2 hours ago
Tokyo, JapanSenior
Base Salary
$108k - $184k/yr
Responsibilities
- Deploy and manage cloud landing zone architectures across Azure, AWS, and Google Cloud Platform using automated provisioning, identity controls, guardrails, network security, and policy enforcement.
- Implement infrastructure and policy as code with IaC templates, GitHub Actions, and CI/CD pipelines.
- Build and maintain integrations using APIs, SDKs, webhooks, and event streams with secrets management, least-privilege access, error handling, and logging.
- Deploy and manage Azure Virtual Desktop and maintain DNS-as-code, certificates, and related configurations.
- Integrate platform logs, alerts, and risk signals into central monitoring tools and automate detection of misconfigurations, risky behavior, and suspicious activity.
- Review cloud configurations against security baselines and compliance requirements and use compliance-as-code tooling where available.
- Coordinate cloud access policies, device compliance rules, and conditional access with identity, device, and cybersecurity teams as part of a Zero Trust model.
- Maintain architecture documentation, configuration baselines, runbooks, and operational procedures.
- Resolve complex cloud platform issues escalated from operations and service desk teams.
Requirements
- Bachelor's degree or equivalent experience.
- At least 5 years of experience in cloud engineering or platform operations.
- At least 3 years deploying and managing production cloud landing zones in Azure, AWS, or GCP.
- At least 2 years implementing infrastructure as code with tools such as Terraform, Bicep, or CloudFormation.
- At least 2 years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies.
- U.S. citizenship is required, and candidates must be authorized to work and perform the work in the United States.
- Ability to obtain and maintain a Public Trust background investigation.
- Preferred qualifications include Azure Virtual Desktop or virtual desktop infrastructure experience; familiarity with NIST 800-53, FedRAMP, CIS benchmarks, and CISA Zero Trust guidelines; SIEM or SOAR integration experience; relevant Azure, AWS, or Google Cloud certifications; and DevSecOps delivery experience with automated security testing in CI/CD pipelines.
Benefits
- Remote-friendly work arrangement with occasional onsite requirements in the Washington, DC Metro area.
- The position must be performed in the United States, with foreign-location access and personal VPN connections prohibited.
- Full-time employment pay range is $108,006.00-$183,610.00.
- The role is contingent upon a contract award.
