Tech Stack
AnsibleAzureChefCloudCyber SecurityDNSFirewallsJavaScriptLinuxPythonTerraformVMware
About the role
- Develop, implement, and support related services and solutions for consulting clients
- Build a customer-focused relationship with clients to identify business challenges and develop specifications and requirements to arrive at the best solution
- Work as a member of the HBS Cloud Architecture Team (CAT) as a leader and contributor that provides consultative and proactive project support to Heartland Business Systems’ (HBS) account base
- Collaborate and be a leader across multiple internal teams to ensure successful delivery and timely execution of the scope of work
- Research new products for selection, enhance configuration standards and best practices, and educate team members on these products and services to enhance the sales process
- Provide senior-level support, maintenance, and administration for customer environments and review for other potential concerns or enhancement opportunities
- Assist with the development and implementation of the Azure cloud security architecture for protecting PHI/PII/PCI data deployed into various cloud, hybrid, HBS Cloud, and on-premises systems
- Implement and manage security architectures for cloud/hybrid systems
- Assess, develop, implement, optimize, and document a comprehensive set of security technologies and processes, data protection, cryptography, key management, identity, and access management (IAM) within SaaS, IaaS, PaaS, and other cloud environments
- Provide input to the development of career plans and education goals for engineers, including mentoring college Interns or recent college graduates
- Create and maintain detailed documentation of past projects to potentially provide time estimates and project scopes for new related projects
- Obtain and maintain current vendor/industry specific certifications and stay current on new products and solutions
- Maintain a positive team atmosphere between regional and virtual practices while maintaining a professional and respectful demeanor
- Minimum of 1,450 hours (billable + presales) per fiscal year prorated based on start date
Requirements
- 3+ years of experience in a technical-related field
- Designing and architecting Microsoft Cloud and Identity solutions – Including but not limited to: Entra ID (EID / Azure AD / AAD), Entra Connect, SAML SSO and OpenID Connect (OIDC), Conditional Access, Multi-Factor Authentication (MFA), Self-Service Password Reset (SSPR), Password Protection, Passwordless Authentication, Privileged Identity Management (PIM)
- Required Experience: 3+ years of experience in a technical-related field
- Preferred Experience: 3 - 5 years in a technical-related field
- 3+ years’ experience working as a consultant (preferred)
- Microsoft Azure Infrastructure experience: Virtual Machines and Azure Virtual Desktop (AVD), Networking and DNS, NSGs, VPN Gateways, Traffic Managers, Load Balancers, Private Link, ExpressRoute, Storage, Azure Backup, Azure Site Recovery, Azure Update Manager, Pricing & Cost Management, Azure Secure Score
- Designing and architecting systems-based solutions with a focus on the cloud: IaaS, PaaS, and SaaS
- Installing and supporting Microsoft enterprise products, including Active Directory (AD) Domain Services (ADDS)
- Comprehensive understanding of IP networking protocols, including DNS, static routing, TCP, UDP, and ICMP
- Configuring on-premises networking, especially firewalls (Palo Alto, Cisco, and/or Fortinet) and site-to-site IKE/IPSEC VPN connections with Azure environments
- Microsoft Intune and Defender for Endpoint / Server: Intune Endpoint Management, Endpoint Security, Application Management, Windows Autopilot, Defender for Endpoint (MDfE / MDATP), Defender for Servers, Attack Surface Reduction (ASR) rules, Secure Score
- Microsoft Security / Purview: Purview (Audit, Data Lifecycle Management / Retention Policies, eDiscovery, DLP, Information Protection (AIP)), Defender for Office 365, Defender for Identity, Defender for Cloud, Defender for Cloud Apps, Secure Score
- PowerShell, Python, or other scripting and development background
- Azure Sentinel, including Kusto Query Language (KQL)
- Public Key Infrastructure (PKI), including working with X.509 certificates and CSRs
- Orchestration and automation of cloud deployment (Bicep & ARM Templates, Terraform, Chef, Ansible, etc.)
- Developing and maintaining security architecture for PHI/PII/PCI data in various cloud, hybrid-cloud, HBS Cloud and on-premises systems
- Thycotic / Delinea Secret Server Cloud (SSC) – deployment and configuration
- Dynamic IP routing protocols, including BGP
- Familiarity or experience with Microsoft Exchange, Linux, Cisco (Hyperflex, Nexus, UCS), HPE Nimble, HPE ProLiant, Dell PowerEdge, VMware ESXi, Nutanix, Hyper-V, and Software Defined Networking (SDA, SD-WAN)
- Experience with Microsoft 365, including Exchange Online, SharePoint, OneDrive, Teams, ConnectWise and Hudu
- Bachelor’s Degree or equivalent (or relevant) certifications
- Must be able to successfully pass a background check per Criminal Justice Information Services (CJIS) requirements, including fingerprinting and criminal history review
- Expected to obtain and hold eight (8+) certifications (certification requirements and path included on professional development plan)
- Competencies: Accountability; Adaptability; Ambition; Applied Learning; Decision Making; Detail Orientated; Ethical; Interpersonal; Organized; Persistence; Technical Aptitude