- Truetandem
- Reston, VA
- Full-Time
- 9 days ago
- $175,000–$230,000
Azure Network Engineer – Cleared (Polygraph).
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Azure Network Engineer – Cleared (Polygraph): our view in 3 lines...
- The Role:This role is for an Azure network engineer supporting Azure and Microsoft 365 services in a cleared federal environment.
- The Person:The person will design and implement Azure network topology, private connectivity, boundary controls, Terraform-based network configuration, platform access controls, and network evidence for the authorization package, then troubleshoot connectivity and ingestion failures.
- Requirements:The ideal candidate has five or more years of experience building Azure infrastructure, with hands-on work in virtual networking, routing, network security groups, Azure Firewall, private endpoints, and private DNS, plus Azure Government or another sovereign or disconnected cloud.
About the role
Key Responsibilities
• Design and implement network topology, routing, and segmentation for Azure Virtual Desktop (AVD), Microsoft 365, Power Platform, management, and telemetry paths.
• Build private connectivity end to end, including private endpoints, link scopes, private DNS zones, and conditional forwarding that resolves from every segment, as required. Coordinate external DNS dependencies.
• Implement and document boundary controls, network security groups, firewall policy, and the controlled transfer path used to move content, packages, and updates.
• Deliver network configuration as Terraform within the program's provider baseline Infrastructure as Code (IaC), central deployment location, and tenant state separation model.
• Implement network-layer access controls for platform administration, including management subnet reachability, administrative paths, and the reachability side of break-glass, in line with the program's design.
• Produce network evidence for the authorization package, including boundary diagrams, data flow descriptions, network configuration baselines, and the control statements that reference them.
• Troubleshoot connectivity and ingestion failures originating below the application and security tooling.
Required Qualifications
• Five or more years of experience, or equivalent experience, building Azure infrastructure, with deep hands-on work in virtual networking, routing, network security groups, Azure Firewall, private endpoints, and private DNS. Networking is the center of this role, not an adjacent skill.
• Direct experience in Azure Government or another sovereign or disconnected cloud.
• Demonstrated ability to diagnose a broken path across routing, DNS, and firewall policy, plus explain the fix in terms an assessor and a customer engineer can understand.
• U.S. citizenship.
• Active Top Secret with Polygraph clearance.
Key Responsibilities
• Design and implement network topology, routing, and segmentation for Azure Virtual Desktop (AVD), Microsoft 365, Power Platform, management, and telemetry paths.
• Build private connectivity end to end, including private endpoints, link scopes, private DNS zones, and conditional forwarding that resolves from every segment, as required. Coordinate external DNS dependencies.
• Implement and document boundary controls, network security groups, firewall policy, and the controlled transfer path used to move content, packages, and updates.
• Deliver network configuration as Terraform within the program's provider baseline Infrastructure as Code (IaC), central deployment location, and tenant state separation model.
• Implement network-layer access controls for platform administration, including management subnet reachability, administrative paths, and the reachability side of break-glass, in line with the program's design.
• Produce network evidence for the authorization package, including boundary diagrams, data flow descriptions, network configuration baselines, and the control statements that reference them.
• Troubleshoot connectivity and ingestion failures originating below the application and security tooling.
Required Qualifications
• Five or more years of experience, or equivalent experience, building Azure infrastructure, with deep hands-on work in virtual networking, routing, network security groups, Azure Firewall, private endpoints, and private DNS. Networking is the center of this role, not an adjacent skill.
• Direct experience in Azure Government or another sovereign or disconnected cloud.
• Demonstrated ability to diagnose a broken path across routing, DNS, and firewall policy, plus explain the fix in terms an assessor and a customer engineer can understand.
• U.S. citizenship.
• Active Top Secret with Polygraph clearance.

