Cloud Platform Engineer
Listed on 2026-07-31
-
IT/Tech
Cloud Computing: Infrastructure & Operations, Cybersecurity
Description
This role is contingent upon a contract award. ICF is seeking a Cloud Platform Engineer to deploy, configure, and maintain cloud infrastructure for a federal technology program. Reporting to the Cloud / Enterprise Architecture Lead, this role is responsible for building and operating the multi-cloud landing zone environment using infrastructure-as-code and Dev Sec Ops practices. Where the EA Lead sets architecture standards and policy, this role executes and maintains them in production.
The ideal candidate is a hands-on cloud infrastructure engineer who writes automation before clicking buttons and treats configuration as code. The right candidate has deployed and operated cloud landing zones in federal environments and is comfortable working across Azure, AWS, and GCP with consistent tooling and governance discipline.
Job Location:
This is a remote-friendly position with occasional onsite requirements in the Washington, DC Metro area. This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections.
- Deploy and manage cloud landing zone architectures across Azure, AWS, and Google Cloud Platform using repeatable, automated provisioning with identity-first controls, guardrails, network security, and policy enforcement.
- Implement infrastructure and policy as code using IaC templates, Git Hub Actions, and CI/CD pipelines so environments can be created, updated, and audited consistently and without manual intervention.
- Build and maintain system integrations using APIs, SDKs, webhooks, and event streams, with proper secrets management, least-privilege scoping, error handling, and logging.
- Deploy and manage Azure Virtual Desktop for remote access scenarios and specific user personas.
- Manage DNS-as-code for all agency platforms and services, including certificates and related configurations.
- Integrate platform logs, alerts, and risk signals into central monitoring tools, and use automation to flag misconfigurations, risky behavior, and suspicious activity.
- Perform quarterly reviews of cloud environment configurations against security baselines and compliance requirements, using compliance-as-code tooling where available.
- Coordinate with identity, device, and cybersecurity teams to ensure cloud access policies, device compliance rules, and conditional access work together as part of a consistent Zero Trust model.
- Maintain documentation of cloud architectures, configuration baselines, runbooks, and operational procedures so others can safely operate and extend the environment.
- Resolve complex cloud platform issues escalated from operations and service desk teams.
- Bachelor's degree or equivalent
- 5+ years of experience in cloud engineering or platform operations
- 3+ years deploying and managing cloud landing zones in Azure, AWS, or GCP in production environments
- 2+ years implementing infrastructure as code using tools such as Terraform, Bicep, Cloud Formation, or equivalent
- 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies
- U.S. Citizenship required due to federal contract requirements
- Ability to obtain and maintain a Public Trust background investigation
- Candidate must reside in the US, be authorized to work in the US, and work must be performed in the US
- Experience managing Azure Virtual Desktop or equivalent virtual desktop infrastructure
- Familiarity with NIST 800-53, FedRAMP, CIS benchmarks, and CISA Zero Trust guidelines as they apply to cloud infrastructure
- Experience integrating platform telemetry with SIEM or SOAR tools for automated alerting and remediation
- Relevant certifications such as Microsoft Azure Administrator, AWS Sys Ops Administrator, or Google Cloud Professional Cloud Engineer
- Experience with Dev Sec Ops delivery practices including automated security testing in CI/CD pipelines
ICF is a global advisory and technology services provider, but we’re not your typical consultants.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).