
Senior Cloud DevOps Network Engineer (FedRAMP, Azure, Advanced Networking)
OneStream Software2 months ago
Remote, United StatesSenior
Base Salary
$140k - $172k/yr
Responsibilities
- Design, implement, continuously monitor, and secure Azure cloud solutions compliant with FedRAMP High and IL4 requirements.
- Lead development of modular Infrastructure-as-Code using Terraform, PowerShell, ARM, Bicep, and YAML.
- Design and implement advanced Azure networking, routing, firewall configurations, private connectivity, IPv6 routing, and egress filtering.
- Translate DISA STIGs and NIST controls into enforceable network guardrails and evidence artifacts.
- Lead moderate-complexity automation and service projects from estimation through completion.
- Maintain reliability of automated systems, participate in the production on-call rotation, and assist with debugging production issues.
- Provide technical leadership through mentoring, design feedback, pull-request reviews, documentation, and knowledge-base updates.
- Monitor Azure and FedRAMP regulatory changes and advise teams on required technical adjustments.
- Collaborate with internal staff, managers, customers, Compliance, and Security teams on cloud operations and controls.
Requirements
- Bachelor’s degree in computer science, engineering, or a technology-related field, or equivalent work experience.
- At least 8 years of cloud infrastructure experience and at least 2 years of experience with compliance programs and security control sets such as NIST SP 800-53, FedRAMP High, and IL4.
- Expert knowledge of VNets, vWAN, subnets, UDRs, routing, peering, ExpressRoute, VPN Gateway, Private Link/Endpoint, Azure Firewall, NSG/ASG, WAF, and Application Gateway.
- Hands-on experience designing networks and configuring firewalls for government-network connectivity using Azure Firewall and/or Palo Alto.
- Hands-on experience with IPv6 routing and strict egress filtering strategies.
- Advanced Infrastructure-as-Code experience with Terraform, CloudFormation, Bicep, or ARM templates on Azure, AWS, or GCP.
- Deep knowledge of Ansible, PowerShell DSC, Chef, and Puppet.
- Strong understanding of Azure Kubernetes Service and container-based deployments, or platforms such as OpenShift, GKS, and EKS.
- At least 8 years of hands-on experience automating processes with PowerShell, Bash, CLI, REST APIs, Python, ARM Templates, or other scripting languages.
- Experience with source-control tools such as Git, BitBucket, or GitHub.
- Experience with Microsoft Azure, AWS or GCP, Windows 11, Windows Server, IIS, Microsoft SQL Server, and Active Directory.
- Preferred experience with cloud, managed-service, or SaaS providers and at least 8 years of relevant Azure experience using Infrastructure-as-Code.
- Preferred experience with Windows Server 2016–2022, IIS, Microsoft SQL Server, Azure Active Directory, Debian, Ubuntu, or other Linux distributions.
- Certifications such as Azure Administrator Associate, Azure Solutions Architect Expert, CCNP, CCIE, CISSP, Azure DevOps Engineer Expert, Certified Kubernetes Administrator, ITIL Foundation, MCP, CompTIA Security+, or CompTIA Network+ are preferred.
- Ability to work independently, address ambiguous problems, prioritize and estimate work, communicate with management, mentor others, and operate effectively in a fast-paced environment.
Benefits
- Remote, USA, full-time position with regular travel not expected.
- Medical, dental, vision, life, short- and long-term disability, vacation time, and paid holidays.
- 401(k) retirement plan and professional-development and training opportunities.
- All candidates must be legally authorized to work for any company in the country where the position is located without sponsorship.