Top 35 business advisory and CPA firm helping clients and team members achieve what's next.
Lead Engineer, Azure
Location
United States
Posted
1 day ago
Salary
$98.9K - $132.8K / year
Seniority
Senior
Job Description
Lead Engineer, Azure
Aprio
• Act as a trusted consultant to clients, guiding them through complex security and compliance challenges • Support the client relationship from discovery through delivery—serve as the technical consultant • Assist in workshops, architecture sessions, and demos to translate client needs into actionable solutions • Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53 • Architect and implement Zero Trust strategies, XDR deployments, and threat modeling frameworks for mid-market and enterprise clients • Ensure compliance while improving operational security—deliver measurable business value
Job Requirements
- Bachelor’s degree or equivalent experience
- 7+ years of consulting experience, partnering with clients to deliver tailored solutions
- Strong communication and stakeholder management skills—comfortable leading client conversations
- 3+ years of Hands-on design and implementation of Microsoft Azure security tools
- Deep understanding of core cybersecurity principles: zero trust, privileged access, APT threats, credential theft, and just-in-time administration
- At least 1 of the following certifications needed (active or obtained within 90 days of hire): AZ-500, AZ-305, SC-100, SC-200, SC-300, SC-401
Benefits
- Medical, Dental, and Vision Insurance on the first day of employment
- Flexible Spending Account and Dependent Care Account
- 401k with Profit Sharing
- 9+ holidays and discretionary time off structure
- Parental Leave – coverage for both primary and secondary caregivers
- Tuition Assistance Program and CPA support program with cash incentive upon completion
- Discretionary incentive compensation based on firm, group and individual performance
- Incentive compensation related to origination of new client sales
- Top rated wellness program
- Flexible working environment including remote and hybrid options
Related Guides
Related Categories
Related Job Pages
More Cloud Engineer Jobs
Role Description Du willst Storage nicht nur betreiben, sondern wirklich gestalten? Für Dich ist Storage mehr als Kapazität und Festplatten? Du willst verstehen, was im Cluster passiert, wenn OSDs ausfallen, Daten neu verteilt werden, Latenzen steigen oder mehrere Petabytes zuverlässig wachsen müssen? Dann werde Teil unseres Cloud Native Teams und gestalte die Storage-Basis unserer souveränen Cloud-Plattform. Wir setzen auf Open Source, eigene deutsche Rechenzentren und Technologien wie Ceph, OpenStack und Kubernetes. Dabei verbinden wir technische Freiheit mit hohen Anforderungen an Verfügbarkeit, Sicherheit und Auditierbarkeit. - Du übernimmst die technische Verantwortung für unsere produktiven Ceph-Cluster und entwickelst deren Architektur kontinuierlich weiter. - Du betreibst, administrierst und optimierst Ceph RBD sowie den Ceph Object Storage mit RGW und einer S3-kompatiblen Schnittstelle. - Du planst und realisierst Upgrades, Erweiterungen sowie Lifecycle-Maßnahmen und setzt diese strukturiert und weitestgehend automatisiert um. - Du analysierst Performance-, Kapazitäts- und Stabilitätsprobleme und entwickelst nachhaltige Lösungen zu deren Behebung. - Du entwickelst unsere Automatisierung mit Ansible, Python und Git kontinuierlich weiter und reduzierst manuelle Eingriffe durch reproduzierbare Prozesse. - Du integrierst Ceph in unsere Cloud-Plattformen, insbesondere in OpenStack- und Kubernetes-Umgebungen. - Du optimierst Monitoring, Alerting, Capacity Management sowie unsere technischen Betriebsstandards kontinuierlich. - Du bearbeitest komplexe Incidents und Problems im 2nd- und 3rd-Level-Support, führst Root-Cause-Analysen durch und leitest nachhaltige Verbesserungsmaßnahmen ab. - Du dokumentierst Architekturentscheidungen, Betriebsverfahren und Automatisierungen nachvollziehbar und revisionssicher. - Du unterstützt Kolleginnen und Kollegen als technische Ansprechperson, teilst dein Wissen aktiv im Team und förderst den fachlichen Austausch. Qualifications - Mehrjährige Berufserfahrung im Engineering und Betrieb komplexer Linux- und Storage-Infrastrukturen. - Fundierte praktische Erfahrung mit Ceph in produktiven Umgebungen. - Sehr gute Kenntnisse in Linux sowie ein fundiertes Verständnis verteilte Systeme und deren Architektur. - Erfahrung mit Fehleranalyse, Performance-Tuning, Kapazitätsplanung sowie Upgrade- und Lifecycle-Prozessen. - Gute Kenntnisse in der Automatisierung mit Ansible und idealerweise Python. - Sicherer Umgang mit Git und nachvollziehbaren, versionskontrollierten Arbeitsweisen. - Solides Verständnis von Netzwerktechnologien wie Routing, DNS, Firewalling und NAT. - Analytische, strukturierte