Cloud Platform Engineer

ICFWashington, DC
Hybrid

About The Position

This role is contingent upon a contract award. ICF is seeking a Cloud Platform Engineer to deploy, configure, and maintain cloud infrastructure for a federal technology program. Reporting to the Cloud / Enterprise Architecture Lead, this role is responsible for building and operating the multi-cloud landing zone environment using infrastructure-as-code and DevSecOps practices. Where the EA Lead sets architecture standards and policy, this role executes and maintains them in production. The ideal candidate is a hands-on cloud infrastructure engineer who writes automation before clicking buttons and treats configuration as code. The right candidate has deployed and operated cloud landing zones in federal environments and is comfortable working across Azure, AWS, and GCP with consistent tooling and governance discipline.

Requirements

  • Bachelor's degree or equivalent
  • 5+ years of experience in cloud engineering or platform operations
  • 3+ years deploying and managing cloud landing zones in Azure, AWS, or GCP in production environments
  • 2+ years implementing infrastructure as code using tools such as Terraform, Bicep, CloudFormation, or equivalent
  • 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies
  • U.S. Citizenship due to federal contract requirements
  • Ability to obtain and maintain a Public Trust background investigation
  • Candidate must reside in the US, be authorized to work in the US, and work must be performed in the US

Nice To Haves

  • Experience managing Azure Virtual Desktop or equivalent virtual desktop infrastructure
  • Familiarity with NIST 800-53, FedRAMP, CIS benchmarks, and CISA Zero Trust guidelines as they apply to cloud infrastructure
  • Experience integrating platform telemetry with SIEM or SOAR tools for automated alerting and remediation
  • Relevant certifications such as Microsoft Azure Administrator, AWS SysOps Administrator, or Google Cloud Professional Cloud Engineer
  • Experience with DevSecOps delivery practices including automated security testing in CI/CD pipelines

Responsibilities

  • Deploy and manage cloud landing zone architectures across Azure, AWS, and Google Cloud Platform using repeatable, automated provisioning with identity-first controls, guardrails, network security, and policy enforcement.
  • Implement infrastructure and policy as code using IaC templates, GitHub Actions, and CI/CD pipelines so environments can be created, updated, and audited consistently and without manual intervention.
  • Build and maintain system integrations using APIs, SDKs, webhooks, and event streams, with proper secrets management, least-privilege scoping, error handling, and logging.
  • Deploy and manage Azure Virtual Desktop for remote access scenarios and specific user personas.
  • Manage DNS-as-code for all agency platforms and services, including certificates and related configurations.
  • Integrate platform logs, alerts, and risk signals into central monitoring tools, and use automation to flag misconfigurations, risky behavior, and suspicious activity.
  • Perform quarterly reviews of cloud environment configurations against security baselines and compliance requirements, using compliance-as-code tooling where available.
  • Coordinate with identity, device, and cybersecurity teams to ensure cloud access policies, device compliance rules, and conditional access work together as part of a consistent Zero Trust model.
  • Maintain documentation of cloud architectures, configuration baselines, runbooks, and operational procedures so others can safely operate and extend the environment.
  • Resolve complex cloud platform issues escalated from operations and service desk teams.

Benefits

  • ICF is an equal opportunity employer
  • Reasonable Accommodations are available
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service