Back to Jobs
DEFCON AI
Development 16h ago

Cloud Systems Engineer

DEFCON AI
United StatesUnited States
Full-time
$160,000-$190,000
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
Python2h 41mFree Trial ✨
Start 10-Day Free Trial
Cloud EngineeringTerraformCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

About the Role

DEFCON AI is hiring a Cloud Systems Engineer to administer AWS, Microsoft Azure, and our Microsoft 365 and Entra ID tenant. This is a single, senior seat covering both halves of the environment β€” the infrastructure that runs our workloads and the identity plane that governs who reaches them β€” with end-to-end ownership of each.

The work spans virtual machine provisioning and network architecture, Infrastructure as Code, tenant and identity administration, endpoint management, automation, and continuous monitoring. We operate under defense-sector compliance obligations, so security hardening and audit-ready documentation are part of the job rather than an afterthought. Experience in regulated or compliance-driven environments β€” defense, healthcare, or financial services β€” is a strong plus.

Responsibilities:

Cloud Infrastructure and Virtual Systems Administration

  • Administer and maintain AWS and Azure environments, including day-to-day operations of virtual machines, networking, and storage across both providers.
  • AWS: deploy, maintain, and optimize EC2, RDS, S3, IAM, KMS, Secrets Manager, and CloudTrail; manage VPCs, subnets, routing tables, security groups, and NACLs.
  • Azure: administer virtual machines, virtual networks and NSGs, storage accounts, Azure Files, Key Vault, Azure Virtual Desktop, and Site Recovery across subscriptions.
  • Build and manage hardened VM images and golden images for consistent, repeatable deployments.
  • Implement and support high availability, auto-scaling, backup, and disaster recovery configurations.
  • Support multi-account and multi-subscription governance structures β€” AWS Organizations, Azure Management Groups, and equivalent landing-zone constructs.

Identity & Microsoft 365 Administration

  • Own the Microsoft 365 tenant end to end: Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and licensing.
  • Administer the identity plane β€” Conditional Access policies, MFA enforcement, RBAC and least privilege, privileged access, hybrid identity, and application registrations, and role assignments, and conditional access policies.
  • Run the full user lifecycle: provisioning, onboarding, role changes, offboarding, and access reviews, automated wherever the volume justifies it.
  • Manage the endpoint fleet through Intune, including compliance policies, configuration profiles, patching, and device lifecycle.
  • Administer single sign-on and provisioning integrations (SAML, SCIM) between Entra ID and the SaaS platforms we operate.
  • Support data governance and protection through Purview, sensitivity labels, and DLP policy where applicable.

Infrastructure as Code and Automation

  • Design and maintain infrastructure using Terraform β€” modular design, remote state management, and workspace strategy β€” across both AWS and Azure.
  • Build reusable, secure baseline modules for network architecture, IAM roles, logging, monitoring, and encryption.
  • Automate operational workflows in PowerShell, Bash, and Python, including Microsoft Graph API automation for identity and tenant tasks.
  • Integrate infrastructure provisioning and security controls into CI/CD pipelines (GitHub Actions, GitLab CI, or equivalent) and maintain version-controlled infrastructure repositories.
  • Implement automated drift detection and remediation, and enforce policy-as-code guardrails.

Security, Compliance & Monitoring

  • Apply and maintain hardening baselines (CIS Benchmarks, DISA STIGs) across Linux and Windows systems and cloud tenants.
  • Configure and monitor AWS CloudTrail, GuardDuty, Security Hub, and Config alongside Microsoft Defender and Entra ID sign-in and audit logging.
  • Support SIEM integration (Splunk, Microsoft Sentinel, or equivalent) and assist with incident response.
  • Maintain the vulnerability management lifecycle: patching, remediation tracking, and reporting.
  • Support compliance aligned to NIST SP 800-171, CMMC, and FedRAMP or SOC 2 as applicable, including evidence collection for assessments.

