Cloud Computing Infrastructure Architect

Booz Allen HamiltonSan Diego, CA
$86,900 - $198,000Remote

About The Position

Cloud security is moving beyond point-in-time compliance toward continuously measured, automated, and resilient security operations. Federal organizations need cloud platforms that can continuously enforce secure configurations, produce trustworthy security evidence, detect sophisticated threats, and respond at machine speed. We are looking for an experienced Azure Cloud Security Engineering Lead to drive the design and implementation of advanced security capabilities within Microsoft Azure Government. In this role, you will lead technical workstreams that strengthen cloud security, modernize cyber operations, improve security telemetry, and advance continuous security assurance aligned with evolving federal requirements. You will work across Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, automation, and Infrastructure as Code to turn security objectives into deployable engineering solutions. You will help continuously identify configuration drift, validate security controls, improve detection coverage, automate response, strengthen data protection, and create measurable evidence that security capabilities are operating as intended. You will also modernize security data and logging architectures so the organization collects the right telemetry - not simply more telemetry. This includes rationalizing duplicate data flows, improving classification and retention, controlling Sentinel cost, and maintaining the visibility required to defend against sophisticated and increasingly AI-enabled nation-state threats. The role requires someone who can move comfortably between architecture and hands-on engineering, guide a small team, and drive work from concept through operational adoption. Grow your skills while helping build the next generation of cloud security operations and continuous assurance in Azure Government.

Requirements

  • 5+ years of experience designing, engineering, or securing Microsoft Azure environments, including cloud security, networking, identity, monitoring, DevSecOps, or infrastructure
  • Experience designing or engineering security solutions within Microsoft Azure Government, and engineering Azure Policy, secure configuration baselines, and automated configuration-drift detection or remediation
  • Experience implementing and operating Microsoft Sentinel, including data connectors, Data Collection Rules, analytic rules, automation, workbooks, KQL, and monitoring architectures, and with Microsoft Defender for Cloud, Defender XDR, or Microsoft security capabilities
  • Experience designing Azure logging and monitoring architectures using Azure Monitor, Log Analytics, Diagnostic Settings, Event Hub, Resource Graph, and Sentinel
  • Experience developing Infrastructure as Code with Terraform and integrating security into CI/CD or DevSecOps pipelines
  • Experience securing cloud identity, including Entra ID, RBAC, PIM, managed identities, service principals, and Key Vault
  • Ability to lead technical workstreams from architecture and design through implementation, testing, deployment, and operational transition while guiding a small engineering team
  • Public Trust
  • Bachelor's degree
  • Microsoft Azure certification

Nice To Haves

  • Experience supporting FedRAMP, FedRAMP 20x, NIST SP 800-53, Continuous Monitoring, or federal Authorization to Operate processes
  • Experience building automated security evidence, continuous control monitoring, compliance-as-code, or Key Security Indicator measurements
  • Experience implementing Detection-as-Code, automated detection testing, or MITRE ATT&CK-aligned security capabilities
  • Experience designing defenses against advanced persistent threats, nation-state adversaries, or AI-enabled cyber attacks
  • Experience with Microsoft Purview, Data Loss Prevention, data classification, or exfiltration monitoring, and integrating vulnerability-management tooling such as Defender, Fortify, Sonatype, Azure DevOps, or ServiceNow
  • Experience with software supply-chain security, including SBOMs, artifact provenance, signing, dependency security, or build attestations
  • Experience implementing Azure backup, recovery, resiliency, or cyber-recovery capabilities
  • Knowledge of OMB M-26-14 logging and network visibility requirements
  • Possession of strong client-facing communication skills
  • Security-focused certifications such as CISSP, CCSP, AZ-500, SC-100, or equivalent cloud security certifications

Responsibilities

  • Drive the design and implementation of advanced security capabilities within Microsoft Azure Government.
  • Lead technical workstreams that strengthen cloud security, modernize cyber operations, improve security telemetry, and advance continuous security assurance aligned with evolving federal requirements.
  • Work across Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, automation, and Infrastructure as Code to turn security objectives into deployable engineering solutions.
  • Continuously identify configuration drift, validate security controls, improve detection coverage, automate response, strengthen data protection, and create measurable evidence that security capabilities are operating as intended.
  • Modernize security data and logging architectures so the organization collects the right telemetry.
  • Rationalize duplicate data flows, improve classification and retention, control Sentinel cost, and maintain the visibility required to defend against sophisticated and increasingly AI-enabled nation-state threats.
  • Move comfortably between architecture and hands-on engineering.
  • Guide a small team.
  • Drive work from concept through operational adoption.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service