{"schemaVersion":"jobsearcher.job.v1","id":"0494eed35c835c2adc66f4f6","url":"https://jobsearcher.com/jobs/0494eed35c835c2adc66f4f6","canonicalUrl":"https://jobsearcher.com/jobs/0494eed35c835c2adc66f4f6","title":"Cloud Security Architect (GCC High)","description":"The roleTwo Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3PAOs during their CMMC Level 2 certification.We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.What you'll ownFinal technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra ID, Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3PAO interview.Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI boundary. These are scoped, billable projects with delivery dates.Runbooks and documentation (~10%). Every environment you touch gets a runbook. Every control you configure gets an implementation statement someone else can read.What you need5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering roleHands-on Microsoft GCC High experience, including working knowledge of where GCC High diverges from Commercial in feature availability, licensing, tenant configuration, and external collaborationEntra ID: Conditional Access policy design, Privileged Identity Management, identity lifecycleIntune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment, Windows endpoint hardening against a recognized benchmark (CIS or DISA STIG)Microsoft Defender suite and Microsoft Sentinel: data connectors, analytics rules, alert triage, and enough KQL to write a query rather than copy oneAzure infrastructure: subscriptions and management groups, Azure Policy, RBAC, virtual networks, network security groups, site-to-site VPNWorking fluency in NIST SP 800-171 at the control level. Given a specific requirement, you can name the configuration that satisfies it, identify what's missing, and write the implementation statement. This is the requirement that distinguishes candidates for us.Clear written communication. You'll write for clients, for assessors, and for teammates who inherit your work.Helpful, not requiredAzure Government or Microsoft 365 DoD experienceCisco Meraki: MX firewall policy, VLAN segmentation, wirelessExperience supporting or sitting for a CMMC Level 2 or DFARS 7012 assessmentGRC platform administration (Drata, Vanta, or similar) with an emphasis on evidence automationAzure Arc, Defender for Cloud, backup and DR design in a Gov cloud regionAZ-500, SC-200, AZ-104, CCP, or CCAPrior work at an MSP, MSSP, or defense contractorFirst 90 daysBy day 30, you're taking escalations independently across at least two client environments. By day 60, you own the open POA&M queue for one client and have closed findings with evidence attached. By day 90, you're leading a buildout or integration workstream end to end and your design decisions are shaping how we scope the next one.Why this is worth your timeYou'll be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters. Our clients are building real defense capability and cannot bid without the compliance posture we help them hold. The environments are technically constrained in ways commercial cloud work isn't, which means the expertise you build here is scarce and it compounds.We are also automating the parts of compliance delivery that should never have been manual. If you have opinions about what should be a script instead of a screenshot, you'll be listened to.","company":"Two Five","rawCompany":"two five","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-08-05T09:44:52.081Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cloud Security Architect (GCC High)","description":"The roleTwo Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3PAOs during their CMMC Level 2 certification.We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.What you'll ownFinal technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra ID, Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3PAO interview.Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI boundary. These are scoped, billable projects with delivery dates.Runbooks and documentation (~10%). Every environment you touch gets a runbook. Every control you configure gets an implementation statement someone else can read.What you need5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering roleHands-on Microsoft GCC High experience, including working knowledge of where GCC High diverges from Commercial in feature availability, licensing, tenant configuration, and external collaborationEntra ID: Conditional Access policy design, Privileged Identity Management, identity lifecycleIntune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment, Windows endpoint hardening against a recognized benchmark (CIS or DISA STIG)Microsoft Defender suite and Microsoft Sentinel: data connectors, analytics rules, alert triage, and enough KQL to write a query rather than copy oneAzure infrastructure: subscriptions and management groups, Azure Policy, RBAC, virtual networks, network security groups, site-to-site VPNWorking fluency in NIST SP 800-171 at the control level. Given a specific requirement, you can name the configuration that satisfies it, identify what's missing, and write the implementation statement. This is the requirement that distinguishes candidates for us.Clear written communication. You'll write for clients, for assessors, and for teammates who inherit your work.Helpful, not requiredAzure Government or Microsoft 365 DoD experienceCisco Meraki: MX firewall policy, VLAN segmentation, wirelessExperience supporting or sitting for a CMMC Level 2 or DFARS 7012 assessmentGRC platform administration (Drata, Vanta, or similar) with an emphasis on evidence automationAzure Arc, Defender for Cloud, backup and DR design in a Gov cloud regionAZ-500, SC-200, AZ-104, CCP, or CCAPrior work at an MSP, MSSP, or defense contractorFirst 90 daysBy day 30, you're taking escalations independently across at least two client environments. By day 60, you own the open POA&M queue for one client and have closed findings with evidence attached. By day 90, you're leading a buildout or integration workstream end to end and your design decisions are shaping how we scope the next one.Why this is worth your timeYou'll be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters. Our clients are building real defense capability and cannot bid without the compliance posture we help them hold. The environments are technically constrained in ways commercial cloud work isn't, which means the expertise you build here is scarce and it compounds.We are also automating the parts of compliance delivery that should never have been manual. If you have opinions about what should be a script instead of a screenshot, you'll be listened to.","datePosted":"2026-08-05T09:44:52.081Z","dateModified":"2026-08-05T09:44:52.081Z","hiringOrganization":{"@type":"Organization","name":"Two Five","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"0494eed35c835c2adc66f4f6"},"url":"https://jobsearcher.com/jobs/0494eed35c835c2adc66f4f6"}}