Senior Cloud Engineer, Azure Government (Remote USA, ET Preferred)
Quick Summary
Microsoft Sentinel integration and log routing, Defender for Cloud, hardened (STIG/CIS) node and container baselines, FIPS-mode configuration across Windows and Linux compute.
Sentinel, Defender for Cloud, Key Vault,

APPLICATION DEADLINE: This opportunity will be taken offline based on applicant volume. We encourage you to apply today if interested.
Who we are:
M-Files is redefining how work gets done. Our context-first document management system offers purpose-built business use cases—spanning universal and industry-specific workflows—to enable secure collaboration, automate processes, and ensure governance.
Unlike traditional systems, M-Files organizes content around the context of your business, connecting documents to related people, projects, and transactions. With our unique metadata-driven architecture, organizations can model content in line with their business processes, unify information across silos, and apply AI at scale. The result is greater productivity, reduced risk, and smarter, faster decisions for over 6,000 customers in 100+ countries.
To learn more about us we encourage you to visit http://www.m-files.com/careers .
Background
M-Files is building a FedRAMP-authorized edition of M-Files Cloud for U.S. federal agencies and the contractors that serve them, hosted in Microsoft Azure Government. The program is in its design phase with a specialist advisory partner, moves into environment build in late 2026, and targets authorization in 2027. You will join a small, senior founding team with direct ownership of a new product line.
You will be the founding infrastructure engineer for the M-Files federal offering and the technical lead for standing up its Azure Government environment. Working from a reference architecture produced with our advisory partner, you will build the environment as code, make it pass a FedRAMP 20x assessment, and then operate it. You own the technical relationship with the advisory partner's engineers during build, and you set the operating standards the rest of the operations team will follow.
Responsibilities
~1 min read- →Design and build the Azure Government environment for the federal offering
- →Author and own the infrastructure as code and the pipelines that deploy it; treat every environment change as a versioned, reviewed redeployment.
- →Implement the security architecture: Microsoft Sentinel integration and log routing, Defender for Cloud, hardened (STIG/CIS) node and container baselines, FIPS-mode configuration across Windows and Linux compute.
- →Stand up the customer-managed-key infrastructure with the product team
- →Build the machine-readable evidence pipeline that FedRAMP 20x requires
- →Work day-to-day with the advisory partner's engineers deploying endpoint security
- →Define the operating runbooks. Patching within federal timeframes, monthly authenticated scanning, backup and restore testing, break-glass access, and lead the on-call rotation as the team forms.
- →Answer for the environment in the third-party assessment: demonstrate controls live, produce evidence on request, remediate findings.
Requirements
~1 min read- 7+ years in cloud infrastructure or platform engineering, with at least 3 years hands-on in Azure at production scale; Azure Government experience strongly preferred.
- Deep Terraform experience and a conviction that infrastructure is code, reviewed and redeployed, never hand-edited.
- Production Kubernetes (AKS preferred), including Windows node pools and containerized .NET workloads.
- Working knowledge of Azure security services: Sentinel, Defender for Cloud, Key Vault, Azure Policy, Private Link, Entra ID and managed identities.
- Experience building or operating an environment under FedRAMP, DoD CC SRG, StateRAMP/GovRAMP, or an equivalent regulated framework (PCI, ISO 27001, SOC 2); familiarity with FIPS 140 and STIG hardening.
- Ability to explain a technical control to a non-engineer assessor clearly and without hedging.
Nice to Have
~1 min read- FedRAMP 20x or OSCAL/machine-readable compliance experience; Azure Security Engineer (AZ-500) or Azure Solutions Architect certification.
- Experience migrating a commercial SaaS into a sovereign or government cloud.
- Environment deployed from code in Azure Government against the signed-off reference architecture.
- Steady-state operations underway with documented runbooks and a functioning on-call rotation.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- October 1, 2026
- First seen
- October 1, 2026
- Last seen
- October 3, 2026
Posting Health
- Days active
- 1
- Repost count
- 0
- Trust Level
- 76%
- Scored at
- October 3, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.