Type of Requisition:Regular
Clearance Level Must Currently Possess:Secret
Clearance Level Must Be Able to Obtain:Secret
Public Trust/Other Required:None
Job Family:Software Engineering
Job Qualifications:Skills:Active Directory (AD), Azure Devops, Azure Monitor, Cloud Infrastructure, Cloud Networking
Certifications:None
Experience:10 + years of related experience
US Citizenship Required:Yes
Job Description:The
Azure Architecture SME - Lead is responsible for architecting, designing, and guiding the implementation of secure, scalable, and high-performing Azure cloud solutions. This role provides technical leadership, problem-solving expertise, and hands-on support across networking, identity, infrastructure automation, and cloud-to-on-prem integrations. The SME will develop architect diagrams, lead complex migrations using Azure Site Recovery, deliver technical presentations to government customers, and design and drive implementation of Entra architecture for enterprise environments.
MAJOR RESPONSIBILITIES:- Lead the design of end-to-end Azure architecture, producing detailed architect diagrams utilizing VISIO and technical documentation.
- Lead technical presentations, architectural discussions, and solution deep dives with government customers and stakeholders.
- Lead and conduct the migration planning and execution using Azure Site Recovery, overseeing dependency mapping, failover testing, and cutover operations.
- Manage and optimize replication traffic over ExpressRoute/VPN; design and isolate VNETs for test and validation to support migration readiness.
- Serve as the point of contact for all Azure networking issues, leading problem-solving efforts, guiding architecture decisions, and advising leadership on technical direction.
- Ensure secure and reliable connectivity between cloud and on-prem environments while maintaining optimal performance, resiliency, and availability.
- Lead, design, implement, and manage Azure networking components including virtual networks, subnets, NSGs, Azure Firewall, VPN/ExpressRoute, load balancers, and routing topologies.
- Lead security hardening and protection of infrastructure across cloud and on-prem environments while supporting system and workload migrations.
- Design and lead implementation of Microsoft Entra architecture, including identity governance, conditional access, role management, and cross-tenant integrations.
- Build and manage Azure infrastructure using DevOps practices and Infrastructure-as-Code (IaC) tools such as Terraform, Bicep, ARM templates, Azure DevOps, and GitHub Actions.
- Mentor and collaborate with System Administrators on account administration, VM configuration, monitoring implementation, patch management, and operational support.
- Oversee all system changes and ensure compliance with DISA STIGs, hardening guidelines, and relevant organizational controls for each VM or server.
QUALIFICATIONS:Education:- Bachelor's degree or higher in Systems Engineering, Computer Science, Information Technology, or a closely related technical field.
Experience:- 10+ years of related experience required, with at least 5+ years of preferred experience in database and data management.
- 5+ years Azure IL5/IL6 environments
Required Certification(s): - CompTia Security+ is required to satisfy DoD 8570.01M requirements for IAT Level II
- Other work-dependent certifications a plus
Required Skills:- Experience with design and development of network solutions in an Azure IL5 and IL6 environment
- Experience using Microsoft Entra ID and Microsoft Entra Monitor
- Extensive knowledge of Azure Network Design and establishing Entra architecture
- Strong Azure networking skills: VNets, NSGs, routing, Azure Firewall, load balancing, and ExpressRoute/VPN
- Understanding of CI/CD concepts and secure pipeline development in controlled cloud environments
- Advanced knowledge using Ansible or PowerShell scripts
Desired Qualifications:Experience with two or more of the areas outlined below is preferred but not required:
- Experience with Azure Migration solutions
- Experience with Cloud based Database systems
- Experience using MS Visio for updating diagrams
- Experience working in Agile/Scrum environments
- Experience working in Federal or State government environments
CLEARANCE REQUIREMENTS:- Must possess active Secret or higher clearance and maintain as a condition of employment
- US Citizenship required
LOCATION:Hybrid in Washington, D.C.; on-site work
at least three days a week at customer location will be required
The likely salary range for this position is $170,000 - $230,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.Scheduled Weekly Hours:40
Travel Required:Less than 10%
Telecommuting Options:Hybrid
Work Location:USA DC Washington
Additional Work Locations:Total Rewards at GDIT:Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.