Our firm, Focused Management, Inc. (FMI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) and, Software Engineering Institute (SEI) – CMMI Maturity Level-3 Services Rated Company and we handle a wide range of government contracting opportunities. www.focusedmgmtinc.com
FMI is seeking a highly experienced Microsoft Cloud System Engineer who should provide advanced engineering, operational, and advisory support for the government’s Microsoft cloud environments, including Microsoft 365, Azure, and Microsoft Security platforms. The objective is to ensure a resilient, scalable, and secure Microsoft cloud environment that supports the government’s mission, cybersecurity posture, and continuity of operations. The Contractor is responsible for designing, implementing, maintaining, and optimizing secure cloud services in alignment with NIST SP 800-53, NIST SP 800-207 (Zero Trust Architecture), and FedRAMP Moderate control requirements. Requirements include enterprise tenant management, Azure infrastructure and application development support, Exchange Online and collaboration services, identity and access management, and the implementation of security controls across Microsoft Defender, Entra ID, Purview, and related services. The Contractor will apply Zero Trust principles, least privilege, continuous verification, and conditional access while supporting compliance, audit readiness, and change management processes.
POSITION: Microsoft Cloud Operations Engineer
LOCATION: Washington, DC
SUMMARY /GENERAL DESCRIPTION OF RESPONSIBILITIES:
Required Qualifications
The Microsoft Cloud Operations Engineer shall:
The scope of work includes, but is not limited to, the following activities:
- Microsoft Cloud Platform Engineering: Design, implement, operate, and optimize Microsoft 365, Azure, and Microsoft Security services to ensure reliability, scalability, and performance in support of government mission requirements.
- Security Architecture & Compliance: Implement and maintain cloud security controls aligned with NIST SP 800-53, NIST SP 800-207 (Zero Trust Architecture), and FedRAMP Moderate requirements, including continuous monitoring, risk mitigation, and security posture management.
- Identity & Access Management: Administer and secure identity services using Microsoft Entra ID, Conditional Access, privileged access controls, and least-privilege models in accordance with Zero Trust principles and Microsoft best practices.
- Collaboration & Messaging Services: Manage and support Exchange Online, Teams, SharePoint Online, and related collaboration services, ensuring availability, security, and compliance with organizational policies.
- Azure Infrastructure & Development Support: Provide engineering support for Azure infrastructure, networking, and application workloads, including configuration, maintenance, troubleshooting, and integration with on-premises or hybrid environments as applicable.
- Security Operations Enablement: Configure and manage Microsoft Defender, Purview, and related security platforms to support threat protection, data governance, information protection, and incident response readiness.
- Change Management & Documentation: Support formal change management processes, maintain technical documentation, and contribute to standard operating procedures to ensure transparency, traceability, and operational continuity.
- Advisory & Technical Leadership: Serve as a senior technical advisor to government stakeholders, collaborating with network, cybersecurity, and cloud teams to resolve complex issues, improve architecture, and support audits, assessments, and compliance reviews.
The Senior Microsoft Cloud Engineer must meet the following specific requirements:
- Demonstrated ability to provide senior-level technical leadership and independent operational support for enterprise Microsoft cloud environments, including Microsoft365, Azure, and Microsoft Security platforms. This includes proof of currently maintained Microsoft certifications in all related areas for a period of no less than 5 years.
- Proven expertise in designing, implementing, operating, and optimizing Microsoft cloud services to ensure high availability, scalability, performance, and mission alignment.
- Ability to implement and maintain cloud security architectures aligned with NIST SP 800-53, NIST SP 800-207 (Zero Trust Architecture), and FedRAMP Moderate requirements, including continuous monitoring, risk mitigation, and security posture management.
- Advanced ability to fully implement and manage a hybrid Active Directory Microsoft M365 and Entra environment implementing the tiered security standards defined by Microsoft’s security framework.
