Senior Cloud Engineer

Vanguard
Huntsville, AL, United States
6 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$140,000.0 - $152,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Data Analysis Microsoft Antivirus Architectural Patterns Microsoft Azure Bash Shell Cloud Computing Cloud Engineering CompTIA Security+ Data Visualization Linux Infrastructure as a Service (IaaS)
+29 more
Subnetting Virtual Private Networks (VPN) Python (Programming Language) Key Management Network Security Log Analysis Machine Learning Windows Servers Network Virtualization OpenShift Platform as a Service (PAAS) Peering Windows PowerShell Role-Based Access Control Red Hat Enterprise Linux Azure Active Directory Systems Architecture Scripting Cloud Monitoring Delivery Pipeline Azure Powershell HybridCloud Gitlab Event Driven Architecture Kubernetes Azure AKS Terraform Data Pipelines Jenkins

Job description

This is the senior-most cloud seat on our team. You will set the reference architectures the software, DevSecOps, and cyber teams build against, drive technical design with leads and product owners, and keep the environment secure, performant, and accreditation-ready as it scales.

We are a small, team-focused defense contractor. There is no layer of program bureaucracy between an engineer and a decision, and the patterns you set here will hold for the life of the contract. This role is on-site at Redstone Arsenal in Huntsville, AL., * Own the architecture of the government-provided hybrid cloud environment, designing for security, performance, operability, and scale as program requirements evolve

  • Develop and maintain cloud reference architectures and documented baselines that development and engineering teams build against
  • Drive technical design with technical leads and product owners, translating solution requirements into architectural patterns the team can execute
  • Design and govern the Terraform baseline for provisioning and managing cloud resources, ensuring consistent, repeatable deployments across environments
  • Architect and oversee Azure Kubernetes Service (AKS) for containerized deployment, scaling, and orchestration, including image hardening in the deployment pipeline
  • Design identity, access, and encryption architecture using Microsoft Entra ID, Azure Key Vault, and RBAC, and set the standards that keep them consistent
  • Establish and maintain DISA STIG compliance and the technical artifacts supporting the RMF and accreditation process, so compliance is a byproduct of how the platform is built
  • Architect virtual networking (virtual networks, subnets, network security groups, hybrid connectivity) for secure and efficient traffic flow
  • Resolve application-to-platform integration issues across PaaS and IaaS offerings, and provide senior technical support to developer and cyber teams
  • Support the machine learning, data analysis, data visualization, and event-driven architecture work the program depends on
  • Create and maintain comprehensive documentation for system architecture, configurations, and operational procedures

Requirements

  • Bachelor’s degree in a relevant technical field and a minimum of 12 years of relevant experience (a government labor category minimum; see the application note below)
  • Demonstrated experience designing, not only administering, hybrid cloud environments, including migration of on-premise applications and infrastructure to the cloud
  • Hands-on Terraform experience at scale, including module structure, state management, and drift control
  • Hands-on experience with Azure Kubernetes Service (AKS) or equivalent container orchestration, and with CI/CD pipelines using Azure DevOps, GitLab, or Jenkins
  • Advanced knowledge of Microsoft Entra ID and RBAC, and experience with Azure Key Vault, Azure Monitor, Log Analytics, and Microsoft Defender for Cloud
  • Experience hardening systems to DISA STIGs and supporting RMF or ATO documentation
  • Strong understanding of Azure networking, including VNet peering, VPN Gateway, and ExpressRoute
  • Linux and Windows server administration, including patching, configuration, and troubleshooting
  • Active Secret security clearance, and the ability to maintain the clearance required for this position
  • U.S. citizenship
  • Residence within a 75-mile radius of Redstone Arsenal, or willingness to relocate before the start date, with the ability to reliably commute to the customer site as business needs dictate

Certifications (must have, or obtain before starting)

  • CompTIA Security+ CE, or another approved DoD 8570.01M IAT Level II certification
  • One of: Azure Solutions Architect Expert, Azure Administrator Associate, Azure Security Engineer Associate, AWS Certified Solutions Architect, CCSP, or GCSA

Preferred Qualifications

  • Proficiency in scripting with PowerShell, Azure CLI, Python, or Bash
  • Prior experience on an MDA program, or on another large DoD software services contract as part of a prime team
  • Experience with AWS in addition to Azure
  • Machine learning, data pipeline, or data visualization work in a production environment
  • Red Hat or OpenShift administration
  • Experience mentoring engineers and setting technical standards across multiple teams

Benefits & conditions

The base salary range for this position is $140,000 to $152,000, depending on experience and qualifications against the labor category. Benefits include:

  • 15 days (120 hours) of PTO per calendar year in a single combined bank, accruing each pay period and usable for any purpose
  • 11 paid federal holidays
  • Medical, dental, and vision coverage, and a retirement savings plan
  • Up to $2,000 per year in tuition and certification reimbursement
  • Bereavement and jury duty leave, separate from and without reducing the PTO bank

Why Vanguard

We are deliberately small. Every team member has a visible role in the quality and integrity of what we deliver to our government customers, and engineers here own real scope rather than a slice of someone else’s. You get direct access to company leadership, on a team small enough that your work is visible without having to campaign for it.

Application note: your resume must state your degree, graduation year, and dated employment history. The government labor category requires us to verify education and years of experience before an offer can be made.

About the company

Vanguard Defense Solutions is seeking a senior Cloud Engineer to own the architecture of the hybrid-cloud environment supporting the Missile Defense Agency Information Management and Software Services (AIMSS) program at Redstone Arsenal, where we serve as a subcontractor to Integration Innovation, Inc. (i3).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:57 min

Securing sensitive defense infrastructure with dual-vendor cloud strategies

Boris Hecker Boris Hecker +3 · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

5:28 min

Bitcoin scaling and the transition to peer-to-peer transactions

Jad Wahab · LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all