Logo for NES Associates, LLC

Cloud Hosting SME

Roles & Responsibilities

  • 10+ years of cloud/platform engineering or cloud architecture with hands-on delivery at enterprise scale
  • At least 3 years leading hybrid/multi-cloud (AWS/Azure) in regulated or federal environments
  • Experience aligning to NIST SP 800-53/RMF, Zero Trust/TIC 3.0, FedRAMP services, and ATO sustainment
  • Proven delivery of container platforms (Kubernetes/OpenShift) and platform services (databases, messaging, caches) with DR/RTO/RPO objectives

Requirements:

  • Design, build, and operate secure, reliable, and cost-effective hybrid/multi-cloud platforms for mission systems
  • Own enterprise design patterns, landing zones, identity and network baselines, observability, automation, and disaster recovery to enable quick and safe deployments across AWS, Azure, and on-prem environments
  • Codify landing zones and guardrails as reusable templates to reduce environment build times and prevent configuration drift
  • Lead the product lifecycle for hosting platforms that meet federal standards (NIST, RMF, TIC 3.0, Zero Trust) and achieve ATO sustainment

Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

MBI (T2)

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Cloud Architectures, Cloud Based Services, Cloud Hosting, Cloud Platform, Security Compliance

Certifications:

None

Experience:

10 + years of related experience

US Citizenship Required:

No

Job Description:

The Cloud Hosting SME is the technical lead for designing, building, and operating secure, reliable, and cost-effective hybrid/multi-cloud platforms for mission systems. You will own the enterprise design patterns, landing zones, identity and network baselines, observability, automation, and disaster recovery that let teams deploy quickly and safely across AWS, Azure, and on-prem environments. You’ll partner with the engineering and delivery teams on a clear service catalog, and with finance on unit economics and optimization, while leading the product life cycle for hosting platforms that meet federal standards (NIST, RMF, TIC 3.0, Zero Trust) and ATO sustainment.

HOW A CLOUD HOSTING SME WILL MAKE AN IMPACT:

You will turn current hosting platforms from a collection of projects into a standardized, auditable platform that accelerates delivery and reduces risk. By codifying landing zones and guardrails as reusable templates, you’ll cut environment build times from weeks to minutes and prevent configuration drift. Your identity-centric designs and policy-as-code controls will raise security without slowing teams down, while SRE practices and progressive delivery will reduce incidents and shorten time to restore. You’ll right-size capacity, apply commitments effectively, and tier storage so cost per unit trends down even as usage grows. The result is visible to executives and end users alike: faster launches, higher availability, cleaner audits, and predictable spend.

WHAT YOU’LL NEED TO SUCCEED:

  • Education: Bachelor's Degree. In lieu of a degree, an additional four years of related experience required

  • 10+ years in cloud/platform engineering or cloud architecture with hands-on delivery at enterprise scale; at least 3 years leading hybrid/multi-cloud (AWS/Azure) in regulated or federal environments.

  • Demonstrated ownership of secure landing zones, network/identity patterns, and CI/CD/IaC pipelines; track record reducing MTTR, change failure rate, and cost per unit.

  • Experience aligning to NIST SP 800-53/RMF, Zero Trust/TIC 3.0, FedRAMP services, and ATO sustainment, evidence of successful audits or compliance assessments.

  • Proven delivery of container platforms (Kubernetes/OpenShift) and platform services (databases, messaging, caches) with DR/RTO/RPO objectives.

  • Leadership in multi-vendor/SIAM settings with shared KPIs, cross-domain change coordination, and incident “swarming”.

  • Security clearance level: Public Trust

  • Location: Austin, TX – Hybrid Remote with periodic on-site meetings as required by the customer

  • Timeline: This is a contingent posting, expected to start in August 2026

TECHNICAL SKILLS:

  • Cloud Platforms: Deep expertise in AWS and Azure (GCP, OCI a plus): Organizations/Entra ID/IAM, Control Tower/Landing Zone, Transit Gateway/vWAN, PrivateLink/Private Endpoints, Key Management, security and monitoring services.

  • Networking & Identity: VPC/VNet design, hub-and-spoke, SD-WAN integration, DNS, NAT, firewalling, service mesh, SSO (SAML/OIDC), PIV/FIDO2, JIT/PIM/PAM.

  • Automation & Delivery: Terraform, CloudFormation/Bicep, Ansible, Packer, Helm; GitOps (Argo CD/Flux); policy-as-code (OPA/Conftest/Cloud Custodian); progressive delivery (blue/green, canary).

  • Containers & Platform Engineering: Kubernetes/OpenShift operations, cluster lifecycle, admission control, image signing/provenance, supply-chain security (SBOM, attestations).

  • Observability & SRE: OpenTelemetry (traces/metrics/logs), Prometheus/Grafana, log analytics/SIEM; SLOs/error budgets; synthetic and RUM monitoring.

  • Data & Storage: Managed databases (e.g., RDS/Aurora, SQL MI, Cosmos/Spanner), backup/restore with immutability/object lock, cross-region replication, tiering and lifecycle management.

  • Security & Compliance: Baseline hardening (CIS/STIGs), vulnerability/patch orchestration, encryption in transit/at rest, secrets management (Vault/KMS), least-privilege patterns; evidence generation for RMF ConMon.

  • Cost & Performance: FinOps fundamentals - commitment management (RIs/SPs/CCAs/Committed Use), autoscaling/scale-to-zero, right-sizing, storage tiering; performance tuning at app/network/data layers.

SKILLS AND ABILITIES:

  • Clear Communication: Converts complex architecture into simple narratives and diagrams for executives, engineers, and non-technical stakeholders; writes crisp runbooks and design docs.

  • Outcome Focus: Designs to measurable targets (availability, MTTR, time-to-provision, control pass rate, cost per unit) and publishes trends transparently.

  • Collaboration & Leadership: Guides cross-functional teams (security, networking, databases, app teams, vendors); mentors engineers; facilitate decisions and resolves blockers quickly.

  • Customer Orientation: Partners with stakeholders to make cloud services easy to request and adopt; builds self-service with safe defaults to reduce tickets and cycle time.

  • Discipline & Execution: Coordinates release trains and maintenance windows; enforces change control with automation first; drives continuous improvement backlogs to closure.

  • Adaptability: Stays current on emerging tech and pilots what measurably improves reliability, security, or cost.

PREFERRED CERTIFICATIONS:

  • AWS Solutions Architect – Professional

  • Microsoft Azure Solutions Architect Expert

  • VMware Certified Professional / Advanced Professional

  • CKA/CKAD or OpenShift Administrator

  • HashiCorp Terraform Associate / Authoring and Operations Professional

GDIT IS YOUR PLACE:

  • Full-flex work week to own your priorities at work and at home

  • 401K with company match

  • Comprehensive health and wellness packages

  • Internal mobility team dedicated to helping you build your skills and own your career

  • Professional growth opportunities including paid education and certifications

  • Cutting-edge technology you can learn from

  • Rest and recharge with paid vacation and 10 company-paid holidays

The likely salary range for this position is $165,750 - $224,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Hybrid

Work Location:

USA TX Home Office (TXHOME)

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Related jobs

Other jobs at NES Associates, LLC

We help you get seen. Not ignored.

We help you get seen faster — by the right people.

🚀

Auto-Apply

We apply for you — automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.