Position Overview
We are seeking a highly experienced Azure Terraform Engineer to design, build, and maintain Azure Virtual Desktop (AVD) environments for a large-scale federal enterprise program. This individual will be responsible for writing advanced Terraform code modules for secure, repeatable, and compliant infrastructure deployments, while ensuring federal standards for performance, resilience, and cybersecurity are met. The role requires deep technical expertise, strong problem-solving skills, and the ability to lead infrastructure-as-code (IaC) automation across hybrid cloud environments.
Key Responsibilities
- Design, author, and maintain Terraform modules for AVD, networking, storage, identity, and security in federal enterprise Azure environments.
- Architect and implement Azure Virtual Desktop deployments (host pools, session hosts, FSLogix, scaling plans, image management, MSIX app attach, monitoring).
- Automate provisioning of AVD infrastructure (VMs, resource groups, VNets, load balancing, Azure AD/Entra integration, Intune configuration) through Terraform.
- Integrate Terraform workflows with Azure DevOps pipelines, Git repositories, and automated testing frameworks.
- Implement federal compliance and Zero Trust requirements (NIST 800-53, FedRAMP, FISMA, CISA baselines).
- Troubleshoot and resolve deployment failures, FSLogix profile issues, and Terraform state management problems.
- Provide technical documentation, system diagrams, and input into System Security Plans (SSPs) and ATO packages.
- Support enterprise migration projects moving on-premise VDI solutions to Azure Virtual Desktop.
- Mentor junior engineers in Terraform development and IaC best practices.
Key Focus Areas
- Compliance & Security Alignment: Ensure all Azure Terraform deployments meet NIST 800-53, FedRAMP, FISMA, and CISA cybersecurity baselines. Provide artifacts and technical input for SSPs and ATO processes.
- Zero Trust Integration: Implement identity, device, and workload protections in line with federal Zero Trust architecture, including conditional access, RBAC, and integration with Entra ID/Intune.
- Enterprise Scale Delivery: Engineer solutions that support tens of thousands of endpoints across multi-tenant, multi-institute, or multi-agency environments. Optimize FSLogix profiles, storage strategies, and scaling plans for federal workloads.
- Program & Stakeholder Engagement: Work directly with federal program managers, contracting officers, and agency technical leads to align solutions with mission needs and enterprise roadmaps.
- Change & Release Management: Support IT Service Management (ITSM) processes by integrating Terraform deployments with federal change control workflows and documentation standards.
- Cloud Modernization: Support large-scale cloud adoption projects, including hybrid Azure/on-premise environments, AVD migration, and integration with enterprise monitoring (Azure Monitor, Sentinel, Splunk, Tenable).
Required Qualifications
- U.S. Citizenship (required for federal programs).
- Active security clearance or ability to obtain [e.g., Public Trust / Secret].
- 7+ years of IT infrastructure/cloud engineering experience.
- 4+ years of hands-on Azure cloud engineering in enterprise-scale environments.
- 3+ years of direct experience with Azure Virtual Desktop design, implementation, and operations.
- Expert-level proficiency in Terraform coding (modules, state files, workspaces, registries, providers, advanced variable usage).
- Strong knowledge of Azure Resource Manager (ARM), Azure AD/Entra ID, RBAC, and Intune integration for AVD.
- Proficiency with scripting languages (PowerShell, Bash, or Python).
- Deep understanding of networking (VNets, ExpressRoute, NSGs, firewalls) and enterprise security controls.
Preferred Qualifications
- Prior experience delivering AVD or VDI modernization at NIH, HHS, NASA, or other large federal agencies.
- Expertise with FSLogix containers, storage optimization, and multi-session Windows 10/11.
- Knowledge of Azure Monitor, Log Analytics, Defender for Cloud, and Sentinel integration.
- Familiarity with configuration of MSIX app attach and dynamic scaling of AVD resources.
- Azure Certifications: AZ-305 (Solutions Architect), AZ-140 (Azure Virtual Desktop Specialty), AZ-400 (DevOps Engineer), Terraform Associate (003).
Job Type: Full-time
Pay: $120,492.52 - $145,109.27 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Work Location: Hybrid remote in Columbia, MD 21046