Two Five Solutions LLC Cloud Security Architect (GCC High) Washington, DC · Full time Company website

Two Five Solutions is hiring a Cloud Security Architect to own the Microsoft GCC High and Azure Government environments we run for defense industrial base contractors — designing CUI boundaries, taking the escalations no one else can close, clearing POA&M findings against NIST SP 800-171 ahead of C3PAO assessments, and standing up new tenants and landing zones as clients are onboarded or acquired. This isn't a helpdesk role, a policy-writing role, or a whiteboard role: you translate controls into configurations and produce the evidence that proves it, which means you're in the console the same week you're in the design document. What matters most is real GCC High depth and 800-171 fluency at the control level — given a requirement, you can name the configuration that satisfies it, say what's missing, and write the implementation statement. You'd be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters.

About Two Five Solutions LLC

Two Five is a cybersecurity and automation solutions firm that helps organizations operate smarter, scale faster, and grow securely. We deliver expert solutions across Governance, Risk & Compliance (GRC), Managed Services, Strategic Consulting, and Innovation & Automation. By combining deep technical knowledge with business-first thinking, we empower our clients to reduce risk, streamline operations, and unlock the full potential of AI and automation. Whether you're building secure infrastructure, navigating compliance, or accelerating transformation, Two Five is your trusted partner for resilient growth.

Description

The role

Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors. Our clients operate in Microsoft GCC High and Azure Government, and the controls we operate on their behalf are assessed directly by C3PAOs during their CMMC Level 2 certification.

We need an architect who can own those environments outright. You will be the final technical authority across our DIB client base — the person who designs the CUI boundary, takes the escalations no one else can close, clears POA&M findings before assessment windows, and stands up or integrates new environments as clients are acquired or spun up.

This is not a Tier 1 helpdesk role and it is not a policy-writing role. Ticket volume stays with our service desk; you take what escalates. Policy and procedure authorship sits with our compliance practice; you translate controls into configurations and produce the evidence that proves it.

It is also not a whiteboard role. You will be in the console the same week you are in the design document. If you have not made a configuration change yourself in the last month, this is not the right seat.


What you'll own

Final technical authority across the DIB client base (~35%). Anything in GCC High, Intune, Entra ID, Defender, Sentinel, or Meraki that the service desk can't resolve lands with you. You are the last stop before the CISO, and your call on a design question is the firm's call.

POA&M remediation and control engineering (~30%). Work open findings against NIST SP 800-171 to closure across client environments — configuration changes, compensating controls, and the evidence artifact that demonstrates the fix. You'll be expected to defend that work in a C3PAO interview.

Environment buildouts and acquisition integrations (~25%). New GCC High tenants, Azure Government landing zones, Meraki networks, and the integration of acquired companies' users, devices, and data into an existing CUI boundary. These are scoped, billable projects with delivery dates.

Runbooks and documentation (~10%). Every environment you touch gets a runbook. Every control you configure gets an implementation statement someone else can read.


What you need

  • 5+ years administering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT engineering role
  • Hands-on Microsoft GCC High experience, including working knowledge of where GCC High diverges from Commercial in feature availability, licensing, tenant configuration, and external collaboration
  • Entra ID: Conditional Access policy design, Privileged Identity Management, identity lifecycle
  • Intune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment, Windows endpoint hardening against a recognized benchmark (CIS or DISA STIG)
  • Microsoft Defender suite and Microsoft Sentinel: data connectors, analytics rules, alert triage, and enough KQL to write a query rather than copy one
  • Azure infrastructure: subscriptions and management groups, Azure Policy, RBAC, virtual networks, network security groups, site-to-site VPN
  • Working fluency in NIST SP 800-171 at the control level. Given a specific requirement, you can name the configuration that satisfies it, identify what's missing, and write the implementation statement. This is the requirement that distinguishes candidates for us.
  • Clear written communication. You'll write for clients, for assessors, and for teammates who inherit your work.


Helpful, not required

  • Azure Government or Microsoft 365 DoD experience
  • Cisco Meraki: MX firewall policy, VLAN segmentation, wireless
  • Experience supporting or sitting for a CMMC Level 2 or DFARS 7012 assessment
  • GRC platform administration (Drata, Vanta, or similar) with an emphasis on evidence automation
  • Azure Arc, Defender for Cloud, backup and DR design in a Gov cloud region
  • AZ-500, SC-200, AZ-104, CCP, or CCA
  • Prior work at an MSP, MSSP, or defense contractor


First 90 days

By day 30, you're taking escalations independently across at least two client environments. By day 60, you own the open POA&M queue for one client and have closed findings with evidence attached. By day 90, you're leading a buildout or integration workstream end to end and your design decisions are shaping how we scope the next one.


Why this is worth your time

You'll be the second-most-senior technical person in a firm small enough that your work is visible and large enough that it matters. Our clients are building real defense capability and cannot bid without the compliance posture we help them hold. The environments are technically constrained in ways commercial cloud work isn't, which means the expertise you build here is scarce and it compounds.

We are also automating the parts of compliance delivery that should never have been manual. If you have opinions about what should be a script instead of a screenshot, you'll be listened to.