Cloud Security Architect; GCC
Listed on 2026-09-30
-
IT/Tech
Cybersecurity
· Full time Company website Apply for Cloud Security Architect (GCC High)
Two Five Solutions is hiring a Cloud Security Architect to own the Microsoft GCC High and Azure Government environments we run for defense industrial base contractors — designing CUI boundaries, taking the escalations no one else can close, clearing POA&M findings against NIST SP 800-171 ahead of C3
PAO assessments, and standing up new tenants and landing zones as clients are onboarded or acquired. This isn't a helpdesk role, a policy-writing role, or a whiteboard role: you translate controls into configurations and produce the evidence that proves it, which means you're in the console the same week you're in the design document. What matters most is real GCC High depth and 800-171 fluency at the control level — given a requirement, you can name the configuration that satisfies it, say what's missing, and write the implementation statement.
You'd be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters.
Two Five is a cybersecurity and automation solutions firm that helps organizations operate smarter, scale faster, and grow securely. We deliver expert solutions across Governance, Risk & Compliance (GRC), Managed Services, Strategic Consulting, and Innovation & Automation. By combining deep technical knowledge with business-first thinking, we empower our clients to reduce risk, streamline operations, and unlock the full potential of AI and automation.
Whether you're building secure infrastructure, navigating compliance, or accelerating transformation, Two Five is your trusted partner for resilient growth.
Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3
PAOs during their CMMC Level 2 certification.
We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.
This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.
It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.
What you'll ownFinal technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra , Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.
POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3
PAO interview.
Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).