Administer and maintain AWS and Azure environments, including day-to-day operations of virtual machines, networking, and storage across both providers
AWS: deploy, maintain, and optimize EC2, RDS, S3, IAM, KMS, Secrets Manager, and CloudTrail; manage VPCs, subnets, routing tables, security groups, and NACLs
Azure: administer virtual machines, virtual networks and NSGs, storage accounts, Azure Files, Key Vault, Azure Virtual Desktop, and Site Recovery across subscriptions
Build and manage hardened VM images and golden images for consistent, repeatable deployments
Implement and support high availability, auto-scaling, backup, and disaster recovery configurations
Support multi-account and multi-subscription governance structures — AWS Organizations, Azure Management Groups, and equivalent landing-zone constructs
Own the Microsoft 365 tenant end to end: Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and licensing
Administer the identity plane — Conditional Access policies, MFA enforcement, RBAC and least privilege, privileged access, hybrid identity, and application registrations. and role assignments, and conditional access policies
Run the full user lifecycle: provisioning, onboarding, role changes, offboarding, and access reviews, automated wherever the volume justifies it
Manage the endpoint fleet through Intune, including compliance policies, configuration profiles, patching, and device lifecycle
Administer single sign-on and provisioning integrations (SAML, SCIM) between Entra ID and the SaaS platforms we operate
Support data governance and protection through Purview, sensitivity labels, and DLP policy where applicable
Design and maintain infrastructure using Terraform — modular design, remote state management, and workspace strategy — across both AWS and Azure
Build reusable, secure baseline modules for network architecture, IAM roles, logging, monitoring, and encryption
Automate operational workflows in PowerShell, Bash, and Python, including Microsoft Graph API automation for identity and tenant tasks
Integrate infrastructure provisioning and security controls into CI/CD pipelines (GitHub Actions, GitLab CI, or equivalent) and maintain version-controlled infrastructure repositories
Implement automated drift detection and remediation, and enforce policy-as-code guardrails
Configure and monitor AWS CloudTrail, GuardDuty, Security Hub, and Config alongside Microsoft Defender and Entra ID sign-in and audit logging
Support SIEM integration (Splunk, Microsoft Sentinel, or equivalent) and assist with incident response
Maintain the vulnerability management lifecycle: patching, remediation tracking, and reporting
Support compliance aligned to NIST SP 800-171, CMMC, and FedRAMP or SOC 2 as applicable, including evidence collection for assessments
Administer the AI platforms in our environment — Anthropic Claude, ChatGPT, AWS Bedrock, and Microsoft 365 Copilot — including seats and licensing, SSO and provisioning, retention and data controls, connector and agent governance, and spend limits
Enforce and communicate standards for what data may be placed into AI tooling, particularly where CUI or controlled data is involved
Partner with engineering, security, and operations to deliver reliable, scalable services
Produce and maintain architecture diagrams, runbooks, SOPs, and audit evidence artifacts without being asked for them
Contribute to capacity forecasting, resource planning, and cloud cost management
5+ years in systems administration, cloud operations, or infrastructure engineering
3+ years hands-on administering AWS in production, including virtual machine administration, networking, and IAM
2+ years administering a Microsoft 365 tenant with real admin rights — Entra ID, Exchange Online, Conditional Access, licensing, and user lifecycle. Help-desk support of Microsoft 365 does not meet this bar
Hands-on Microsoft Azure administration in a production environment
Demonstrated automation of operational workflows using PowerShell, Bash, or Python; working Terraform experience
Strong understanding of IAM, encryption (KMS, TLS), and network segmentation
Experience with Linux (RHEL or Amazon Linux) and Windows Server in a cloud context
Experience working in Department of Defense or Department of War environments and applying their security requirements
Disciplined documentation habits — runbooks, SOPs, and configuration records maintained as a matter of course
US Citizenship Required. All work must be performed within the United States
Microsoft 365 GCC High tenant experience
Terraform depth including modular design, state management, and leading IaC migrations from legacy tooling
Container platform experience — Docker with ECS, EKS, or AKS
AWS certifications (Solutions Architect, SysOps Administrator, Security Specialty) or Azure equivalents (AZ-104); Microsoft 365 Administrator (MS-102); CompTIA Security+
AWS Control Tower, Landing Zones, or Azure Landing Zone governance tooling
SIEM platform experience (Splunk, Microsoft Sentinel)
Administration of AI platforms at the tenant or account level - Anthropic, OpenAI, Bedrock and Copilot
Managed service provider background administering across many client tenants
Regulated-industry experience: defense (CMMC, NIST 800-171), healthcare (HIPAA), or financial services (SOC 2)
Active DoD security clearance (Secret or above), or eligibility to obtain and maintain one
Infrastructure and identity ownership — takes end-to-end accountability for the health, security, and performance of both the infrastructure and the identity plane
Automation mindset — proactively replaces manual processes with scalable, repeatable solutions
Security-first thinking — embeds security into every layer of design and operations rather than bolting it on
Cross-functional communication — translates technical complexity for business and compliance stakeholders
Disciplined documentation — produces clear, audit-ready artifacts without being prompted
Adaptability — comfortable across cloud providers, toolchains, and an evolving compliance landscape
AWS, Azure, and the Microsoft 365 tenant are stable, secure, observable, and documented
Identity is governed: access follows least privilege, joiners and leavers are handled cleanly, and access reviews are routine
Infrastructure changes are repeatable through code, with clear review and rollback paths
Monitoring, logging, and vulnerability remidiation are routine rather than scramble-driven
Audit artifacts - diagrams, runbooks, evidence - stay current and usable
A fully remote, results-based environment
Competitive salary, bonus and equity package
100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
Unlimited PTO, with your manager's approval
Flexible work environment where you manage your work day
14 weeks of fully-paid parental leave
Career track opportunity with potential for rapid advancement with strong performance as the firm grows
100% employer paid, comprehensive health care including medical, dental, and vision for you and your family
Paid maternity and paternity for 14 weeks at employees' normal pay
Unlimited PTO, with management approval
Opportunities for professional development and continued learning
Optional 401K, FSA, and equity incentives available
Mental health benefits are available through Tara Mind
Cost effective GLP-1 solutions available through Crux
Managing and administering your application throughout the hiring process
Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases
Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories