Overview
Skills
Job Details
Job Title: Azure Security Architect
Location: Denver, CO (Hybrid/Onsite Preferred)
Independent candidates only
Job Description
We are seeking a highly skilled Azure Security Architect with a deep understanding of application security and cloud security best practices to lead the secure design and architecture of enterprise applications hosted on Azure.
Responsibilities
Architect Secure Azure Solutions: Design secure architectures for cloud-native applications, APIs, web, and mobile apps hosted in Azure.
Azure Security SME: Serve as the subject matter expert for Azure security across IaaS, PaaS, and SaaS environments.
Azure Networking Security: Implement and manage NSGs, ASGs, Azure Firewall, WAF (Azure Front Door/Application Gateway), Private Link, VPNs, and ExpressRoute.
Identity & Access Management: Configure and enforce AAD, MFA, Conditional Access, PIM, and Hybrid Identity integrations.
Data Protection: Implement encryption and key management using Azure Key Vault, Azure Disk Encryption, SQL DB Security, and storage encryption.
Security Services: Utilize Azure Defender for Cloud, Azure Sentinel, Azure Policy, Monitor, and DDoS Protection to ensure secure operations.
Application Security: Conduct threat modeling, SAST/DAST scans, code reviews, and vulnerability assessments.
Secure SDLC: Integrate security into DevOps pipelines (Azure DevOps) with automation tools and secure coding practices.
Policies & Standards: Define and enforce security standards aligned with OWASP, Microsoft Best Practices, CIS Benchmarks, etc.
Incident Response: Collaborate on incident investigations and provide remediation recommendations.
Advisory Role: Educate and consult with developers, operations teams, and leadership on secure design and cloud threats.
Tool Evaluation: Research and recommend Azure-native and third-party tools to improve cloud security posture.
Required Qualifications
Bachelor s degree in Computer Science, Information Security, or related field.
10+ years of experience in information security, with a focus on architecture and cloud security.
Proven expertise in Azure security services: Azure Defender for Cloud, Azure Sentinel, AAD, Key Vault, Network Security Groups, Azure Firewall, and WAF.
Experience with secure SDLC in an Azure DevOps environment.
Hands-on experience with Infrastructure as Code (ARM Templates, Terraform).
Familiarity with regulatory and compliance standards (NIST, ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS).
Strong communication skills, capable of translating complex security concepts for diverse audiences.
Strong analytical and troubleshooting capabilities.
Preferred Certifications
Microsoft Certified: Azure Security Engineer Associate
Microsoft Certified: Cybersecurity Architect Expert
CISSP, CCSP, or equivalent