386,863open jobs
10,118companies
50,530added this week
Browse all
Salary
$87k – $198k per year
Location
In office (San Diego)
Seniority
Architect · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Booz Allen Hamilton is an American consulting firm founded in 1914 that has spent most of the past century working for the United States government, and today derives almost all of its revenue from federal clients. It supplies technology and mission services to defence, intelligence, civil and health agencies, covering systems engineering, cyber operations, data platforms and increasingly artificial intelligence deployed inside classified environments. Headquartered in McLean, Virginia and listed on the New York Stock Exchange, it employs tens of thousands of security-cleared staff and competes with the other large federal services contractors for multi-year programme awards.
Cloud Computing Infrastructure Architect

The Opportunity:

Cloud security is moving beyond point-in-time compliance toward continuously measured, automated, and resilient security operations. Federal organizations need cloud platforms that can continuously enforce secure configurations, produce trustworthy security evidence, detect sophisticated threats, and respond at machine speed.

We are looking for an experienced Azure Cloud Security Engineering Lead to drive the design and implementation of advanced security capabilities within Microsoft Azure Government. In this role, you will lead technical workstreams that strengthen cloud security, modernize cyber operations, improve security telemetry, and advance continuous security assurance aligned with evolving federal requirements.

You will work across Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, automation, and Infrastructure as Code to turn security objectives into deployable engineering solutions. You will help continuously identify configuration drift, validate security controls, improve detection coverage, automate response, strengthen data protection, and create measurable evidence that security capabilities are operating as intended.

You will also modernize security data and logging architectures so the organization collects the right telemetry - not simply more telemetry. This includes rationalizing duplicate data flows, improving classification and retention, controlling Sentinel cost, and maintaining the visibility required to defend against sophisticated and increasingly AI-enabled nation-state threats. The role requires someone who can move comfortably between architecture and hands-on engineering, guide a small team, and drive work from concept through operational adoption.

Grow your skillswhile helping build the next generation of cloud security operations and continuous assurance in Azure Government.

Join us. The world can't wait.

You Have:

  • 5+ years of experiencedesigning, engineering, or securing Microsoft Azure environments, including cloud security, networking, identity, monitoring, DevSecOps, or infrastructure
  • Experiencedesigning or engineering security solutions within Microsoft Azure Government, and engineering Azure Policy, secure configuration baselines, and automated configuration-drift detection or remediation
  • Experienceimplementing and operating Microsoft Sentinel, including data connectors, Data Collection Rules, analytic rules, automation, workbooks, KQL, and monitoring architectures, and with Microsoft Defender for Cloud, Defender XDR, or Microsoft security capabilities
  • Experiencedesigning Azure logging and monitoring architectures using Azure Monitor, Log Analytics, Diagnostic Settings, Event Hub, Resource Graph, and Sentinel
  • Experiencedeveloping Infrastructure as Code with Terraform and integrating security into CI/CD or DevSecOps pipelines
  • Experiencesecuring cloud identity, including Entra ID, RBAC, PIM, managed identities, service principals, and Key Vault
  • Ability tolead technical workstreams from architecture and design through implementation, testing, deployment, and operational transition while guiding a small engineering team
  • Public Trust
  • Bachelor's degree
  • Microsoft Azure certification

Nice If You Have:

  • Experiencesupporting FedRAMP, FedRAMP 20x, NIST SP 800-53, Continuous Monitoring, or federal Authorization to Operate processes
  • Experiencebuilding automated security evidence, continuous control monitoring, compliance-as-code, or Key Security Indicator measurements
  • Experienceimplementing Detection-as-Code, automated detection testing, or MITRE ATT&CK-aligned security capabilities
  • Experiencedesigning defenses against advanced persistent threats, nation-state adversaries, or AI-enabled cyber attacks
  • Experiencewith Microsoft Purview, Data Loss Prevention, data classification, or exfiltration monitoring, and integrating vulnerability-management tooling such as Defender, Fortify, Sonatype, Azure DevOps, or ServiceNow
  • Experiencewith software supply-chain security, including SBOMs, artifact provenance, signing, dependency security, or build attestations
  • Experienceimplementing Azure backup, recovery, resiliency, or cyber-recovery capabilities
  • Knowledge ofOMB M-26-14 logging and network visibility requirements
  • Possession ofstrong client-facing communication skills
  • Security-focused certifications such as CISSP, CCSP, AZ-500, SC-100, or equivalentcloud security certifications

Vetting:

Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client;Public Trust determination is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,900.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model

Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
386,863 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Diego
$127k – $232k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Tysons • San Antonio
Java
C#
Java
Maven
C#
.NET
DevOps
AWS
Azure
CI/CD
Apply
$78k – $176k per year • In office • Full-Time • Bachelor's Degree • Arlington
Python
Databases
Apache Kafka
Kafka
AI/ML
Fine-tuning
Reinforcement Learning
Spark
DevOps
CI/CD
Docker
Git
Kubernetes
Apply
Solutions Architect 1 hour ago
$99k – $225k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Chantilly
DevOps
AWS
Azure
GCP
Apply
Solutions Architect 1 hour ago
$99k – $225k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chantilly • Aurora
DevOps
AWS
Azure
GCP
Apply
$134k – $193k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Cambridge
Python
SQL
Databases
Snowflake
DevOps
AWS
Azure
GitHub
OpenShift
Cybersecurity
GDPR
HIPAA
Apply
$99k – $225k per year • In office • Full-Time • 8+ years exp • High School Diploma • United States
DevOps
VMWare
Cybersecurity
Zero Trust
Apply
$78k – $176k per year • In office • Full-Time • Bachelor's Degree • Arlington
Python
Databases
Apache Kafka
Kafka
AI/ML
Fine-tuning
Reinforcement Learning
Spark
DevOps
CI/CD
Docker
Git
Kubernetes
Apply
Solutions Architect 1 hour ago
$99k – $225k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Chantilly
DevOps
AWS
Azure
GCP
Apply
Solutions Architect 1 hour ago
$99k – $225k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chantilly • Aurora
DevOps
AWS
Azure
GCP
Apply
$69k – $158k per year • In office • Full-Time • Bachelor's Degree • Bremerton
Apply
$152k – $228k per year • In office • Full-Time • 7+ years exp • San Diego
Go
Python
DevOps
AWS
CI/CD
Kubernetes
Apply
$152k – $228k per year • In office • Full-Time • San Diego
DevOps
AWS
IAM
Kubernetes
Terraform
Apply
$183k – $275k per year • In office • Full-Time • 7+ years exp • San Diego
Python
DevOps
AWS
Kubernetes
Apply
$150k – $262k per year • Equity • In office • Full-Time • 8+ years exp • San Diego
C#
C++
JavaScript
TypeScript
Frontend
Angular
Lit
React.js
Vue.js
Management
ServiceNow
Apply
$82k – $102k per year • In office • Full-Time • Master's Degree • San Diego
DevOps
CI/CD
Shift-Left
Cybersecurity
Shift-Left Security
Apply
See all jobs
This is one of many
386,863 more open roles from verified company boards, updated every day.