Senior Azure Engineer
B5 Recruiting
2 days ago
Full-time
On-site
Washington, District of Columbia, United States
$148,000 - $172,000 USD yearly
Azure
Job Description
At a Glance
• Location: Washington, DC — 888 First Street NE. Hybrid; on site at least two (2) days per week, with additional on-site days for migration events, cutovers, and client reviews.
• Citizenship: U.S. citizenship required.
• Clearance: Must be able to obtain and maintain a Public Trust clearance.
• Role type: Senior individual contributor — architecture, analysis, and recommendation. Not a people-management or day-to-day operations role.
• Experience: 8+ years in infrastructure engineering, with senior-level Azure design ownership.
• Key Personnel: This is a designated Key Role on the program. The government client reviews and approves the selected candidate's resume before start — a standard step on federal programs, and one we will walk you through.
About the Role
A federal agency is planning its move off Azure VMware Solution (AVS) and onto native Azure, and this role owns the technical answer to how. You will design the post-AVS target state, determine which Azure-native services can replace the platforms the agency runs today, build the cost model that supports budget submissions, and shape the 18–24 month cloud roadmap that leadership executes against.
Early work includes assessing Azure application delivery services — Application Gateway, Front Door, and Load Balancer, as alternatives to F5, and answering the broader question of which legacy and third-party platforms can be replaced with Microsoft-native capabilities over the next 18–24 months.
You are the program's deep Azure expert. Your designs set the target state, and your options analyses and recommendations go to the Infrastructure Engineering Lead, program leadership, and government stakeholders as the plan of record. You will assess the current environment, evaluate Azure-native services against what the agency runs today, prototype candidates in non-production, and turn the results into decision-ready recommendations. Direction and prioritization come from the Infrastructure Engineering Lead; the depth that makes those decisions sound comes from you.
The work is architecture and analysis rather than ticket queues or team management. You will partner closely with the network, systems, and security teams so that what you design is something they can actually run, and serve as the escalation point when a hard Azure problem lands.
What You Will Do
• Own the post-AVS target-state design. Develop and compare target-state options, identify decision points, dependencies, and risks, and plan how workloads move from AVS to native Azure services.
• Shape the 18–24 month cloud roadmap. Provide the technical inputs that keep the roadmap aligned to agency planning and budget cycles.
• Evaluate and prototype Azure-native capabilities. Research, prototype, and recommend Microsoft services that replace legacy platforms, improve service delivery, and advance the agency's modernization goals.
• Build the cost case. Develop and maintain the AVS-versus-native-Azure cost model, identify near-term savings in the existing environment, and support budget submissions with defensible projections.
• Make designs operable. Document the operational impacts of design decisions — monitoring, patching, backup, disaster recovery (DR), runbooks — and advise on the skills operations teams will need as the model shifts from traditional networking and virtualization to cloud platform management.
• Serve as the Azure escalation point. Provide expert guidance on complex Azure issues and share what you know with the engineers around you.
• Write it down well. Produce technical designs, options analyses, recommendation memos, roadmaps, and change records suitable for government review.
Nice to Have
You do not need all of these. Tell us which ones you have.
• Cloud cost modeling and optimization — reservations, savings plans, right-sizing, and platform consolidation — presented with quantified savings and implementation effort.
• Experience in Azure Government (GCC) environments, and familiarity with FedRAMP High service authorization boundaries and Azure Government service availability.
• Hands-on implementation of Azure Application Gateway, Azure Front Door, or Azure Load Balancer.
• Familiarity with Azure Migrate, Azure Firewall, Azure Virtual WAN, Log Analytics, Microsoft Defender for Cloud, or Azure Site Recovery.
• Infrastructure-as-code (IaC) familiarity — Bicep, Terraform, or ARM templates — and Azure DevOps (ADO) pipelines, with a track record of championing automation to reduce manual effort.
• Familiarity with the Microsoft Cloud Adoption Framework (CAF), the Azure Well-Architected Framework (WAF), and landing zone design.
• Experience with Azure DevOps (ADO) boards, and with IT service management (ITSM) processes and tooling such as ServiceNow.
Additional Details
-
Citizenship / Clearance: U.S. citizenship required; must be able to obtain and maintain
Requirements
• 8+ years of infrastructure engineering experience, including senior-level ownership of cloud design with Microsoft Azure as the primary platform — you have produced designs and recommendations that others built from, not just executed tickets.
• Deep working knowledge of core Azure services — compute, virtual networking, storage, Microsoft Entra ID (formerly Azure Active Directory / Azure AD), Azure Policy, Azure Monitor, and Cost Management — with the depth to validate designs, troubleshoot complex issues, and answer the hard questions.
• Experience planning or leading migrations of VMware-based workloads to Azure — from on-premises VMware vSphere / ESXi / vCenter, from Azure VMware Solution (AVS), or from a comparable platform — including workload assessment, sequencing, and cutover planning. Judgment about how migrations are scoped and sequenced matters more to us than the exact source platform.
• Solid understanding of Azure Networking — ExpressRoute, virtual networks (VNets) and peering, network security groups (NSGs), private endpoints, load balancing, DNS, and hybrid routing — enough to design hybrid topologies and evaluate replacing appliance-based load balancing with Azure-native services.
• Experience designing or operating cloud infrastructure in a security- and compliance-driven environment (federal, FedRAMP, or a similarly regulated industry), with a working understanding of NIST 800-53 as it applies to cloud environments.
• Strong communication and documentation skills — comfortable in deep technical discussion with engineers, able to present findings and recommendations to program leadership and government stakeholders, and able to translate complex technical options into clear business terms and written deliverables that stand up to government review.
• Bachelor's degree in a technical discipline, or equivalent additional experience.
• U.S. citizenship, and the ability to obtain and maintain a Public Trust clearance