We are seeking a highly skilled Senior Azure Cloud Engineer to support critical mission infrastructure. The ideal candidate will have extensive hands-on experience designing, deploying, and maintaining secure Azure environments, with a primary focus on robust identity and access management using Microsoft Entra ID.
Required Minimum Qualifications
- Clearance: Must hold a current DoW Secret clearance and be eligible for TS/SCI.
- Education: Bachelor’s degree in a technical discipline.
- Experience: A minimum of 5 years of dedicated, hands-on engineering and administration experience within Microsoft Azure.
- Identity Expertise: Proven Subject Matter Expert (SME) level proficiency in Microsoft Entra ID architecture and management.
Key Skills: Microsoft Entra ID (Core Requirement)
The candidate must demonstrate strong technical proficiency and hands-on experience in the following Entra ID (formerly Azure AD) capabilities:
- Identity & Access Management (IAM):
- Demonstrated ability to design and implement secure identity lifecycle management, including automated user provisioning and de-provisioning with SCIM (System for Cross-domain Identity Management).
- Expertise in architecting and enforcing comprehensive Role-Based Access Control (RBAC) models at all scopes (Management Group, Subscription, Resource Group, and individual Resource) based on the principle of least privilege.
- Experience creating and managing custom RBAC roles to meet specific mission requirements that are not covered by built-in roles.
- Proven experience conducting periodic access reviews for privileged and non-privileged accounts to ensure compliance and reduce standing access.
- Certificate-Based Authentication (CBA) & CAC Integration:
- Deep expertise in configuring and deploying Entra ID Certificate-Based Authentication (CBA) to enable phishing-resistant, password less authentication natively in the cloud.
- Hands-on experience integrating Department of War (DoW) Common Access Cards (CAC) and Public Key Infrastructure (PKI) certificates with cloud identities.
- Proficiency in managing trusted Certificate Authorities (CAs), uploading Certificate Revocation Lists (CRLs), and configuring certificate bindings (e.g., mapping Principal Name or RFC822Name to User Principal Name).
- Experience enforcing strict CAC-only access to highly sensitive mission environments and applications by leveraging Conditional Access Authentication Strength policies.
- Conditional Access:
- Deep understanding of building, testing, and enforcing complex Conditional Access policies to secure user access and protect mission data.
- Experience leveraging a wide range of signals, including user/group membership, named locations (IP ranges), device compliance state (via Intune), and sign-in/user risk levels.
- Proficiency in applying granular controls, such as enforcing Multi-Factor Authentication (MFA), requiring compliant devices, limiting session lifetimes, and blocking legacy authentication protocols.
- Skilled in using the “what-if” tool to validate policy changes before deployment to avoid user lockout or mission interruption.
- Privileged Identity Management (PIM):
- Expertise in configuring and managing PIM for both Entra ID roles and Azure resource roles to govern privileged access.
- Proven ability to implement just-in-time (JIT) access, time-bound role assignments, and custom approval workflows for activating privileged accounts.
- Experience establishing and running access reviews for all privileged roles to ensure only authorized personnel maintain eligibility.
- Ability to audit PIM activity, configure alerts for suspicious activations, and generate compliance reports.
- Enterprise Applications & Single Sign-On (SSO):
- Extensive experience registering and managing Enterprise Applications, including gallery and non-gallery apps, to enable secure SSO.
- Strong understanding of modern authentication protocols (SAML 2.0, OAuth 2.0, and OpenID Connect) and experience integrating applications using these standards.
- Proficiency in managing API permissions, application consent policies, and service principal security to prevent illicit consent grant attacks and ensure secure application-to-application communication.
- Hybrid Identity:
- Hands-on experience deploying, managing, and troubleshooting hybrid identity solutions using Microsoft Entra Connect or Entra Connect Cloud Sync.
- In-depth knowledge of various authentication methods, including Password Hash Synchronization (PHS), Pass-Through Authentication (PTA), and Federation (AD FS), and the ability to recommend the appropriate model based on security and operational requirements.
- Experience monitoring synchronization health with Entra Connect Health and troubleshooting object synchronization errors.
- Identity Protection & Security:
- Proven ability to leverage Entra ID Identity Protection to detect, investigate, and remediate identity-based risks.
- Experience configuring and tuning user risk policies and sign-in risk policies and integrating them with Conditional Access for automated responses, such as forcing a secure password reset or blocking access.
- Deep understanding of Continuous Access Evaluation (CAE) and its role in enforcing security policies in near real-time by revoking access based on critical events.
Highly Desired Qualifications
Candidates possessing the following supplementary skills will be given strong preference:
- Microsoft Sentinel: Experience deploying and configuring Sentinel for cloud-native SIEM/SOAR capabilities, including custom analytic rules and playbooks.
- Microsoft Defender for Cloud: Proficiency in managing Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) to secure Azure resources.
- Azure Arc: Experience onboarding and managing hybrid, multi-cloud, or on-premises servers and Kubernetes clusters through Azure Arc.
To apply for this job email your details to jobs@dei.net