ForgeApply · Job listing
Cloud Systems Engineer
Defcon
See all 8 open roles at Defcon →
Tailor your resume for this Defcon job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on Defcon's site with it. You review everything before it's sent. Free trial, no card required.
About this role
ABOUT DEFCON AI
RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems. In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.
About the Role
DEFCON AI is hiring a Cloud Systems Engineer to administer AWS, Microsoft Azure, and our Microsoft 365 and Entra ID tenant. This is a single, senior seat covering both halves of the environment — the infrastructure that runs our workloads and the identity plane that governs who reaches them — with end-to-end ownership of each.
The work spans virtual machine provisioning and network architecture, Infrastructure as Code, tenant and identity administration, endpoint management, automation, and continuous monitoring. We operate under defense-sector compliance obligations, so security hardening and audit-ready documentation are part of the job rather than an afterthought. Experience in regulated or compliance-driven environments — defense, healthcare, or financial services — is a strong plus.
Responsibilities:
Cloud Infrastructure and Virtual Systems Administration
• Administer and maintain AWS and Azure environments, including day-to-day operations of virtual machines, networking, and storage across both providers.
• AWS: deploy, maintain, and optimize EC2, RDS, S3, IAM, KMS, Secrets Manager, and CloudTrail; manage VPCs, subnets, routing tables, security groups, and NACLs.
• Azure: administer virtual machines, virtual networks and NSGs, storage accounts, Azure Files, Key Vault, Azure Virtual Desktop, and Site Recovery across subscriptions.
• Build and manage hardened VM images and golden images for consistent, repeatable deployments.
• Implement and support high availability, auto-scaling, backup, and disaster recovery configurations.
• Support multi-account and multi-subscription governance structures — AWS Organizations, Azure Management Groups, and equivalent landing-zone constructs.
Identity & Microsoft 365 Administration
• Own the Microsoft 365 tenant end to end: Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and licensing.
• Administer the identity plane — Conditional Access policies, MFA enforcement, RBAC and least privilege, privileged access, hybrid identity, and application registrations. and role assignments, and conditional access policies
• Run the full user lifecycle: provisioning, onboarding, role changes, offboarding, and access reviews, automated wherever the volume justifies it.
• Manage the endpoint fleet through Intune, including compliance policies, configuration profiles, patching, and device lifecycle.
• Administer single sign-on and provisioning integrations (SAML, SCIM) between Entra ID and the SaaS platforms we operate.
• Support data governance and protection through Purview, sensitivity labels, and DLP policy where applicable.
Infrastructure as Code and Automation
• Design and maintain infrastructure using Terraform — modular design, remote state management, and workspace strategy — across both AWS and Azure.
• Build reusable, secure baseline modules for network architecture, IAM roles, logging, monitoring, and encryption.
• Automate operational workflows in PowerShell, Bash, and Python, including Microsoft Graph API automation for identity and tenant tasks.
• Integrate infrastructure provisioning and security controls into CI/CD pipelines (GitHub Actions, GitLab CI, or equivalent) and maintain version-controlled infrastructure repositories.
• Implement automated drift detection and remediation, and enforce policy-as-code guardrails.
Security, Compliance & Monitoring
• Apply and maintain hardening baselines (CIS Benchmarks, DISA STIGs) across Linux and Windows systems and cloud tenants.
• Configure and monitor AWS CloudTrail, GuardDuty, Security Hub, and Config alongside Microsoft Defender and Entra ID sign-in and audit logging.
• Support SIEM integration (Splunk, Microsoft Sentinel, or equivalent) and assist with incident response.
• Maintain the vulnerability management lifecycle: patching, remediation tracking, and reporting.
• Support compliance aligned to NIST SP 800-171, CMMC, and FedRAMP or SOC 2 as applicable, including evidence collection for assessments.
AI Platform Administration
• Administer the AI platforms in our environment — Anthropic Claude, ChatGPT, AWS Bedrock, and Microsoft 365 Copilot — including seats and licensing, SSO and provisioning, retention and data controls, connector and agent governance, and spend limits.
• Enforce and communicate standards for what data may be placed into AI tooling, particularly where CUI or controlled data is involved.
Collaboration and Documentation
• Partner with engineering, security, and operations to deliver reliable, scalable services
• Produce and maintain architecture diagrams, runbooks, SOPs, and audit evidence artifacts without being asked for them
• Contribute to capacity forecasting, resource planning, and cloud cost management.
Qualifications :
• 5+ years in systems administration, cloud operations, or infrastructure engineering.
• 3+ years hands-on administering AWS in production, including virtual machine administration, networking, and IAM.
• 2+ years administering a Microsoft 365 tenant with real admin rights — Entra ID, Exchange Online, Conditional Access, licensing, and user lifecycle. Help-desk support of Microsoft 365 does not meet this bar.
• Hands-on Microsoft Azure administration in a production environment.
• Demonstrated automation of operational workflows using PowerShell, Bash, or Python; working Terraform experience.
• Strong understanding of IAM, encryption (KMS, TLS), and network segmentation.
• Experience with Linux (RHEL or Amazon Linux) and Windows Server in a cloud
Tailor your resume for this Defcon role before you apply.
Tailor my resume for this jobSimilar jobs
- Cloud Systems Engineer — Booz Allen Hamilton · El Segundo, CA
- Cloud Systems Engineer — AIS · Remote
- Cloud Systems Engineer 4 — AIS · Remote
- Cloud Systems Engineer II — Taketwo · Austin, Texas, United States
- Cloud Systems Administrator — Accenturefederalservices · Hill AFB, UT
- Cloud Solutions Engineer — The Aerospace Corporation · Chantilly, VA
- Cloud Systems Administrator II — CACI · Annapolis Junction, MD
- Desktop Systems Engineer — Drweng · New York City
Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)