Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable local laws, regulations, and ordinances.
Senior Cloud Solution Architect Cybersecurity (Exercises) - CTJ - Top Secret
Location
United States
Posted
72 days ago
Salary
$106K - $222K / year
Seniority
Senior
Job Description
Senior Cloud Solution Architect Cybersecurity (Exercises) - CTJ - Top Secret
Microsoft
Overview We are seeking a senior cybersecurity professional to lead defender-focused (Blue Cell) capabilities within large-scale cyber exercises. This role is responsible for designing, operationalizing, and continuously improving how participants detect, investigate, and respond to adversary activity in realistic, mission-aligned scenarios. The Blue Team Lead defines the defender experience: developing workflows, training objectives, evaluation criteria, and reference materials that reflect real-world security operations. This role ensures exercises produce measurable improvements in customer detection and response capabilities across both proactive threat hunting and reactive incident response. Cyber exercises operate as live environments where timing, tooling, adversary actions, and participant behavior evolve dynamically. The Blue Team Lead ensures defender guidance is actionable, outcomes are measurable, and lessons learned translate into lasting operational improvements. Responsibilities Microsoft Federal is seeking individuals passionate about advancing cybersecurity readiness through immersive, hands-on exercises that strengthen operational resilience for U.S. Federal agencies. Ideal candidates for this role will demonstrate technical expertise, strong facilitation skills, and a commitment to driving measurable security outcomes. As a Senior Cloud Solution Architect Cybersecurity (Exercises), you will support the planning, facilitation, and delivery of immersive cybersecurity exercises for U.S. Federal customers. Working alongside senior CSAs, you will help design scenarios, operationalize technical solutions, and drive measurable security outcomes through hands-on engagement and collaboration. Responsibilities include: Blue Cell Design Authority - Own the design of defender-facing content across exercises, including workflows, tasks, success criteria, and evaluation frameworks. - Ensure all defender activities align to realistic security operations and customer mission requirements. - Establish and run the daily briefing rhythm to confirm customer findings and prevent analytical rabbit holes (customer briefs “was this you,” red validates yes/no) Blue Team-focused Stakeholder Orchestration - Align exercise scope, objectives, and communications with account team, customer, and delivery stakeholders; coordinate control‑cell and intelligence for injects; manage blue team operations schedule. - Represent the program in customer briefings and executive touchpoints; set expectations and ensure outcomes are landed with account teams. - Translate complex technical tradecraft into clear, outcome-focused narratives for senior customer leadership and non-technical stakeholders. - Ensure defensive actions remain grounded in realistic operational constraints and decision-making Drive Business Outcomes - Translate exercise results into actionable recommendations for improving customer security operations. Own and lead defender outcomes aligned to strategic customer objectives, accelerating adoption and operationalization of Microsoft security tools through repeatable, measurable defender workflows. - Partner with account teams to translate exercise findings into follow-on opportunities (control fixes, detection coverage improvements, and roadmap-aligned next steps). - Track and communicate exercise-driven outcomes (skill uplift, detection gaps closed, and prioritized remediation guidance) in a way that is actionable for customer leadership and Microsoft account teams. Design Defender Workflows & Hunt Content - Develop and govern defender-facing content: workflows, evaluation points, and success criteria aligned to security operations and customer mission needs. - Build and maintain reusable hunting content packages (KQL quick sheets, investigation playbooks, validation checklists, and scenario-aligned hunt guides) that scale delivery consistency. - Translate red team TTPs into defender detection expectations (telemetry sources, logging gaps, validation steps), enabling rapid iteration during delivery and clear improvements post-exercise. - Lead after-action analysis focused on defensive performance, detection coverage, and response effectiveness. - Drive post-exercise refinement of defender guidance, detection expectations, and learning materials based on observed outcomes and identified gaps. Mentorship & Collaboration - Mentor junior team members in defensive tradecraft, analytical reasoning, and exercise delivery. - Lead regular team knowledge-sharing sessions that improve blue-team hunting quality and delivery consistency across parallel exercises. - Develop and standardize playbooks, methodologies, and content to improve consistency across the team. - Partner tightly with red team and control-cell to ensure timing, injects, and debriefs produce maximum defender learning value and actionable takeaways. Travel is an integral part of this position. You should be willing to travel as is demanded by the needs of our customers and our business. This position requires approximately 50-75% overnight travel. Qualifications Required Qualifications: Bachelor's Degree in Computer Science, Information Technology, Engineering, Business, Liberal Arts, or related field AND 4+ years experience in cloud/infrastructure technologies, information technology (IT) consulting/support, systems administration, network operations, software development/support, technology solutions, practice development, architecture, and/or consulting OR equivalent experience. Other Requirements: Security Clearance Requirements: Candidates must be able to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: - The successful candidate must have an active U.S. Government Top Secret Security Clearance. Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. Failure to maintain or obtain the appropriate clearance and/or customer screening requirements may result in employment action up to and including termination. - Clearance Verification: This position requires successful verification of the stated security clearance to meet federal government customer requirements. You will be asked to provide clearance verification information prior to an offer of employment. - Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter. - Citizenship & Citizenship Verification: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance Preferred Qualifications: - Bachelor's Degree in Computer Science, Information Technology, Engineering, Business, Liberal Arts, or related field AND 8+ years experience in cloud/infrastructure technologies, information technology (IT) consulting/support, systems administration, network operations, software development/support, technology solutions, practice development, architecture, and/or consulting OR Master's Degree in Computer Science, Information Technology, Engineering, Business, Liberal Arts, or related field AND 6+ years experience in cloud/infrastructure technologies, technology solutions, practice development, architecture, and/or consulting OR equivalent experience. - 4+ years experience working in a customer-facing role (e.g., internal and/or external). - 4+ years experience working on technical projects. Technical Certification in Cloud (e.g., Azure, Amazon Web Services, Google, security certifications). Defensive Cyber Operations (Proactive + Reactive): - Experience leading or operating within security operations, threat hunting, detection engineering, or incident response functions in enterprise or U.S. Federal environments - Ability to design and execute both proactive (hypothesis-driven hunting, coverage development) and reactive (investigation, containment, recovery) defensive workflows - Experience translating operational activity into improved detection logic, response playbooks, and defensive tradecraft - Coach and mentor customers on defensive actions during live cyber exercises (e.g., account actions, device isolation, blocking indicators, mitigation activity), including justifications and operational risk. - Detection Engineering & Telemetry Analysis: - Strong understanding of how adversary behaviors map to telemetry across identity, endpoint, network, application, and cloud environments. - Experience developing and iterating detection logic, hunting methodologies, and investigation workflows. - Experience building reusable defensive content (playbooks, analytic patterns, hunt guides, validation frameworks). - Ability to identify visibility gaps, define data requirements, and validate detection coverage against adversary techniques. - Lead and facilitate exercise delivery after action reports (AARs) with customer-facing security response teams, executive level leadership, and Microsoft security personnel. - Experience applying AI/ML and GenAI-assisted workflows to defensive cyber operations Cloud, Identity, & Hybrid Environments: - Experience investigating and defending modern environments, including identity-centric attacks, cloud resource abuse, and hybrid infrastructure scenarios. Ability to correlate activity across multiple data sources and platforms to build a complete operational picture. - Cyber Exercise Design & Blue Cell Leadership. Experience designing defender-facing exercise content, including: - Detection and response workflows - Participant tasks and decision points - Success criteria and evaluation metrics. - Ability to translate real-world adversary behavior into structured learning objectives and measurable outcomes. - Experience supporting or leading cyber exercises, simulations, or operational training environments. - Leadership & Operational Excellence - Ability to lead and mentor teams in high-tempo, ambiguous environments. - Strong facilitation skills across technical operators and senior leadership audiences. - Experience driving consistency and quality across multiple concurrent efforts. - Ability to translate technical findings into clear, mission-relevant insights and recommendations. Certifications (Preferred, Not Required): - Microsoft Security Operations Analyst (SC-200) or Azure Security Engineer (AZ-500). - Industry recognized blue team or cybersecurity security certifications like GCFR, GCIH, or GCFA are desirable but not mandatory. Cloud Solution Architecture IC4 - The typical base pay range for this role across the U.S. is USD $106,400 - $203,600 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $137,600 - $222,600 per year. Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Related Guides
Related Categories
Related Job Pages
More Cloud Engineer Jobs
IT CLOUD ENGINEER PROFESSIONAL
inchcapeInchcape is the leading global automotive distributor operating in 38 markets. We partner with some of the biggest brands in the business to sustainably power better mobility today and in the future. Our diverse global team of over 16,000 talented colleagues foster an inclusive and collaborative culture, delivering a brilliant experience for our customers and partners. We’re a dynamic and fast-growing business, driving the transformation of our industry and redefining tomorrow.
