- Company Name
- AllianceIT Inc
- Job Title
- Senior Azure Security Engineer
- Job Description
-
**Job Title:**
Senior Azure Security Engineer
**Role Summary:**
Design, implement, and sustain secure Azure Government cloud environments for classified (Secret or higher) government systems. Lead the entire security lifecycle – architecture, controls, automation, monitoring, compliance, and Authority to Operate (ATO) authorization.
**Expectations:**
- Minimum 10 years of information security experience, 5 + in cloud security and 2 + specifically in Azure Government/DoD environments.
- Active Secret clearance required at start.
- DoD 8570 IAT Level II certification (Security+, CISSP, or CISM).
- Proven track record of achieving and maintaining ATO for classified systems.
**Key Responsibilities:**
- Architect and enforce zero‑trust, role‑based access, and identity federation (Azure AD B2B/B2C with CAC/PIV).
- Configure and manage Azure security controls: Microsoft Defender for Cloud, Azure Key Vault, Azure Policy, NSGs, Private Endpoints, and related networking.
- Automate infrastructure and security operations with PowerShell, Terraform, Bicep/ARM templates.
- Integrate SIEM/SOAR (Microsoft Sentinel) for continuous monitoring, logging, and incident response.
- Conduct vulnerability assessments and remediate in line with NIST 800-53, DoD STIGs, JSIG, and ICD 503.
- Collaborate with developers and compliance teams to embed security into DevSecOps pipelines.
- Prepare and maintain System Security Plans (SSPs), Plans of Actions & Milestones (POA&M), and other RMF documentation for ATO.
- Lead risk assessments, support third‑party audits, and coordinate with ISSO, program managers, and authorizing officials.
- Maintain continuous monitoring plans and comply with agency change‑management processes.
**Required Skills:**
- Azure Government / DoD cloud security, Azure AD B2B/B2C, Azure Defender, Key Vault, Policy, NSG, Private Endpoints.
- Scripting: PowerShell, Python, Bash.
- Infrastructure‑as‑Code: ARM, Bicep, Terraform.
- SIEM/SOAR: Microsoft Sentinel.
- Regulatory frameworks: NIST 800-53, DoD STIGs, JSIG, FedRAMP High, SRG, ICD 503.
- RMF tools: eMASS, SCAP, patching, ACM.
- Network security: IPsec, VPN, PKI, firewalls, proxies, DNS, access lists.
- Agile development, Jira, secure coding practices.
- Strong analytical, organizational, and communication abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Information Systems Security or related field (Master’s or equivalent experience preferred).
- Active Secret clearance (or higher).
- DoD 8570 IAT Level II certification (Security+, CISSP, or CISM).
Washington dc-baltimore, United states
On site
Senior
17-03-2026