Two Five Solutions is hiring a Microsoft Cloud Engineer to build and support Microsoft 365 and Azure environments — both GCC High and commercial — for our defense industrial base and regulated commercial clients. You'll stand up new tenants, run migrations, and serve as Tier 2/3 escalation across our client base, working out of our Washington, DC office. This role requires 5+ years of hands-on Microsoft 365 and Azure experience; GCC High, NIST/CMMC exposure, and Microsoft certifications are a plus. It's a chance to build depth in both commercial and government cloud — a combination the market underprices — at a firm small enough that your work is visible.
The role
Two Five Solutions runs managed IT, managed security, and CMMC 2.0 compliance programs for defense industrial base contractors and regulated commercial firms. Our client environments span Microsoft GCC High, Azure Government, and commercial Microsoft 365 and Azure — and we build them, migrate into them, and operate them end to end.
We need an engineer who can do both halves of that: stand up new environments — GCC High and commercial tenants, Azure landing zones, identity and endpoint baselines — and carry Tier 2/3 support across the client base once they're live. You will be a senior technical resource on the delivery team, working escalations the service desk can't close and running buildout projects with real delivery dates.
This is not a Tier 1 helpdesk role. Ticket intake and first response stay with our service desk; you take what escalates and you build what's new.
What you'll own
Environment buildouts and migrations (~40%). New Microsoft 365 tenants in GCC High and Commercial, Azure and Azure Government landing zones, Entra ID and Intune baselines, tenant-to-tenant migrations, and the integration of acquired companies' users, devices, and data. These are scoped, billable projects — you own the delivery.
Tier 2/3 support across the client base (~40%). Escalations from the service desk across Microsoft 365, Entra ID, Intune, Exchange Online, Defender, and Azure infrastructure — in both GCC High and commercial tenants. You diagnose, resolve, and document so the same issue doesn't escalate twice.
Standards and hardening (~10%). Keep client tenants aligned to our configuration baselines — Conditional Access, device compliance, endpoint hardening — and flag drift before it becomes a finding or an incident.
Runbooks and documentation (~10%). Every environment you build gets a runbook. Every escalation pattern you resolve gets a knowledge-base article the analyst tier can use.
What you need
• 5+ years of hands-on Microsoft work — administering and engineering Microsoft 365 and Azure in a managed services, systems engineering, or internal IT role. This is the requirement; everything below describes what that experience should look like.
• Tenant buildout experience: you have stood up Microsoft 365 tenants and Azure environments from nothing, not just administered ones someone else built
• Entra ID: Conditional Access, MFA design, identity lifecycle, hybrid identity with Entra Connect
• Intune and Autopilot: device enrollment, configuration profiles, compliance policies, application deployment
• Exchange Online and Teams administration, including migrations
• Azure infrastructure: subscriptions, RBAC, virtual networks, VPN connectivity, and enough PowerShell or Graph API fluency to script what you'd otherwise click through twice
• Comfortable working escalations across multiple client environments in the same day — context-switching is the job, not an interruption to it
• Clear written communication. You'll write for clients, for teammates who inherit your work, and occasionally for assessors.
Helpful, not required
• Microsoft GCC High or Azure Government experience, including working knowledge of where GCC High diverges from Commercial in features, licensing, and external collaboration
• NIST SP 800-171 or CMMC exposure — implementing controls, supporting an assessment, or working POA&M findings to closure
• Microsoft certifications: AZ-104, MS-102, SC-300, AZ-500, MD-102, or similar
• Defender suite and Microsoft Sentinel administration
• Cisco Meraki: MX firewall policy, VLAN segmentation, wireless
• Prior work at an MSP or MSSP
First 90 days
By day 30, you're taking Tier 2/3 escalations independently across at least three client environments. By day 60, you're running a buildout or migration workstream with support from the Technical Lead. By day 90, you own environment delivery end to end — scoping input, execution, documentation, handoff to support.
Why this is worth your time
You'll work in both worlds — commercial cloud where the platform moves fast, and government cloud where the constraints make the expertise scarce. Most engineers get one or the other; here you build depth in both, and the GCC High side compounds into a skill set the market underprices right now.
We are also automating the parts of managed services delivery that should never have been manual. If you have opinions about what should be a script instead of a ticket, you'll be listened to.