Cloud Engineer

Posted 2 Days Ago
Be an Early Applicant
Denver, CO, USA
In-Office
Senior level
Cloud • Information Technology • Business Intelligence • Consulting
The Role
Administers and engineers enterprise identity and messaging services across Active Directory, Entra ID, Exchange, Exchange Online, and hybrid Microsoft environments. Responsibilities include infrastructure design, security hardening, identity synchronization, authentication, network troubleshooting, compliance, automation, cloud modernization, documentation, and Tier III support within complex federal environments. The role requires extensive PowerShell automation, federal cybersecurity compliance, incident response support, and participation in on-call rotations.
Summary Generated by Built In
Planet Technologies, the Nation’s leading Microsoft services provider to the public sector, is looking for a highly motivated individual to join our growing team as Cloud Infrastructure Engineer. In this role, you will be supporting impactful projects that make a difference for our country. 

The Senior Identity and Messaging Engineer is responsible for supporting, maintaining, securing, and enhancing enterprise identity and messaging services across on-premises and Microsoft cloud environments. This hands-on role administers and engineers Microsoft Active Directory, Microsoft Entra ID, Exchange Server, Exchange Online, and the hybrid services that connect them in a complex federal environment.  

  • Must have existing Top Secret and/or DOE Q Clearance

Responsibilities

    Active Directory Administration & Engineering

  • Design, implement, configure, and maintain multi-domain and multi-forest Microsoft Active Directory Domain Services infrastructure, including trusts, Flexible Single Master Operations roles, domain controller lifecycle management, schema changes, functional-level upgrades, and disaster recovery.
  • Manage Domain Controllers, Group Policy Objects (GPOs), DNS, DHCP, Sites and Services, and Active Directory replication.
  • Perform schema modifications, forest and domain functional level upgrades, and disaster recovery planning.
  • Harden Active Directory using tiered administration, Local Administrator Password Solution, privileged access workstations, Microsoft Defender for Identity, and findings from tools such as PingCastle and Purple Knight. Design, maintain, or support administrative forest and tiered administration architectures, and advise customers on transitioning from legacy ESAE or Red Forest models to Microsoft's Enterprise Access Model where appropriate.
  • Monitor and optimize AD performance, health, and security.
  • Exchange Administration & Engineering

  • Administer and support Exchange Server 2016, Exchange Server 2019, Exchange Server Subscription Edition, and Exchange Online, including Database Availability Groups, transport services, certificates, cumulative updates, security updates, and high-availability configurations.
  • Manage mailbox provisioning, migrations, retention policies, archive solutions, and email routing.
  • Build, maintain, and troubleshoot Exchange hybrid deployments using the Hybrid Configuration Wizard, organization relationships, free/busy services, mail flow connectors, and centralized mail transport. Plan and execute remote-move, cutover, and cross-tenant mailbox migrations with minimal disruption to users.
  • Manage Exchange Online Protection and Microsoft Defender for Office 365, including SPF, DKIM, DMARC, transport rules, anti-spam, anti-phishing, and email encryption controls. Support retention, eDiscovery, litigation hold, journaling, and Microsoft Purview compliance workloads.
  • Support email continuity, backup, recovery, and high-availability configurations.
  • Identity & Access Management

    • Implement and support Microsoft Entra ID (Azure Active Directory).
    • Deploy, configure, maintain, and troubleshoot Microsoft Entra Connect and Entra Cloud Sync, including scoping and filtering, attribute flow, source anchor decisions, synchronization monitoring, and error remediation.
    • Configure and troubleshoot hybrid authentication using Password Hash Synchronization, Pass-through Authentication, and Active Directory Federation Services, and support migrations away from federation where appropriate. Implement Single Sign-On, Conditional Access, Multi-Factor Authentication, Privileged Identity Management, and phishing-resistant authentication using PIV/CAC and certificate-based authentication.
    • Participate in identity governance and role-based access control initiatives.
    • Collaborate with security teams to enforce Zero Trust architecture principles.
    • Network and Infrastructure

    • Work within segmented, multi-enclave federal networks to maintain Active Directory replication, authentication, directory synchronization, and mail flow across firewalls, VLANs, proxies, and security zones.
    • Identify and document required ports, protocols, Microsoft 365 endpoints, and GCC High or DoD-specific allow-list requirements.
    • Troubleshoot connectivity with Wireshark, netsh, pktmon, port testing, packet captures, and log analysis to isolate identity, application, and network failures.
    • Configure and troubleshoot split-brain and conditional DNS, forwarders, load balancers, VPN, SD-WAN, ExpressRoute, TIC 3.0 paths, DMZ services, and disconnected or cross-domain environments as applicable.
    • Cybersecurity & Compliance

