Senior Azure Cloud Security Engineer, 40 hrs/wk, 13 Weeks, Immediate Start
Only freelancers located in the U.S. may apply.U.S. located freelancers only
We are staffing a senior Azure security engineer onto a 13-week implementation engagement with a large enterprise client. This is hands-on build work, not assessment or strategy. You will be writing policy, wiring federation, and shipping infrastructure-as-code alongside the client's own engineering teams. Start date is August 17, 2026. Please only apply if you can commit to that date and to 40 hours per week through mid-November. WHAT YOU WILL BE DOING: Credential elimination. You will inventory service principals, client secrets, and long-lived credentials across the Azure estate, then retire them. That means standing up workload identity federation and OIDC trust patterns for CI/CD and Kubernetes workloads, migrating applications onto managed identities in partnership with the teams that own them, and putting preventive controls in place so that net-new static secrets cannot be created after you leave. Blast radius reduction. Private Endpoint and Private Link architecture for data-plane services, network access rules on storage and Key Vault and other PaaS, Azure Policy enforced at the management group scope, and RBAC tightening with custom roles where the built-ins are too permissive. The goal is that a compromised identity or workload cannot reach data it has no business reaching, regardless of what a role assignment says. Audit logging and exfiltration visibility. Diagnostic settings deployed at scale through policy rather than by hand, Entra ID sign-in and audit log routing, activity logs, AKS control plane and audit logging, and closing data-plane logging gaps on storage and other exfiltration-relevant services. You will work with the client detection team to confirm the telemetry actually supports their use cases. External attack surface. Discovery and inventory of internet-facing Azure resources, assessment of permissive NSG rules and unnecessary public IPs and exposed PaaS endpoints, then remediation execution. Everything you build gets documented as a reusable pattern. The client intends to adopt these organization-wide after the initial engagement, so the quality of your Terraform modules and runbooks matters as much as the controls themselves. WHAT WE NEED YOU TO HAVE Five or more years in cloud security engineering, with the majority of that time in Azure. Production depth in Entra ID, specifically managed identities, workload identity federation, app registrations and service principals, conditional access, and RBAC including custom role design. Azure Policy at enterprise scale. Management group hierarchy design, deny and deployIfNotExists effects, and remediation tasks. Azure network security for data protection. Private Link and Private Endpoints, NSGs, service endpoints, and the DNS design implications that come with each. Diagnostic settings, Log Analytics, and log delivery into a SIEM such as Sentinel or Splunk. Terraform or Bicep in production, not just in a lab. You will be writing modules that other people consume. A track record of driving security changes through engineering teams who did not ask for your controls, do not report to you, and have their own deadlines. This is the part most candidates underestimate. STRONG PLUSES AKS security depth including workload identity, network policy, audit logging, and admission control. GitHub Actions OIDC federation into Azure. PowerShell or Python automation against Microsoft Graph and Azure Resource Manager. Certifications such as AZ-500, SC-100, or SC-300, or equivalent demonstrated capability. Prior consulting or staff augmentation experience.
- More than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:50+
- Last viewed by client:last week
- Interviewing:0
- Invites sent:6
- Unanswered invites:6
About the client
- United StatesIowa City9:12 AM
- $15K total spent9 hires, 3 active
- 177 hours
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by