- Proven experience creating and managing all aspects of Windows, MacOS, and Apple iOS devices in Intune including compliance and policy delivery.
- Proven experience creating and managing Autopilot delivery of operating system images and use of policy and on-demand delivery of software using Intune for environments of at least 700 endpoints.
- Practical experience locking down remote PowerShell access for administrative tasks in Entra and Azure across all related APIs to allow necessary administration including headless Exchange Online mailbox provisioning, SharePoint custom user profile field imports, and all Microsoft Graph related access.
- Advanced proficiency in identity and access management, including Microsoft Entra ID, Conditional Access, privileged access management, and least-privilege access models, including the implementation and minimal impact transition between MFA providers, implementation of 3rd party MFA as an Entra provider, and implementation of Smart Card and FIDO based key authentication methods across Windows and MacOS systems.
- Experience managing and supporting collaboration and messaging services, including Exchange Online, Microsoft Teams, SharePoint Online, and related Microsoft 365 workloads.
- Capability to provide Azure infrastructure and application support, including cloud networking, workload configuration, maintenance, troubleshooting, and hybrid integration where applicable.
- Hands-on experience configuring and managing Microsoft security platforms, including Defender, Sentinel, and Purview, to support threat protection, data governance, information protection, and incident response readiness.
- Demonstrated ability to manage and configure data sources feeding into Microsoft Sentinel including ongoing health reporting and alerting on ingest log data quality.
- Ability to support and comply with formal change management processes, produce and maintain technical documentation, training materials, and contribute to standard operating procedures.
- Demonstrated capacity to act as a senior technical advisor, collaborating with government engineering teams to resolve complex technical issues and support audits, assessments, and compliance reviews.
- Ability to perform duties with minimal supervision, exercising sound independent judgment and technical authority in maintaining a secure, resilient, and compliant Microsoft cloud environment.
- Implement automated reporting and dashboard creation using Power BI and other Microsoft tools. Reporting must include systems health monitoring, compliance reports, current spend and forecasted spend reports, and utilization reports across all aspects of the government’s Microsoft cloud infrastructure.
- Must have proven experience setting up spending budget configurations in Azure including alerting and reporting for potential overages against budgets that allow 90 days lead time to allow government decision time for appropriate actions including either reduction in usage to avoid overages or acquisition and allocation of increased funding.
- Implement incident response and disaster response playbook responses as clearly written practical procedural documents that integrate into government’s existing IR and COOP documentation and procedural documents.
Mandatory Requirements:
- U.S. Citizenship
- Ability to obtain and successfully maintain an Active Public Trust Security Clearance
- Bachelor’s degree in computer science, Software Engineering, Information Systems, or related discipline.
- Experience supporting Federal Government IT environments.
- Experience integrating enterprise applications with Microsoft cloud platforms.
- Experience supporting production enterprise applications.
- Experience leading technical discussions with Government stakeholders.
Mandatory Certifications
Microsoft 365 Certified: Administrator Expert
Microsoft Certified: Cybersecurity Architect Expert
Microsoft Certified: Azure Solutions Architect Expert
Microsoft 365 Certified: Endpoint Administrator Associate
Microsoft Certified: Identity and Access Administrator Associate
Microsoft Certified: Windows Server Hybrid Administrator Associate
Microsoft 365 Certified: Teams Administrator Associate
Microsoft Certified: Information Security Administrator Associate
Job Types: Full-time, Contract
Pay: $145,000.00 - $160,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Education:
Experience:
- Federal Government IT support: 5 years (Required)
- Zero Trust : 4 years (Preferred)
- Microsoft Cloud Platform engineering: 4 years (Required)
- NIST standards: 5 years (Required)
- Azure : 4 years (Required)
- Microsoft Defender: 4 years (Preferred)
- Government Community Cloud (GCC): 5 years (Required)
- Microsoft Dynamics 365: 4 years (Required)
Security clearance:
Work Location: In person