Cloud Systems Engineer
- Work model
- Remote
- Location
- Remote, USA
- Posted
- 5d ago
<div class="content-intro"><h3>About Us</h3> <p>Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.</p></div><p> </p> <p>DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.<br>In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.</p> <p></p> <p><strong>About the Role</strong></p> <p>DEFCON AI is hiring a <strong>Cloud Systems Engineer</strong> to administer AWS, Microsoft Azure, and our Microsoft 365 and Entra ID tenant. This is a single, senior seat covering both halves of the environment — the infrastructure that runs our workloads and the identity plane that governs who reaches them — with end-to-end ownership of each.</p> <p>The work spans virtual machine provisioning and network architecture, Infrastructure as Code, tenant and identity administration, endpoint management, automation, and continuous monitoring. We operate under defense-sector compliance obligations, so security hardening and audit-ready documentation are part of the job rather than an afterthought. Experience in regulated or compliance-driven environments — defense, healthcare, or financial services — is a strong plus.</p> <p><strong>Responsibilities:</strong></p> <p><strong>Cloud Infrastructure and Virtual Systems Administration</strong></p> <ul> <li>Administer and maintain AWS and Azure environments, including day-to-day operations of virtual machines, networking, and storage across both providers.</li> <li>AWS: deploy, maintain, and optimize EC2, RDS, S3, IAM, KMS, Secrets Manager, and CloudTrail; manage VPCs, subnets, routing tables, security groups, and NACLs.</li> <li>Azure: administer virtual machines, virtual networks and NSGs, storage accounts, Azure Files, Key Vault, Azure Virtual Desktop, and Site Recovery across subscriptions.</li> <li>Build and manage hardened VM images and golden images for consistent, repeatable deployments.</li> <li>Implement and support high availability, auto-scaling, backup, and disaster recovery configurations.</li> <li>Support multi-account and multi-subscription governance structures — AWS Organizations, Azure Management Groups, and equivalent landing-zone constructs.</li> </ul> <p><strong>Identity & Microsoft 365 Administration</strong></p> <ul> <li>Own the Microsoft 365 tenant end to end: Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and licensing.</li> <li>Administer the identity plane — Conditional Access policies, MFA enforcement, RBAC and least privilege, privileged access, hybrid identity, and application registrations. and role assignments, and conditional access policies</li> <li>Run the full user lifecycle: provisioning, onboarding, role changes, offboarding, and access reviews, automated wherever the volume justifies it.</li> <li>Manage the endpoint fleet through Intune, including compliance policies, configuration profiles, patching, and device lifecycle.</li> <li>Administer single sign-on and provisioning integrations (SAML, SCIM) between Entra ID and the SaaS platforms we operate.</li> <li>Support data governance and protection through Purview, sensitivity labels, and DLP policy where applicable.</li> </ul> <p><strong>Infrastructure as Code and Automation</strong></p> <ul> <li>Design and maintain infrastructure using Terraform — modular design, remote state management, and workspace strategy — across both AWS and Azure.</li> <li>Build reusable, secure baseline modules for network architecture, IAM roles, logging, monitoring, and encryption.</li> <li>Automate operational workflows in PowerShell, Bash, and Python, including Microsoft Graph API automation for identity and tenant tasks.</li> <li>Integrate infrastructure provisioning and security controls into CI/CD pipelines (GitHub Actions, GitLab CI, or equivalent) and maintain version-controlled infrastructure repositories.</li> <li>Implement automated drift detection and remediation, and enforce policy-as-code guardrails.</li> </ul> <p><strong>Security, Compliance & Monitoring</strong></p> <ul> <li>Apply and maintain hardening baselines (CIS Benchmarks, DISA STIGs) across Linux and Windows systems and cloud tenants.</li> <li>Configure and monitor AWS CloudTrail, GuardDuty, Security Hub, and Config alongside Microsoft Defender and Entra ID sign-in and audit logging.</li> <li>Support SIEM integration (Splunk, Microsoft Sentinel, or equivalent) and assist with incident response.</li> <li>Maintain the vulnerability management lifecycle: patching, remediation tracking, and reporting.</li> <li>Support compliance aligned to NIST SP 800-171, CMMC, and FedRAMP or SOC 2 as applicable, including evidence collection for assessments.</li> </ul> <p><strong>AI Platform Administration</strong></p> <ul> <li>Administer the AI platforms in our environment — Anthropic Claude, ChatGPT, AWS Bedrock, and Microsoft 365 Copilot — including seats and licensing, SSO and provisioning, retention and data controls, connector and agent governance, and spend limits.</li> <li>Enforce and communicate standards for what data may be placed into AI tooling, particularly where CUI or controlled data is involved.</li> </ul> <p><strong>Collaboration and Documentation</strong></p> <ul> <li>Partner with engineering, security, and operations to deliver reliable, scalable services</li> <li>Produce and maintain architecture diagrams, runbooks, SOPs, and audit evidence artifacts without being