Company Description
TrueTandem's mission is to be a trusted information technology solutions provider, committed to the success of our customers, communities and employees. To enable this mission, we listen to our customers’ needs, empower our dedicated and talented employees, envision success together, and deliver innovative cost-effective solutions. For our customers, we aim to deliver more power to meet their business outcomes through technology implementation, integration, optimization and customization. We enable some of the most well-known companies, nonprofits and federal agencies in the United States to intelligently plan and develop their applications, modernize their infrastructure and manage their data.
This position supports a project that operationalizes Azure plus supporting Microsoft Azure and Office 365 services. The role centers on Azure networking, including virtual network topology, routing, private connectivity, name resolution, ingress controls, and egress controls.
Key Responsibilities
- Design and implement network topology, routing, and segmentation for Azure Virtual Desktop (AVD), Microsoft 365, Power Platform, management, and telemetry paths.
- Build private connectivity end to end, including private endpoints, link scopes, private DNS zones, and conditional forwarding that resolves from every segment, as required. Coordinate external DNS dependencies.
- Implement and document boundary controls, network security groups, firewall policy, and the controlled transfer path used to move content, packages, and updates.
- Deliver network configuration as Terraform within the program's provider baseline Infrastructure as Code (IaC), central deployment location, and tenant state separation model.
- Implement network-layer access controls for platform administration, including management subnet reachability, administrative paths, and the reachability side of break-glass, in line with the program's design.
- Produce network evidence for the authorization package, including boundary diagrams, data flow descriptions, network configuration baselines, and the control statements that reference them.
- Troubleshoot connectivity and ingestion failures originating below the application and security tooling.
Required Qualifications
- Five or more years of experience, or equivalent experience, building Azure infrastructure, with deep hands-on work in virtual networking, routing, network security groups, Azure Firewall, private endpoints, and private DNS. Networking is the center of this role, not an adjacent skill.
- Direct experience in Azure Government or another sovereign or disconnected cloud.
- Demonstrated ability to diagnose a broken path across routing, DNS, and firewall policy, plus explain the fix in terms an assessor and a customer engineer can understand.
- U.S. citizenship.
- Active Top Secret with Polygraph clearance.

