Role: Senior DevSecOps Engineer (Azure) - Compliance & Immutable Cloud Platform
Location: Chicago, IL
Must-Have Skills
· 5+ years building production workloads on Azure with event-driven and API-first architectures
· Strong APIM experience: policies (inbound/outbound XML), backends, named values, developer portal, versioning
· Experience implementing immutable/append-only storage patterns (WORM blob policies, Cosmos DB change feed auditing, or equivalent)
· Deploy and manage NoSQL and CosmosDB databases
· Familiarity with envelope encryption patterns using Key Vault (CMK, key rotation, purge protection)
· Understanding of zero-trust network design: Private Endpoints, VNet integration, NSG/UDR patterns
· Solid Terraform skills: modules, remote state, Azure Provider, CI/CD integration via GitHub Actions or Azure DevOps
· Strong coding experience in Python and Node.js
· Hands-on proficiency with integrated testing tools
· Ability to write KQL for operational queries, alerting rules, and audit log analysis
· Experience integrating with third-party tool APIs (GRC platforms, vulnerability scanners, ticketing systems, or similar)
· Effective written and verbal communication skills to collaborate with cross-functional teams
· 5+ years architecting and building high-compliance, event-driven production platforms on Azure, with a proven track record of implementing immutable, append-only storage patterns in a regulated environment (e.g., PCI-DSS, SOX, GLBA)
Nice-to-Have Skills
· Azure Security Engineer Associate
· AWS Certified Security – Specialty
· CISSP
· CCSP
· Degree in Computer Science, Information Management, or related field
Description
· We are building a next-generation, cloud-native platform to store and manage compliance evidence.
· This system will ingest data from various internal tools via secure APIs, store it with cryptographic integrity guarantees, and make it available for auditing and GRC workflows.
· We''re looking for a Senior DevSecOps Engineer to lead the design, development, and hardening of this critical platform on Microsoft Azure.
· What You''ll Do Design and build secure API ingestion pipelines using Azure API Management (APIM) with OAuth2/JWT validation and rate limiting.
· Develop event-driven ingestion workflows using Azure Service Bus and Durable Azure Functions.
· Implement an immutable, tamper-evident storage solution using Azure Blob Storage (WORM policies) and Azure Cosmos DB.
· Architect high-performance query caching using Redis Cache, while maintaining source-of-truth immutability.
· Integrate Azure Key Vault for envelope encryption of stored artifacts, including managing customer-managed keys (CMK).
· Build comprehensive Log Analytics Workspace pipelines to track ingestion events, access audits, and integrity checks.
· Write all infrastructure as code using Terraform, ensuring a policy-as-code compliant environment.
· Integrate with third-party tools (e.g., GRC platforms, vulnerability scanners) to build a seamless ingestion process.
Key Responsibilities:
• Design and implement API ingestion pipelines via Azure API Management (APIM) with OAuth2/JWT validation, rate limiting, and schema enforcement.
• Build event-driven ingestion workflows using Azure Service Bus and Azure Functions (durable, fan-out patterns).
• Implement immutable artifact storage using Azure Blob Storage with WORM policies (time-based retention locks) and Azure Cosmos DB for tamper-evident metadata indexing.
• Architect Redis Cache for high-throughput query caching while preserving source-of-truth immutability guarantees.
• Integrate Azure Key Vault for envelope encryption of stored artifacts (customer-managed keys, automated rotation).
• Build Log Analytics Workspace telemetry pipelines covering ingestion events, access audit trails, and integrity verification logs.
• Write Terraform IaC for all infrastructure — no click-ops; all resources policy-as-code compliant.
• Implement third-party tool integrations (connector APIs) to ingest evidence artifacts from source systems.