Cloud Security Architect (GCC High
Listed on 2026-08-09
-
IT/Tech
Systems Engineer, Cybersecurity
Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3
PAOs during their CMMC Level 2 certification.
We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.
This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.
It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.
The roleTwo Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3
PAOs during their CMMC Level 2 certification.
We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.
This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.
It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.
What you’ll own- Final technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra , Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.
- POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3
PAO interview. - Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI boundary. These are scoped, billable projects with delivery dates.
- Runbooks and documentation (~10%). Every environment you touch gets a runbook. Every control you configure gets an implementation statement someone else can read.
- 5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering role
- Hands‑on Microsoft GCC High experience, including working knowledge of where GCC High diverges from Commercial in feature availability, licensing, tenant configuration, and external collaboration
- Entra l Access policy design, Privileged Identity Management, identity lifecycle
- Intune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment, Windows endpoint hardening against a recognized benchmark (CIS or DISA STIG)
- Microsoft Defender suite and Microsoft Sentinel: data connectors, analytics rules, alert triage, and enough KQL to write a query rather than copy one
- Azure infrastructure: subscriptions and management groups, Azure Policy, RBAC,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).