Lead Azure Architecture SME
Location: Washington, DC – Hybrid (3 days onsite)
Experience: 10+ years
Clearance: Active Secret Clearance required
Openings: 1
Job Summary
We are looking for a Lead Azure Architecture SME to design, implement, and support secure and scalable Microsoft Azure solutions in a government environment. The ideal candidate will have strong expertise in Azure architecture, networking, Microsoft Entra ID, cloud migration, DevOps, and Infrastructure as Code (IaC).
The candidate will provide technical leadership, work directly with government customers, lead Azure migration activities, and support cloud-to-on-premises integrations.
Key Responsibilities
· Lead end-to-end Microsoft Azure architecture and solution design.
· Create architecture diagrams and technical documentation using MS Visio.
· Lead technical discussions and presentations with customers and stakeholders.
· Design and implement Azure networking solutions including:
o VNets and Subnets
o NSGs
o Azure Firewall
o Load Balancers
o Routing
o ExpressRoute and VPN
· Lead Azure migration activities using Azure Site Recovery (ASR).
· Plan dependency mapping, failover testing, and production cutovers.
· Design secure connectivity between Azure and on-premises environments.
· Design and implement Microsoft Entra ID architecture, including Conditional Access, Identity Governance, RBAC, and cross-tenant integration.
· Develop and manage Azure infrastructure using Terraform, Bicep, ARM Templates, Azure DevOps, and GitHub Actions.
· Use PowerShell or Ansible for automation and infrastructure management.
· Support security hardening and compliance with DISA STIGs and DoD requirements.
· Troubleshoot Azure networking and infrastructure issues.
· Mentor system administrators and provide technical guidance.
· Work with Agile/Scrum teams and support government cloud environments.
Required Qualifications
· Bachelor's degree or higher in Computer Science, Information Technology, Systems Engineering, or a related field.
· 10+ years of relevant IT/engineering experience.
· 5+ years of experience working with Azure IL5/IL6 environments.
· Strong experience with Azure architecture and networking.
· Hands-on experience with Microsoft Entra ID and Entra Monitor.
· Strong knowledge of:
o Azure VNets
o NSGs
o Azure Firewall
o ExpressRoute/VPN
o Load Balancing
o Routing
· Experience with Azure Site Recovery and migration solutions.
· Experience with Terraform, Bicep, ARM, Azure DevOps, or GitHub Actions.
· Strong PowerShell or Ansible scripting experience.
· Understanding of CI/CD and secure pipeline development.
· CompTIA Security+ certification required.
· Experience with security hardening and DISA STIG compliance.
· Active Secret clearance required.
· ship required.
Preferred Qualifications
· Experience with Azure migration projects.
· Experience with cloud-based databases/data management.
· Experience creating/updating architecture diagrams using MS Visio.
· Experience in Agile/Scrum environments.
· Experience working with Federal or State Government customers.
· Additional relevant Azure or security certifications.
Key Skills
Microsoft Azure | Azure Architecture | Azure Networking | Azure IL5/IL6 | Microsoft Entra ID | Azure Site Recovery | ExpressRoute | VPN | Azure Firewall | Terraform | Bicep | ARM | Azure DevOps | GitHub Actions | PowerShell | Ansible | DISA STIG | Cloud Migration | DevOps