Lead Azure Architecture SME
GDIT · USA DC Washington · Posted 2026-09-03
Job description
Type of Requisition: Regular Clearance Level Must Currently Possess: Secret Clearance Level Must Be Able to Obtain: Secret Public Trust/Other Required: None Job Family: Software Engineering Job Qualifications: Skills: Active Directory (AD), Azure Devops, Azure Monitor, Cloud Infrastructure, Cloud Networking Certifications: None Experience: 10 + years of related experience US Citizenship Required: Yes Job Description: The Azure Architecture SME – Lead is responsible for architecting, designing, and guiding the implementation of secure, scalable, and high-performing Azure cloud solutions. This role provides technical leadership, problem-solving expertise, and hands-on support across networking, identity, infrastructure automation, and cloud-to-on-prem integrations. The SME will develop architect diagrams, lead complex migrations using Azure Site Recovery, deliver technical presentations to government customers, and design and drive implementation of Entra architecture for enterprise environments. MAJOR RESPONSIBILITIES: • Lead the design of end-to-end Azure architecture, producing detailed architect diagrams utilizing VISIO and technical documentation. • Lead technical presentations, architectural discussions, and solution deep dives with government customers and stakeholders. • Lead and conduct the migration planning and execution using Azure Site Recovery, overseeing dependency mapping, failover testing, and cutover operations. • Manage and optimize replication traffic over ExpressRoute/VPN; design and isolate VNETs for test and validation to support migration readiness. • Serve as the point of contact for all Azure networking issues, leading problem-solving efforts, guiding architecture decisions, and advising leadership on technical direction. • Ensure secure and reliable connectivity between cloud and on-prem environments while maintaining optimal performance, resiliency, and availability. • Lead, design, implement, and manage Azure networking components including virtual networks, subnets, NSGs, Azure Firewall, VPN/ExpressRoute, load balancers, and routing topologies. • Lead security hardening and protection of infrastructure across cloud and on-prem environments while supporting system and workload migrations. • Design and lead implementation of Microsoft Entra architecture, including identity governance, conditional access, role management, and cross-tenant integrations. • Build and manage Azure infrastructure using DevOps practices and Infrastructure-as-Code (IaC) tools such as Terraform, Bicep, ARM templates, Azure DevOps, and GitHub Actions. • Mentor and collaborate with System Administrators on account administration, VM configuration, monitoring implementation, patch management, and operational support. • Oversee all system changes and ensure compliance with DISA STIGs, hardening guidelines, and relevant organizational controls for each VM or server. QUALIFICATIONS: Education: • Bachelor’s degree or higher in Systems Engineering, Computer Science, Information Technology, or a closely related technical field. Experience: • 10+ years of related experience required, with at least 5+ years of preferred experience in database and data management. • 5+ years Azure IL5/IL6 environments Required Certification(s): • CompTia Security+ is required to satisfy DoD 8570.01M requirements for IAT Level II • Other work-dependent certifications a plus Required Skills: • Experience with design and development of network solutions in an Azure IL5 and IL6 environment • Experience using Microsoft Entra ID and Microsoft Entra Monitor • Extensive knowledge of Azure Network Design and establishing Entra architecture • Strong Azure networking skills: VNets, NSGs, routing, Azure Firewall, load balancing, and ExpressRoute/VPN • Understanding of CI/CD concepts and secure pipeline development in controlled cloud environments • Advanced knowledge using Ansible or PowerShell scripts Desired Qualifications: Experience with two or more of the areas outlined below is preferred but not required: • Experience with Azure Migration solutions • Experience with Cloud based Database systems • Experience using MS Visio for updating diagrams • Experience working in Agile/Scrum environments • Experience working in Federal or State government environments CLEARANCE REQUIREMENTS: • Must possess active Secret or higher clearance and maintain as a condition of employment • US Citizenship required LOCATION: Hybrid in Washington, D.C.; on-site work at least three days a week at customer location will be required GDIT IS YOUR PLACEAt GDIT, the mission is our purpose, and our people are at the center of everything we do.Growth: AI-powered career tool that identifies career steps and learning opportunitiesSupport: An internal mobility team focused on helping you achieve your career goalsRewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time offCommunity: Award-winning culture of innovation and a military-friendly workplaceOWN YOUR OPPORTUNITYExplore a career in software development at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your dedication to advancing innovation.#TechModernization The likely salary range for this position is $170,000 - $230,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Hybrid Work Location: USA DC Washington Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/