Microsoft Azure Systems Engineer

Ridgeline InternationalTysons, VA
16h

About The Position

This is a deeply hands-on engineering role focused on building, configuring, and troubleshooting Azure infrastructure on a daily basis. We’re seeking engineers who have personally architected and operated production Azure environments and who take pride in owning the full lifecycle — from design through deployment and ongoing operations. The ideal candidate brings real-world, production experience and enjoys rolling up their sleeves to deliver reliable, secure, and scalable cloud solutions. What you will do: Cloud Architecture & Engineering You will design and implement scalable, secure Azure infrastructure (IaaS, PaaS, and hybrid) You will deploy and manage Azure Virtual Networks, NSGs, Azure Firewall, and private endpoints You will architect and support hybrid connectivity (VPN, ExpressRoute) You will implement high availability and disaster recovery solutions Systems & Identity You will own the deployment, configuration, patching, and operational health of Windows workloads running in Azure You will integrate Azure AD / Entra ID with enterprise identity systems You will implement RBAC, Conditional Access, and least-privilege access models You will support Microsoft 365 and Azure AD integrations where required Automation & Infrastructure as Code You will build and maintain infrastructure using Terraform (preferred), ARM/Bicep templates, PowerShell, and Azure CLI You will ensure deployments are idempotent and repeatable — manual deployments are not acceptable You will contribute to CI/CD pipelines for infrastructure delivery Security & Compliance You will implement Azure Security Center / Defender for Cloud controls You will configure logging and monitoring (Azure Monitor, Log Analytics) You will support compliance frameworks (e.g., NIST, RMF, CMMC as applicable) You will conduct vulnerability remediation and hardening Monitoring & Operations You will implement alerting and performance monitoring You will own backup and recovery strategy (Azure Backup, Site Recovery) You will participate in incident response and root cause analysis — and personally drive remediation You will document architecture and operational runbooks What You’ll Accomplish in Your First Six Months This role is about maturing and optimizing an already functional Azure environment into a fully standardized, enterprise-ready platform — while keeping delivery moving at full speed. Months 0–2: Understand and Stabilize Build a deep understanding of the current Azure architecture, deployment pipelines, networking, and security model. Identify opportunities to simplify, standardize, and reduce operational risk. Ensure CI/CD pipelines continue operating smoothly and reliably. Begin developing clear, structured documentation of infrastructure, dependencies, and operational workflows. Establish a practical, prioritized roadmap for platform improvements aligned to business objectives. Months 2–4: Standardize and Strengthen Introduce infrastructure-as-code and repeatable deployment patterns where needed to increase consistency and reliability. Refine identity, access controls, and network architecture to align with enterprise-grade best practices. Implement consistent naming, tagging, and environment standards. Partner with the Network Operations Center to onboard systems into a 24×7 monitoring and alerting framework. Enhance logging, observability, and operational visibility across the environment. Months 4–6: Scale with Confidence Improve resiliency through well-defined backup, disaster recovery, and restoration testing. Increase deployment reliability with improved rollback strategies and change discipline. Reduce technical debt while preserving development velocity. Deliver a well-documented, supportable, and scalable Azure platform designed for long-term growth. By the six-month mark, the environment will be more consistent, observable, resilient, and operationally mature — positioned to support both current demands and future expansion.

Requirements

  • An Active Secret Clearance at a minimum
  • 5+ years of systems engineering experience with direct, hands-on technical execution — not project management, not oversight
  • 3+ years building and operating Microsoft Azure infrastructure in production environments — you must be able to demonstrate personal technical contributions, not team-level accomplishments
  • Proven hands-on experience with Azure networking — you have personally deployed and troubleshot VNets, NSGs, peering, private endpoints, and hybrid connectivity (VPN or ExpressRoute)
  • Direct implementation experience with Azure AD / Entra ID — you have personally configured Conditional Access policies, RBAC assignments, and enterprise identity integrations
  • Working Infrastructure as Code practice — you maintain and deploy Terraform (preferred), ARM/Bicep, or equivalent in real environments, not just lab or training contexts
  • Strong PowerShell scripting ability demonstrated in production automation — not just basic cmdlet usage
  • Experience as a primary engineer responsible for production Azure workloads — including incident response, root cause analysis, and remediation you personally executed

Nice To Haves

  • Azure certifications such as AZ 104 or AZ 305
  • Experience in regulated or Department of Defense environments
  • Azure Kubernetes Service experience
  • Azure DevOps or GitHub Actions pipeline experience
  • Microsoft Defender suite experience
  • Zero trust architecture implementation

Responsibilities

  • design and implement scalable, secure Azure infrastructure (IaaS, PaaS, and hybrid)
  • deploy and manage Azure Virtual Networks, NSGs, Azure Firewall, and private endpoints
  • architect and support hybrid connectivity (VPN, ExpressRoute)
  • implement high availability and disaster recovery solutions
  • own the deployment, configuration, patching, and operational health of Windows workloads running in Azure
  • integrate Azure AD / Entra ID with enterprise identity systems
  • implement RBAC, Conditional Access, and least-privilege access models
  • support Microsoft 365 and Azure AD integrations where required
  • build and maintain infrastructure using Terraform (preferred), ARM/Bicep templates, PowerShell, and Azure CLI
  • ensure deployments are idempotent and repeatable — manual deployments are not acceptable
  • contribute to CI/CD pipelines for infrastructure delivery
  • implement Azure Security Center / Defender for Cloud controls
  • configure logging and monitoring (Azure Monitor, Log Analytics)
  • support compliance frameworks (e.g., NIST, RMF, CMMC as applicable)
  • conduct vulnerability remediation and hardening
  • implement alerting and performance monitoring
  • own backup and recovery strategy (Azure Backup, Site Recovery)
  • participate in incident response and root cause analysis — and personally drive remediation
  • document architecture and operational runbooks

Benefits

  • Flexible PTO + holidays
  • Generous 401k match benefit up to 10%, with an automatic 3% safe harbor contribution and additional matching based on employee contributions.
  • Medical (HSA & PPO Plans Available), dental, vision, disability, and life insurance
  • Employer Contribution to Health Savings Account (HSA)
  • Learning & Development opportunities
  • Professional coaching services
  • Free Personal Privacy Protection Services
  • Get the technology you want to do your job
  • We have free daily snacks & drinks
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service