-
Azure Cloud Engineer
- TEKsystems (Mclean, VA)
-
Top Skills' Details
5+ years of Azure cloud infrastructure experience
***Infrastructure as Code (IaC) - experience is a MUST
Azure - Landing zone and VNets
Must be able to script in Powershell or code in Python or Golang
***somewhat active Github
Azure Skills/Services (in order of priority):
Virtual Network
Storage Services
Blob, Queue, Table, File
VM & Scale Sets
Load Balancer
EntraID
Automation
Disk Storage
ExpressRoute
Monitor
Site Recovery
Application Gateway
This role focuses on supporting and enhancing the Azure cloud platform environment. It involves a combination of Business As Usual (BAU) support and critical engineering work. A significant portion of the role is dedicated to ensuring governance, compliance, and security posture within the Azure environment. The primary objective is to proactively address compliance requirements and security findings.
Key Responsibilities:
• Engage proactively in Azure governance and compliance activities.
• Pull and analyze compliance data to identify non-compliance findings.
• Review control adherence and take necessary action on non-compliant resources or configurations.
• Ensure Azure services and the teams utilizing them maintain compliance with established standards.
• Proactively address potential compliance issues before they are identified by auditors or testers.
• Perform security bug fixes to remediate non-compliance issues, which is considered engineering work. This involves problem-solving and developing solutions to bring configurations back into compliance.
• Participate in control validation processes and testing walkthroughs. Provide documentation or walkthroughs to show how controls are met and monitored.
• Understand and interpret existing runbooks, many of which are written in PowerShell, used for monitoring control effectiveness.
• Conduct feasibility reviews for net new controls proposed by the cyber risk team, assessing their technical viability within Azure.
• Review, update, and/or create new detective controls. This may involve translating existing controls from PowerShell runbooks into Wiz/Rego. Implementation of these controls is the responsibility of this role.
• Identify issues related to controls where policies are not used and monitoring relies on runbooks (often Azure Automation runbooks written in PowerShell).
• Contribute to discussions and potentially the implementation of a future disconnected Azure tenant/sandbox environment, with a focus on establishing controls and governance
• May contribute to identity-related work within Azure, understanding authentication and authorization concepts.
Required Skills & Qualifications:
• Solid foundation in cloud infrastructure, with expertise in Microsoft Azure services and architecture. Must understand Azure services inside out, including various configurations and associated risks.
• Ability to build with code; again the role is not that of a cloud administrator solely performing tasks via the GUI.
• Essential knowledge of PowerShell is required to understand existing runbooks and control configurations.
• Familiarity with or the ability to quickly learn Wiz/Rego for implementing detective controls is necessary.
• Understanding of cloud security principles, governance frameworks, and compliance requirements.
• Ability to troubleshoot technical issues within the Azure platform.
• Understanding of cloud-based identity and access management (IAM) concepts, including authentication and authorization.
Note: The current work priority for Azure is BAU and security bug fixes (non-compliance remediation).
Skills
Golang, azure, restful api, infrastructure as code, IaC, landing zones, powershell
Pay and Benefits
The pay range for this position is $65.00 - $75.00/hr.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a fully remote position.
Application Deadline
This position is anticipated to close on Jun 11, 2025.
About TEKsystems and TEKsystems Global Services
We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
-