Role Description Are you looking to accelerate your professional development, build a brilliant career, and thrive in a highly supportive team? Join Inchcape Digital part of Inchcape’s global network. You’ll play a key part in delivering great experiences for our customers and colleagues. With lots of interesting opportunities and challenges for you to explore that will take us, and your progression, to the next level. Our IT Operations platform is seeking an IT Cloud Engineer Professional to join our team in Colombia. In this position, you will be responsible for: - Management and administration of cloud platforms, applications, and computer services. - Ensuring high availability of client/server applications. - Configuring new implementations and developing processes for ongoing management of the cloud environment. - Learning best practices for deploying resources in the cloud. - Maintaining cloud security, integrity, and safety of server and cloud resources. The main responsibilities include: - Administration of platforms, including servers and operating system maintenance. - Maintaining and administering technologies associated with NCI's Cloud services. - Becoming a referent for the correct use of NCI's Cloud services. - Monitoring and proposing improvements to mitigate risks associated with the infrastructure. - Providing services to worldwide Inchcape markets. - Working closely with the NCI project & Service Delivery area on the DDC (Colombia and Philippines). - Collaborating with cross-functional teams to embed best practices into the infrastructure delivery lifecycle. - Participating in project execution, implementing solutions, and managing new project infrastructure. - Providing day-to-day support for Azure and CMS DevSecOps pipelines across multiple regions. - Managing CI/CD pipelines and implementing DevOps practices. - Available to work in different time zones and 7x24 shifts. - Some afterhours work will be required to join online meetings with global team members. Qualifications - Hands-on experience with Microsoft Azure services (AKS, App Services, Azure Functions, Storage, Key Vault, Networking, Virtual Machine, Entra-ID, DNS, among others). - Experience designing, maintaining, and troubleshooting GitHub Actions. - Secrets management in Key Vault, administration, and access control. - Permissions and management of primary app registration and service for access to roles and applications in Azure AD (AAD). - Basic to intermediate knowledge of infrastructure as code (Terraform). - Basic to intermediate knowledge of Docker and Kubernetes (AKS) for application deployment and lifecycle management. - Deployment of network resources appliances VPN S2S, Route tables, VNET, peering, Virtual private link, NSG, VHUB, Network segmentation, Firewall policies, and Zero-Trust principles. - Remote access: Bastion, MFA, conditional access enforcement. - Bachelor’s degree in computer science, Information Technology, Engineering, or a related field. - Equivalent hands-on experience in Cloud, or IT Operations may be considered in place of a formal degree. - Microsoft Certified: Azure Fundamentals (AZ-900) and Azure Administrator (AZ-104) – Desirable. Benefits - Supportive Environment: Work alongside a dynamic team committed to your success. - Career Growth: We're invested in your development and offer ample opportunity for advancement. - Work-Life Balance: Enjoy a role that balances strategic analysis with day-to-day business support. - Industry Leadership: Be part of a company that leads the transformation of the automotive distribution industry. Company Description Inchcape is the leading global automotive distributor operating in 38 markets. We partner with some of the biggest brands in the business to sustainably power better mobility today and in the future. Our diverse global team of over 16,000 talented colleagues foster an inclusive and collaborative culture, delivering a brilliant experience for our customers and partners. We’re a dynamic and fast-growing business, driving the transformation of our industry and redefining tomorrow. Inchcape Digital employs over 1,300 team members across Colombia and Philippines. Our portfolio includes vehicle distribution for world-renowned brands, market-leading fulfilment solutions, exceptional retail experiences, and tailored financial services.