AI Platform Administration

  • Administer the AI platforms in our environment β€” Anthropic Claude, ChatGPT, AWS Bedrock, and Microsoft 365 Copilot β€” including seats and licensing, SSO and provisioning, retention and data controls, connector and agent governance, and spend limits.
  • Enforce and communicate standards for what data may be placed into AI tooling, particularly where CUI or controlled data is involved.

Collaboration and Documentation

  • Partner with engineering, security, and operations to deliver reliable, scalable services.
  • Produce and maintain architecture diagrams, runbooks, SOPs, and audit evidence artifacts without being asked for them.
  • Contribute to capacity forecasting, resource planning, and cloud cost management.

Qualifications:

  • 5+ years in systems administration, cloud operations, or infrastructure engineering.
  • 3+ years hands-on administering AWS in production, including virtual machine administration, networking, and IAM.
  • 2+ years administering a Microsoft 365 tenant with real admin rights β€” Entra ID, Exchange Online, Conditional Access, licensing, and user lifecycle. Help-desk support of Microsoft 365 does not meet this bar.
  • Hands-on Microsoft Azure administration in a production environment.
  • Demonstrated automation of operational workflows using PowerShell, Bash, or Python; working Terraform experience.
  • Strong understanding of IAM, encryption (KMS, TLS), and network segmentation.
  • Experience with Linux (RHEL or Amazon Linux) and Windows Server in a cloud context.
  • Experience working in Department of Defense or Department of War environments and applying their security requirements.
  • Disciplined documentation habits β€” runbooks, SOPs, and configuration records maintained as a matter of course.
  • US Citizenship Required. All work must be performed within the United States.

Preferred Qualifications:

  • Microsoft 365 GCC High tenant experience.
  • Terraform depth including modular design, state management, and leading IaC migrations from legacy tooling.
  • Container platform experience β€” Docker with ECS, EKS, or AKS.
  • AWS certifications (Solutions Architect, SysOps Administrator, Security Specialty) or Azure equivalents (AZ-104); Microsoft 365 Administrator (MS-102); CompTIA Security+.
  • AWS Control Tower, Landing Zones, or Azure Landing Zone governance tooling.
  • SIEM platform experience (Splunk, Microsoft Sentinel).
  • Administration of AI platforms at the tenant or account level - Anthropic, OpenAI, Bedrock and Copilot.
  • Managed service provider background administering across many client tenants.
  • Regulated-industry experience: defense (CMMC, NIST 800-171), healthcare (HIPAA), or financial services (SOC 2).
  • Active DoD security clearance (Secret or above), or eligibility to obtain and maintain one.

Core Competencies

  • Infrastructure and identity ownership β€” takes end-to-end accountability for the health, security, and performance of both the infrastructure and the identity plane.
  • Automation mindset β€” proactively replaces manual processes with scalable, repeatable solutions.
  • Security-first thinking β€” embeds security into every layer of design and operations rather than bolting it on.
  • Cross-functional communication β€” translates technical complexity for business and compliance stakeholders.
  • Disciplined documentation β€” produces clear, audit-ready artifacts without being prompted.
  • Adaptability β€” comfortable across cloud providers, toolchains, and an evolving compliance landscape.

What Success Looks Like

  • AWS, Azure, and the Microsoft 365 tenant are stable, secure, observable, and documented.
  • Identity is governed: access follows least privilege, joiners and leavers are handled cleanly, and access reviews are routine.
  • Infrastructure changes are repeatable through code, with clear review and rollback paths.
  • Monitoring, logging, and vulnerability remediation are routine rather than scramble-driven.
  • Audit artifacts - diagrams, runbooks, evidence - stay current and usable.

What We Offer

  • A fully remote, results-based environment
  • Competitive salary, bonus and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager's approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

How would you rate this job post?

See what other professionals think about this role.

banner

DEFCON AI is a defense technology company building AI-powered modeling, simulation, and analysis (MS&A) tools for mobility and logistics optimization. Founded in 2022 and headquartered in McLean, Virginia, the software firm equips military leaders, defense transportation planners, and commercial logistics networks with dynamic decision-support software to overcome disruptive disruptions and maintain operational supply continuity.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More