security assessment remediation.
This is an opportunity to apply practical Azure engineering experience while working directly with client stakeholders, application teams, cloud platform teams, SOC teams, and senior security engineers. You'll help translate technical requirements into clear implementation steps, support secure migration and modernization efforts, and communicate findings in a way that executives, program leaders, and engineers can act on.
You'll support work that includes Azure cloud migrations, identity and access management (IAM), security control remediation, centralized logging, Micro sof t Sentinel and Azure Monitor optimization, diagnostic logging review, detection support, and cost-conscious logging improvements. Your ability to combine hands-on Azure execution with strong client communication will help the team improve security outcomes while reducing unnecessary operational complexity and recurring cloud spend. Due to the nature of work performed within this facility, U.S. citizen ship is required .
Join us. The world can't wait.
You Have: - 3+ years of experience with Azure cloud engineering, Azure security, cloud migration, IAM, security operations, or enterprise technology delivery
- Experience with Micro sof t Azure services, including virtual machines (VMs), networking, storage, subscriptions, resource groups, monitoring, or migration services
- Experience supporting cloud readiness assessments, security assessments, application migration planning, dependency discovery, or environment reviews
- Experience with Azure Monitor, Log Analytics, diagnostic settings, dashboards, operational reporting, or cloud monitoring workflows
- Experience translating technical findings into client-ready recommendations, roadmaps, executive briefings, or implementation plans
- Experience working directly with client stakeholders, application owners, platform teams, security teams, or cross-contractor engineering teams
- Experience with scripting, automation, or cloud tooling using technologies such as PowerShell, Azure CLI, Python, ARM templates, Bicep, or Terraform
- Ability to perform independent research, learn new Azure technologies quickly, and apply technical concepts to client delivery challenges
- Ability to create and present information for technical stakeholders, program leaders, and executive-level audiences
- Bachelor's degree in Cybersecurity, IT, Security and Risk Analysis, CS, or Engineering
Nice If You Have: - Experience designing or supporting Azure cloud migration activities, including VM sizing, application dependency mapping, Azure Migrate, migration agents, and performance met ric collection
- Experience with Micro sof t Sentinel cost and ingestion analysis, including identifying duplicate connectors, duplicate diagnostic settings, high-volume tables, or unnecessary workspace routing
- Experience writing KQL queries for log analysis, alert validation, ingestion review, dashboarding, or security investigation
- Experience with Micro sof t Defender for Cloud, Azure Policy , Key Vault, private endpoints, NSGs, Azure Firewall, managed identities, or secure Azure networking patterns
- Experience with Splunk, Splunk ITSI, ServiceNow, auto-ticketing workflows, or enterprise monitoring platforms
- Experience supporting cloud cost optimization efforts, including duplicate ingestion cleanup, workspace rationalization, commitment tier analysis, or log pipeline tiering
- Knowledge of Azure SDKs, Azure CLI, Micro sof t Graph, REST APIs, or cloud automation patterns
- Ability to explain Micro sof t cloud concepts and technical tradeoffs to non-technical stakeholders in plain language
- Ability to identify unde rus ed cloud capabilities, adoption blockers, configuration gaps, or automation opportunities and convert them into practical delivery plans
- Micro sof t Certification such as AZ-900, AZ-104, AZ-500, SC-200, SC-300, or equivalent Certification
CompensationAt Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,900.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity StatementAs part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage PolicyAI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on
your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited
unless permission is explicitly provided.
Work ModelOur people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-DiscriminationAll qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.