• Design, implement, and manage AWS-based cloud infrastructure. • Build and maintain CI/CD pipelines using GitHub Actions and AWS CodeBuild. • Manage and optimize containerized environments using Docker. • Support and optimize application deployments, particularly for .NET-based systems. • Monitor system performance and troubleshoot infrastructure and deployment issues. • Collaborate with development teams to improve deployment processes and system reliability. • Ensure scalability, security, and high availability of cloud environments. • Continuously improve infrastructure through automation and best practices.
Cloud Engineer
AIS (Applied Information Sciences)A Partner That Brings Enterprise Cloud Transformation Full Circle
• Design, configure, and administer Microsoft Purview compliance capabilities across the Microsoft 365 environment. • Implement and support eDiscovery Standard and Premium workflows, including: Case creation and management, Custodian and non-custodial data source identification, Legal hold configuration, Search and collection design, Review set preparation, Export and handoff support. • Perform and support Content Search, Audit, and Communication/Collaboration data investigations across Exchange Online, SharePoint Online, OneDrive, Teams, and other supported M365 workloads. • Design and manage retention labels, retention label policies, retention policies, and records management configurations aligned with business, legal, and regulatory requirements. • Support implementation of sensitivity labels and Microsoft Information Protection integrations where they intersect with compliance and governance objectives. • Configure and support Data Loss Prevention (DLP) policies for Microsoft 365 workloads, including tuning, testing, and operational troubleshooting. • Assist legal, compliance, and information governance teams with preservation, collection, defensibility, and chain-of-custody-oriented processes within Microsoft 365 tooling. • Support investigation workflows using Microsoft Purview Audit and related compliance telemetry. • Collaborate with security, messaging, collaboration, and identity teams to ensure Purview solutions align with enterprise architecture and access controls. • Develop operational runbooks, standard operating procedures, governance standards, and technical documentation. • Support role-based access control, least privilege, and administrative segmentation within the Purview and Microsoft 365 compliance ecosystem. • Participate in roadmap planning for information governance, data protection, and compliance modernization initiatives. • Provide Tier 3 support and troubleshooting for escalated Purview, eDiscovery, retention, and compliance policy issues.
Oracle Cloud Change Management Project Lead
Automus Consulting IncEOE/Must be legally authorized to work in the United States without sponsorship. Send resumes to: careers@automus.com
Role Description Automus is seeking a Change Management Project Lead with 10+ years of experience working with Oracle Cloud or another ERP / large system implementation. The role involves leading cross-functional discussions at various levels with client HR, Steering Committee, business users, and end users to: - Analyze change readiness - Assess change impacts - Identify risks - Develop training plans and organizational change plans The Change Management Project Lead will also help articulate solutions and recommend best practices to stakeholders. This is a very independent, highly visible client-facing role. Other responsibilities include: - Documenting and executing on change management plan - Conducting change impact assessments - Creating training plans The Change Management Project Lead will work alongside Automus functional consultants and project managers during design, build, and test phases, and will play a key role in guiding the client during end user training in the final solution including: - Go-live readiness - Hyper-care support at go-live Qualifications - Bachelor’s degree in Business, Finance, Accounting, Communications, Technology or other related field - 10+ years progressive experience in a consulting environment or related industry experience, preferable implementing an ERP system - 5+ years’ experience with change management for ERP implementations - Project management experience - Certification in change management (PROSCI) would be an added advantage - Self-motivated, positive attitude, with a can-do approach - Work independently and manage multiple task assignments in a fast-paced environment - Interact effectively with team and clients through in-person meetings, chat, email, phone, and video conferencing as appropriate - Excellent verbal and written communication along with strong analytical skills - Resolve problems in a timely and effective manner, involving project managers and executive management as appropriate - Demonstrate high level computer skills and knowledge in Office 365 (Teams, Outlook, Word, PowerPoint, Excel, Visio) and in Smartsheet - Experience with AI is a plus Requirements - Ability to travel nationwide up to 25% to client site – typically once a month


