Senior Infrastructure Engineer (Azure)
Summary
Senior Infrastructure Engineer at Nava PBC, a govtech consultancy, building and administering a secure Azure production platform for government clients. Day to day: designing landing zones, identity/access (Entra ID, RBAC, PIM), networking, and infrastructure-as-code with Terraform, Bicep, and GitOps in a client-facing role.
About Nava
Final title/compensation will be determined by how your interview weighs against our core competencies during your interview cycle.
Position summary
The Senior Infrastructure Engineer is responsible for managing various systems and platforms using tools such as Visual Studio Code, Azure DevOps, Terraform, and GitOps. This role is focused on support, administration, maintenance, of a planned production platform supporting multiple systems that will leverage the platform.
The Senior Infrastructure Engineer works on a small team to assist our clients in becoming leading agencies in leveraging modern cloud technology. These responsibilities support Nava’s culture and mission: Be Active Stewards, Pursue the Root Cause, Think Long-Term, Build Together, Inclusion is Essential and Progress Takes Work.
What you'll do
- Establish and manage a code-first platform, automated provisioning, configuration, and lifecycle management of infrastructure and platforms.
- Assess and/or build the existing Azure environment, infrastructure dependencies, and modernization requirements to inform the target architecture
- Act as a trusted advisor or a key personnel, in a client-facing role, responsible for driving and executing decisions on architecture design and build for IT infrastructure and platforms in partnership with the client.
- Design the Azure tenant structure, including management groups, subscriptions, landing zones, networking, and resource organization
- Define cloud architecture standards, naming conventions, tagging strategies,etc. and document them in architecture decision records (ADRs)
- Advise on identity and access management, including Entra ID, RBAC, PIM, Conditional Access, and least-privilege access models
- Develop secure networking and connectivity patterns between Azure, on-premises systems, federal partners, and external integrations
- Adhere to and/or Define Infrastructure-as-Code standards, reusable modules, repository structure, and CI/CD workflows for development teams
- Produce architecture documentation, operational guidance, governance artifacts, and platform runbooks to support long-term maintainability
Required skills
- Proven experience as Azure Cloud expert, including Azure Landing Zones, Management Groups, and subscription design, for large-scale government or regulated environments
- Experience supporting enterprise-scale infrastructure platforms in an enterprise environment
- Experience implementing Infrastructure as Code (IaC) using Azure Bicep, ARM templates, Terraform, CI/CD automation and GitOps.
- Must have experience scripting with tools such as Python, Powershell, Bash
- Experience designing identity and access management solutions using Microsoft Entra ID, Role-Based Access Control (RBAC), Privileged Identity Management (PIM), and Conditional Access
- Knowledge of cloud security, governance, and compliance frameworks, including HIPAA, NIST, Azure Policy, Microsoft Defender for Cloud, and Authorization to Operate (ATO) processes
- Experience supporting the Authorization to Operate (ATO) processes is desired
- Experience establishing cloud governance standards, including resource organization, naming conventions, tagging strategies, policy guardrails, and cost management practices
- Proficient with DevSecOps practices, automated deployment pipelines, infrastructure monitoring, and operational observability, including SIEM integration.
- Experience developing architecture documentation, Architecture Decision Records (ADRs), technical standards, and operational runbooks
- Experience collaborating with government stakeholders, infrastructure teams, security teams, and multiple vendors to define cloud architecture and implementation strategies
- Experience in designing highly available platforms and build the desired Disaster recovery posture
- Experience working in an agile delivery team
- Strong technical leadership and communication skills, with experience coaching and mentoring other engineers
- Ability and desire to grow Nava’s Azure community of practice by driving organization-level standards and growth
Other requirements
Perks working with Nava
Location
Stay in touch
Equal Employment Opportunity
As published by greenhouse · 21 questions · 3 written answers
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (5)
- Preferred First Name optional
- LinkedIn Profile:
- How did you hear about us? (Previous or Current Employee, LinkedIn, Conference, Job board, etc) optional
- Were you referred to Nava? If so, please provide their name below. optional
- What is your targeted salary compensation based on this posting?
Pick from a list (13)
- Are you legally authorized to work in the United States?
- Will you now, or in the future, require any type of sponsorship for employment Visa Status (e.g., H-1B)?
- What is your highest level of education completed?
- Do you live in one of our approved remote work states? Alabama, Arizona, California, Colorado, Delaware, DC, Florida, Georgia, Illinois, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, North Carolina, New Jersey, New York, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Tennessee, Utah, Virginia, Washington, Wisconsin
- What state will you be working in? optional
- Please note: This role requires you to work from the contiguous United States.
- In the last 5 years, how many have you lived in the Continental United States? (Must be at least 3 out of the last 5 years)
- What past or current government experience? optional
- Have you previously been employed by the U.S. Federal government (including as a civilian, military service member, contractor, or in any other official capacity)? optional
- If you answered “Yes”, please note that you will be required to provide a post Employment Government Ethics opinion letter prior to hire. If you have the letter, please attach to your application. optional
- Do you have any active non-competes or restrictive covenants that may hinder us from hiring you? optional
- Are you currently subject to any federal or regulatory cooling-off periods that would restrict your ability to engage in this role? optional
- Some of Nava’s projects may require an “On Call” rotation. Are you comfortable participating in an on-call rotation if required by the needs of the project? (Please note: a “No” answer will not disqualify you from consideration.) optional
Written answers (3)
- If you answered yes to any of the above, please specify what agencies you have worked for previously: optional
- If the above answer is “yes”, could you provide details on the duration and scope of any such restrictions? optional
- Additional Information Add a cover letter or anything else you want to share optional