Skip to content

Open nowPosted 16 hours ago

Cloud Administrator

Knox Systems15 open roles

Where
United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCloud AdministratorKnox Systems · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Knox Systems's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Knox Systems postings stay open a median of 45 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 16 hours ago

Knox Systems median: 45 days open

The posting

About Knox

Knox runs the largest Federal & DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

THE ROLE

Knox is seeking a Cloud Administrator which secures, builds, and operates multi-cloud infrastructure across AWS, Microsoft Azure, and Google Cloud Platform, including their government regions (AWS GovCloud (US), Azure Government, and Google Cloud Assured Workloads). The role manages identity and access, designs segmented and encrypted networks, and keeps systems hardened to DISA STIGs and CIS Benchmarks within FedRAMP, NIST SP 800-53 and SP 800-171, CMMC, and DoD Impact Level requirements up to IL5. Using scripting and Infrastructure as Code, the Cloud Administrator makes environments repeatable and changes reviewable, feeds cloud logs to the SIEM, and supports incident response. As the final escalation point for the help desk, this person troubleshoots complex cross-platform problems and maintains audit-ready documentation that supports continuous monitoring and POA&M evidence.

In addition to the cloud environment, this role supports Knox's on-premises employee infrastructure across multiple office sites, including employee workstations, local networks, printers, and conference room equipment. The administrator manages the office collaboration software that employees use every day, including email, calendars, file sharing, chat, and video meetings, and handles account setup, licensing, security settings, and user support. They keep workstations patched, hardened, and enrolled in endpoint management and protection tools at every site, and they resolve problems that reach them from the help desk.

KEY RESPONSIBILITIES

· Manages identity and access in AWS (Amazon Web Services) IAM (Identity and Access Management), Microsoft Entra ID for Azure, and GCP (Google Cloud Platform) IAM: single sign-on, multi-factor authentication, least privilege, privileged account control, and regular access reviews.

· Designs secure networks and manages encryption: segmentation with AWS and GCP Virtual Private Clouds and Azure Virtual Networks, private connections such as AWS Direct Connect and Azure ExpressRoute, boundary controls, and encryption keys in AWS KMS (Key Management Service), Azure Key Vault, and Google Cloud KMS using FIPS (Federal Information Processing Standards) 140 validated modules.

· Keeps systems at a known secure baseline: hardens to DISA STIGs (Defense Information Systems Agency Security Technical Implementation Guides) and CIS (Center for Internet Security) Benchmarks, catches drift with AWS Config, Azure Policy, and GCP Security Command Center, and patches by risk with evidence of what was fixed and what was accepted as an exception.

· Operates within FedRAMP (Federal Risk and Authorization Management Program), NIST (National Institute of Standards and Technology) SP 800-53 and SP 800-171, CMMC (Cybersecurity Maturity Model Certification), and the DoD (Department of Defense) Cloud Computing Security Requirements Guide Impact Levels, including IL5.

· Builds and runs infrastructure across all three providers, including the government regions: AWS GovCloud (US), Azure Government, and Google Cloud Assured Workloads.

· Automates with scripting (PowerShell, Bash, Python) and Infrastructure as Code tools such as Terraform, AWS CloudFormation, and Azure Bicep, so environments are repeatable and changes are reviewed.

· Sends logs from AWS CloudTrail, Azure Monitor, and GCP Cloud Logging to the SIEM (Security Information and Event Management) system, and supports security during incident response.

· Troubleshoots hard problems that cross systems and providers, works methodically under pressure, and serves as the final escalation point for the help desk.

· Keeps documentation that holds up in audits: System Security Plans, runbooks, diagrams, and change records that serve as continuous monitoring and POA&M (Plan of Action and Milestones) evidence.

· Supports Knox’s on premises employee infrastructure across multiple office sites, including employee workstations, local networks, printers, and conference room equipment.

· Manages the office collaboration software employees use every day, including email, calendars, file sharing, chat, and video meetings and handles account set-up, licensing, security settings, and user support.

· Keeps workstations at every site patched, hardened, and enrolled in endpoint management and protection tools.

· Resolves on-premises and collaboration issues escalated from the help desk. Troubleshoots hard problems that cross systems, providers and office sites. Works methodically under pressure, and serves as the final escalation point for the help desk.

QUALIFICATIONS

- 5+ years of hands-on experience administering cloud infrastructure, with production experience in at least two of AWS, Azure, and GCP and working knowledge of the third.

- Experience operating in government cloud environments such as AWS GovCloud (US), Azure Government, or Google Cloud Assured Workloads.

- Demonstrated expertise in cloud identity and access management (AWS IAM, Microsoft Entra ID, GCP IAM), including SSO, MFA, least privilege, privileged access controls, and access reviews.

- Experience designing and securing cloud networks (VPCs, VNets, segmentation, private connectivity like Direct Connect or ExpressRoute) and managing encryption keys with FIPS 140 validated services.

- Practical experience hardening systems to DISA STIGs and CIS Benchmarks and monitoring configuration drift with AWS Config, Azure Policy, or GCP Security Command Center.

- Working knowledge of FedRAMP, NIST SP 800-53, NIST SP 800-171, CMMC, and the DoD Cloud Computing SRG, including the requirements of IL5.

- Proficiency in scripting with PowerShell, Bash, and Python, and in Infrastructure as Code using Terraform, CloudFormation, or Bicep.

- Experience integrating cloud logging (CloudTrail, Azure Monitor, Cloud Logging) with a SIEM and supporting incident response activities.

- Strong troubleshooting skills across systems and providers, with the ability to work methodically under pressure as a senior escalation point.

- Ability to produce clear, audit-ready documentation, including System Security Plans, runbooks, network diagrams, and change records.

- DoD 8140 (formerly 8570) compliant baseline certification, such as CompTIA Security+ or equivalent.

- U.S. citizenship and an active Secret clearance, or the ability to obtain one.

Preferred Qualifications

- Cloud certifications such as AWS Certified Security – Specialty or SysOps Administrator, Microsoft Certified: Azure Administrator Associate (AZ-104) or Azure Security Engineer (AZ-500), and Google Professional Cloud Security Engineer.

- Advanced security certifications such as CISSP or CCSP.

- Experience supporting a FedRAMP authorization, CMMC assessment, or DoD ATO (Authority to Operate) from preparation through continuous monitoring.

- Experience with CI/CD pipelines and policy-as-code tools for automated compliance checks.

- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent experience.

Compensation Range: $95k-110k, variable annual bonus, and equity

Benefits & Perks

Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PTO, and an employee funded 401k plan. Please note, benefits are subject to change.

We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.

Knox is proud to support veteran hiring — we encourage veterans and transitioning service members to apply and welcome the unique skills and experience you bring.

Hiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Any offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Knox Systems's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Knox Systems's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Knox Systems's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.