Role: Senior Azure DevSecOps Engineer - Compliance & Immutable Cloud PlatformLocation: Chicago, IL (Local Candidates Only)
Work Authorization: Genuine consultants only with a valid LinkedIn profile that matches the resume.
Experience: 12+ years of relevant experience in the required technologies.
Position OverviewWe are seeking a highly experienced
Senior Azure DevSecOps Engineer to design, build, and secure a cloud-native immutable evidencing platform on Microsoft Azure. This platform will ingest compliance artifacts, audit evidence, and control attestations from various enterprise systems via APIs, store them with cryptographic integrity guarantees, and provide secure querying and retrieval capabilities for Governance, Risk, and Compliance (GRC) and audit workflows.
The ideal candidate will have deep expertise in Azure cloud services, DevSecOps, Infrastructure as Code (Terraform), event-driven architectures, API Management, and cloud security, with experience supporting regulatory frameworks such as
PCI-DSS, SOX, and GLBA.
Required Education- Bachelor's degree in Computer Science, Information Management, Information Technology, or a related field.
Preferred Certifications (Nice to Have)- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Security - Specialty
- CISSP
- CCSP
Required Skills & Experience- 10+ years of experience designing and deploying enterprise-grade production workloads on Microsoft Azure using API-first and event-driven architectures.
- Strong hands-on experience with Azure API Management (APIM), including:
- Inbound/Outbound XML policies
- Backend configuration
- Named Values
- Versioning
- Developer Portal
- Experience implementing immutable or append-only storage solutions, including:
- Azure Blob Storage WORM (Write Once Read Many) policies
- Azure Cosmos DB Change Feed auditing
- Equivalent immutable storage architectures
- Hands-on experience deploying and managing Azure Cosmos DB and other NoSQL databases.
- Strong understanding of envelope encryption using Azure Key Vault, including:
- Customer Managed Keys (CMK)
- Key rotation
- Purge protection
- Experience designing secure Zero Trust Azure networking using:
- Private Endpoints
- Virtual Network (VNet) Integration
- NSGs
- UDRs
- Strong Terraform expertise, including:
- Modular infrastructure design
- Remote state management
- Azure Provider
- CI/CD integration using GitHub Actions or Azure DevOps
- Strong programming experience with Python and Node.js.
- Hands-on experience with automated and integrated testing frameworks/tools.
- Ability to develop Kusto Query Language (KQL) queries for:
- Operational monitoring
- Alerting
- Audit log analysis
- Experience integrating enterprise applications with third-party APIs, including:
- GRC platforms
- Vulnerability management tools
- Ticketing systems
- Other enterprise SaaS platforms
Key Responsibilities- Design and implement secure API ingestion pipelines using Azure API Management (APIM) with:
- OAuth2/JWT authentication
- Rate limiting
- Schema validation
- API security best practices
- Build scalable, event-driven ingestion workflows using:
- Azure Functions
- Durable Functions
- Azure Service Bus
- Fan-out/Fan-in processing patterns
- Develop immutable artifact storage solutions using:
- Azure Blob Storage with WORM retention policies
- Azure Cosmos DB for tamper-evident metadata indexing
- Architect and implement Azure Redis Cache for high-performance query caching while preserving immutable source-of-truth data.
- Implement secure envelope encryption using Azure Key Vault, including customer-managed keys and automated key rotation.
- Build and maintain monitoring and telemetry pipelines using Azure Log Analytics Workspace for:
- Ingestion monitoring
- Access auditing
- Integrity verification
- Operational visibility
- Develop and maintain Infrastructure as Code (IaC) using Terraform.
- Ensure all Azure resources are deployed through automation with Policy-as-Code and eliminate manual ("click-ops") deployments.
- Build integrations with third-party systems to securely ingest compliance evidence and audit artifacts via APIs.
- Design secure, scalable, and compliant cloud infrastructure aligned with PCI-DSS, SOX, and GLBA requirements.
- Collaborate with security, infrastructure, compliance, and development teams to deliver enterprise-grade cloud solutions.
Required Soft Skills- Excellent verbal and written communication skills.
- Strong analytical and problem-solving abilities.
- Ability to collaborate effectively with cross-functional technical and business teams.
- Self-driven with the ability to work independently in a fast-paced Agile environment.