    • Ensure systems comply with DOE requirements, NIST Special Publication 800-53, FISMA, FedRAMP, DISA Security Technical Implementation Guides, and applicable CISA Secure Cloud Business Applications baselines. Support Authority to Operate activities, security control assessments, audit evidence requests, vulnerability remediation, and compliance reporting.
    • Perform vulnerability remediation, security hardening, and patch management.
    • Support audits, security assessments, and compliance reporting activities.
    • Implement security baselines and monitor for unauthorized changes or suspicious activity.
    • Assist with incident response and forensic investigations involving identity and messaging systems.
    • Automation & Engineering

    • Develop and maintain PowerShell and Microsoft Graph automation for administration, reporting, monitoring, user lifecycle management, mailbox provisioning, group management, and repeatable operational tasks.
    • Automate user lifecycle management, mailbox provisioning, and group management processes.
    • Produce solution designs, operational runbooks, standard operating procedures, as-built documentation, port and protocol matrices, and technical diagrams that meet federal documentation and audit standards.
    • Support enterprise modernization initiatives involving Microsoft 365 and cloud migrations.
    • Operations Support

      • Provide Tier III escalation support for identity and messaging-related issues.
      • Participate in on-call support rotations as required.
      • Troubleshoot complex authentication, replication, Exchange, and directory synchronization issues.
      • Coordinate maintenance activities and planned outages.

Qualification

    • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or related field with 7 or more years of experience administering Active Directory in enterprise environments, including multi-domain or multi-forest architectures.
    • 5 or more years of experience administering Exchange Server, including hands-on responsibility for at least one Exchange hybrid deployment, and three or more years supporting Microsoft 365, Microsoft Entra ID, and Exchange Online.
    • Experience supporting enterprise environments with 5,000+ users preferred.
    • Senior-level experience supporting federal government customers onsite, with a demonstrated record of working effectively with government program managers, CIO staff, security officers, and contractors in professional, multi-vendor environments.
    • Demonstrated knowledge of TCP/IP, routing, subnetting, Network Address Translation, VLANs, firewalls, DNS, PKI and certificates, SMTP, Kerberos, and LDAP. Proven ability to diagnose network-related authentication, directory synchronization, and mail flow failures using packet capture, port testing, and log analysis in environments with strict change control.
    • PowerShell scripting and automation
    • Microsoft 365 Administration
    • Identity and Access Management (IAM)
    • Certificate Services (PKI)
    • Active Directory Federation Services (ADFS)
    • Windows Server Administration
    • Infrastructure:  Windows Server (2003-2025), Active Directory / GPO, Hyper-V & VMware, DHCP / DNS / NPS

      Security & Compliance:  DISA STIGs, Trellix EPO / HIPS, Vulnerability Scanners, (ACAS / Nessus)

      Systems Management:  MECM / SCCM, Exchange Server (2003-2019), Microsoft Active Directory, Entra ID and Azure AD Connect, Domain Services (AD DS), Red Hat / Linux+, Orchestrator / PowerShell

      Preferred Qualifications

      • Experience implementing Exchange Hybrid environments.
      • Experience with Microsoft Defender, Microsoft Purview, and Microsoft Sentinel.
      • Experience with CyberArk, Beyond Trust, or other Privileged Access Management (PAM) solutions.
      • Experience supporting Zero Trust initiatives.
      • Familiarity with virtualization technologies such as VMware or Hyper-V.
      • Experience administering Microsoft 365 in GCC, GCC High, or DoD tenants, including government-specific endpoints, security controls, service limitations, and hybrid connectivity requirements.
      • Experience with PIV/CAC authentication, federal Identity, Credential, and Access Management requirements, administrative forest or ESAE/Red Forest architectures, one-way trusts, shadow principals, bastion forests, or Microsoft Identity Manager Privileged Access Management.
      • Familiarity with Active Directory consolidation, domain migrations, tenant-to-tenant migrations, Azure networking, TIC 3.0, Zero Trust network architecture, and cross-domain solutions.
      • Certifications (Preferred)

      • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
      • Microsoft 365 Certified: Administrator Expert (MS-102)
      • Microsoft 365 Certified: Messaging Administrator Associate (MS-203 legacy)
      • CompTIA Security+ or another DoD 8140-qualifying certification
      • CCNA, Network+, or equivalent networking certification
      • CISSP
      • GIAC Certifications
      • ITIL Foundation

Skills Required

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field
  • Seven or more years administering Active Directory in enterprise environments, including multi-domain or multi-forest architectures
  • Five or more years administering Exchange Server, including hands-on experience with at least one Exchange hybrid deployment
  • Three or more years supporting Microsoft 365, Microsoft Entra ID, and Exchange Online
  • Existing Top Secret and/or DOE Q clearance
  • Senior-level experience supporting federal government customers onsite
  • Knowledge of TCP/IP, routing, subnetting, NAT, VLANs, firewalls, DNS, PKI, certificates, SMTP, Kerberos, and LDAP
  • Ability to diagnose authentication, directory synchronization, and mail flow failures using packet capture, port testing, and log analysis
  • PowerShell scripting and automation experience
  • Microsoft 365 administration experience
  • Identity and Access Management experience
  • Certificate Services, ADFS, and Windows Server administration experience
  • Experience with Active Directory, GPO, Hyper-V or VMware, DHCP, DNS, and NPS
  • Experience with DISA STIGs, vulnerability scanners, ACAS or Nessus, and security compliance
  • Experience supporting enterprise environments with 5,000 or more users
  • Experience implementing Exchange hybrid environments
  • Experience with Microsoft Defender, Microsoft Purview, and Microsoft Sentinel
  • Experience with CyberArk, BeyondTrust, or other privileged access management solutions
  • Experience supporting Zero Trust initiatives
  • Experience administering Microsoft 365 in GCC, GCC High, or DoD tenants
  • Experience with PIV/CAC authentication, federal identity requirements, administrative forests, ESAE or Red Forest architectures, and cross-domain solutions
  • Familiarity with Active Directory consolidation, domain migrations, tenant-to-tenant migrations, Azure networking, and TIC 3.0
  • Microsoft SC-300, MS-102, MS-203, CompTIA Security+, CCNA, Network+, CISSP, GIAC, or ITIL certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Gaithersburg, MD
286 Employees
Year Founded: 1997

What We Do

Planet Technologies was built around investing in and developing long term relationships with our customers and corporate partners. We work hard to keep our staff trained on the latest technologies, policy and operational issues impacting today’s federal and corporate environments. Being an expert on the technology we support is the first step, more importantly is understanding your business mission and integrating technology into a long term strategic plan. Planet Technologies is the leading provider of Microsoft consulting services to public sector and commercial organizations. Our team of Microsoft experts provides support for Office 365, CRM, SharePoint, System Center, SQL, and Windows 7-10. Planet has significant experience in deploying business intelligence, cloud services, unified communications, records management, workflow automation, collaboration, systems management, virtualization and more. A Global Leader in Microsoft Technologies: Few companies can compare to Planet Technologies when it comes to an established relationship with Microsoft. As a company with a 100% focus on the Microsoft platform, we know Microsoft technologies and we are a trusted partner. As a team of experienced and certified Microsoft consultants and Microsoft trainers, we are the best partner to help your staff get up to speed quickly and cost effectively in order to make your business more productive with your Enterprise Agreement investment. Advanced certifications • Microsoft Partner with five gold and ten silver competencies • CPLS Microsoft certified training Highly skilled staff • Microsoft Certified Solutions Masters (MCSM) • Microsoft Most Valuable Professionals (MVP) • Microsoft Certified Trainers (MCT) • Microsoft CRM Rangers • 150+ Microsoft Consultants We are a full-service, independent training company providing a range of IT and developer training services based on Microsoft technologies to individuals and organizations.

Similar Jobs

In-Office or Remote
2 Locations
175633 Employees
85K-193K Annually

EchoStar Logo EchoStar

Senior Cloud Engineer

Aerospace • Cloud • Digital Media • Information Technology • Mobile • News + Entertainment • Generative AI
In-Office
Littleton, CO, USA
14500 Employees
96K-138K Annually

bet365 Logo bet365

Cloud Platform Engineer

Digital Media • Gaming • Software • Esports • Automation
Hybrid
Denver, CO, USA
10000 Employees
110K-150K Annually
In-Office
Colorado Springs, CO, USA
22677 Employees
94K-141K Annually

Similar Companies Hiring

Compa Thumbnail
Artificial Intelligence • HR Tech • Software • Business Intelligence
Irvine, California
75 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account