und lösungsorientierte Arbeitsweise. - Freude daran, technische Verantwortung zu übernehmen und Entscheidungen nachvollziehbar zu vertreten. - Gute Deutsch- und Englischkenntnisse in Wort und Schrift. - Abgeschlossene IT-Ausbildung, ein technisches Studium oder eine durch einschlägige Berufserfahrung erworbene gleichwertige Qualifikation. Benefits - Unbefristeter Arbeitsvertrag und flexible Arbeitszeiten. - Ruhezeitenausgleich auf Dein Stundenkonto. - Arbeiten an verschiedenen Standorten möglich (z.B. Nürnberg, Aschheim, Berlin) oder auch zu 100% Remote. - Hochwertiges Equipment: Laptop und Firmenhandy auch zur privaten Nutzung. - Individuelle Förderung und Weiterentwicklung durch Inhouse-Trainings und externe Schulungen. - Kinderbetreuungskostenzuschuss (pro Monat/Kind) und Corporate Benefits. - Attraktive Firmenevents (inkl. Reisekostenübernahme), kollegiales und wertschätzendes Arbeitsumfeld sowie Duz-Kultur ab dem ersten Tag. - Großzügiger Zuschuss zum Deutschlandticket. - Gesundheitsmanagement (z.B. kostenlose Massagen inhouse), Jobrad Leasing und betriebliche Altersvorsorge mit Zuschuss. - Welcome Day, direkter Ansprechpartner (m/w/d) und strukturierte Einarbeitungsphase. - Getränke for free (auch Softdrinks) und frisches Obst an den Standorten.
• Define technical strategy and architecture for secure cloud platform services. • Lead the design of centralized platform APIs, reusable CI/CD components, and automated deployment workflows. • Drive automation of federal promotion processes with reliable, gated delivery pipelines. • Establish best practices for service onboarding, deployment validation, operational readiness, and rollback safety. • Lead architecture and design reviews for services moving into federal environments. • Partner across teams to resolve technical dependencies and drive key engineering decisions. • Mentor engineers and raise the bar for architecture, code quality, operational practices, and incident response.
• Manage large security projects, proactively enhance system defenses, and ensure compliance with regulations like HIPAA and the HITRUST r2 CSF • Develop robust and secure code for security tooling, automation, and critical integrations to improve our security posture • Partner with cross-departmental leaders in Suki to reduce the friction, increase speed-to-market and deliver secure-by-design products • Conduct security assessments and red-teaming on proprietary and third-party AI/ML models, LLMs, and data pipelines (testing for prompt injection, data poisoning, training data extraction, and model inversion) • Implement guardrails to prevent PHI exposure in model training, vector databases, RAG architectures, and fine-tuning datasets • Own the technical security architecture across our multi-cloud footprint (AWS / GCP / Azure), ensuring zero-trust principles and robust Cloud Security Posture Management (CSPM) • Secure Kubernetes clusters, container registries, and Infrastructure-as-Code (Terraform / CloudFormation) within CI/CD deployment pipelines • Design and enforce least-privilege IAM policies, role-based access controls (RBAC), just-in-time (JIT) provisioning, and secrets management across cloud environments • Design and enforce microsegmentation, VPC architecture, SASE/VPN solutions, and strict network isolation for multi-tenant health data architectures • Manage network security controls, intrusion detection/prevention systems (IDS/IPS), and Web Application Firewalls (WAF) to prevent unauthorized data exfiltration • Proven track record in cloud network design, VPC routing, cloud firewalls, Zero Trust Network Access (ZTNA), and egress control
IT Cloud Architect
Circular Action AllianceCAA is a U.S. Producer Responsibility Organization dedicated to implementing effective EPR laws for paper and packaging.
• Administration of M365 Services: Copilot/Agents, Copilot Studio, Power Platform, Power BI, Docusign and Kiteworks • Solid working knowledge of Azure Services and Integrations • Assess the existing environment to identify improvements • Evaluate new technologies and trends to make recommendations on how they can be implemented to impact the company positively • Design solutions and lead staff in the implementation of the designs through mentorship and guidance • Provide a bridge between technical staff and business leadership • Increase efficiency within the IT department through streamlining and automating processes • Provide technical direction on system implementation • Drive plans for the integration of new infrastructure systems • Drive virtual infrastructure design and implementation • Collaborate with the IT Operations Architect to implement platform standards, reference architectures, and operational best practices • Ensure infrastructure designs incorporate a security-first approach




