Azure DevOps Audit for a Live SaaS Platform - Security & Reliability
Worldwide
We have an established SaaS application running in Microsoft Azure and are looking for an experienced individual engineer to review the environment as it exists today. The platform is already in production, so this is not a migration or rebuild. The goal is to find specific reliability, security, monitoring, deployment, backup, and operational gaps, then separate what needs attention now from what can reasonably wait. You’ll work directly with our current DevOps engineer, and we’ll provide the existing architecture documentation along with appropriate read-only Azure access. The initial engagement will be a fixed-price infrastructure and DevOps audit. You’ll start by mapping the production and staging resources, application dependencies, network entry points, and current deployment path. The review should cover Azure networking and public exposure, Entra ID and RBAC permissions, administrator and service accounts, Key Vault and secret handling, Azure Monitor, Application Insights, Log Analytics, alert configuration, and Defender for Cloud where those services are being used. We need more than a configuration inventory. We want to confirm whether logs from critical services are collected and retained, whether alerts cover real application and infrastructure failures, whether access is limited appropriately, and whether important resources have avoidable single points of failure. The CI/CD review should follow a change from source control through staging and production, checking approvals, environment separation, credential handling, failed-deployment detection, and rollback procedures. The backup review should confirm what is protected, how long backups are retained, whether failures are reported, when recovery was last tested, and whether the current recovery process is realistic. SOC 2 and CJIS readiness are also part of the longer-term direction. Relevant experience should include practical work around least-privilege access, MFA, audit logging, change records, vulnerability remediation, incident response, backup and disaster-recovery evidence, and ongoing access reviews. We need someone who understands which gaps require Azure configuration changes and which require policies, operating procedures, documentation, or coordination with an outside assessor. The audit deliverable should be a concise written report describing the current strengths, confirmed gaps, affected Azure areas, business or production risk, recommended correction, and priority. It should cover production reliability, monitoring and alerting, backup and recovery, CI/CD, networking, access control, security hardening, and any unnecessary cost or complexity. Recommendations should be grouped into critical, near-term, and later improvements so the report can be turned into a practical work plan. If the audit goes well, there may be ongoing work involving production support, incident troubleshooting, deployments, monitoring improvements, security remediation, recovery testing, and compliance preparation. The engineer must already work on a U.S. schedule and be able to collaborate with the current team in real time. Before starting the full audit, shortlisted candidates will complete a small paid technical test using limited or sanitized project information. This is simply to confirm technical fit and communication style before either side commits to the larger engagement. Please keep your proposal specific. Instead of general statements such as “I can do this,” include links to one or two live SaaS products or similar Azure projects you personally built or supported. Explain your exact role, which Azure and DevOps areas you owned, and what you were responsible for in production. Please also describe one real outage or infrastructure problem you personally diagnosed and resolved, along with any direct SOC 2 or CJIS preparation work. We are hiring an individual engineer and will work directly with that person, so agencies and outsourced teams are not a fit. This is also not intended as an opportunity to learn Azure or compliance while completing the assignment. AI tools are fine as assistants, but the audit cannot be driven primarily by ChatGPT or Claude; findings and recommendations must come from your own experience and be independently verified.
- More than 30 hrs/weekHourly
- 6+ monthsDuration
- ExpertExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:last week
- Hires:1
- Interviewing:2
- Invites sent:10
- Unanswered invites:7
About the client
- United StatesWashington Township10:37 PM
- $962 total spent16 hires, 8 active
- 37 hours
- Health & FitnessMid-sized company (10-99 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by