Senior Azure Security/DevOps Engineer
Only freelancers located in the U.S. may apply.U.S. located freelancers only
We are looking for a Senior Azure Security / DevOps Engineer for a hands-on engagement focused on hardening a production Azure environment and establishing security patterns that can be rolled out organization-wide. This is not an advisory-only role. You’ll be expected to assess the existing Azure estate, identify security gaps, design the right controls, and then implement them using Terraform/Bicep, Azure Policy, Entra ID, networking, and native Azure security services. What you’ll work on Credential elimination Inventory service principals, client secrets, certificates, and other long-lived credentials across Azure. Replace static credentials with Managed Identities wherever possible. Implement Workload Identity Federation / OIDC for CI/CD pipelines and Kubernetes/AKS workloads. Work with application teams to migrate existing workloads safely. Put preventive controls in place so new long-lived credentials cannot quietly creep back into the environment. Blast-radius reduction Design and implement Private Endpoint / Private Link patterns for Azure PaaS and data-plane services. Lock down Storage Accounts, Key Vault, databases, and other sensitive services. Tighten Entra ID / Azure RBAC, including custom roles where built-in roles are too broad. Implement Azure Policy at the Management Group level using deny, audit, modify, and deployIfNotExists patterns. Reduce unnecessary lateral access between workloads, identities, and data. Audit logging & exfiltration visibility Deploy diagnostic settings at scale through Azure Policy rather than configuring resources manually. Route Entra ID sign-in/audit logs, Azure Activity Logs, AKS control-plane/audit logs, Storage logs, and other relevant data-plane telemetry into Log Analytics and the client’s SIEM. Identify logging gaps around services that could be used for data exfiltration. Partner with the detection/security team to make sure the telemetry actually supports their detection and investigation use cases. External attack surface Discover and inventory internet-facing Azure resources. Review permissive NSGs, public IPs, public PaaS endpoints, and unnecessary external exposure. Prioritize findings based on actual risk and execute remediation rather than simply producing an assessment report. Infrastructure as Code & documentation Build reusable Terraform or Bicep modules for the security patterns introduced during the engagement. Produce practical runbooks and architecture documentation so the client's internal teams can continue applying the controls after the engagement. Keep implementations maintainable and realistic for a large Azure environment. What we need 5+ years of cloud security engineering experience, with the majority of that experience in Microsoft Azure. Strong production experience with Entra ID, including Managed Identities, Workload Identity Federation, OIDC, App Registrations, Service Principals, Conditional Access, and RBAC. Deep experience with Azure Policy at enterprise scale, including Management Groups, initiatives, deny policies, deployIfNotExists, and remediation tasks. Strong Azure networking/security knowledge including Private Link, Private Endpoints, NSGs, service endpoints, VNet integration, private DNS, and public network access controls. Experience designing and operating Diagnostic Settings, Log Analytics, Azure Monitor, and SIEM integrations such as Microsoft Sentinel or Splunk. Strong hands-on Terraform or Bicep experience in real production environments. Experience securing AKS/Kubernetes workloads and implementing workload identity patterns. Comfortable working directly with application, platform, networking, and security/detection teams. Nice to have Experience with large multi-subscription Azure estates, enterprise landing zones, CI/CD security, GitHub Actions or Azure DevOps OIDC federation, Microsoft Defender for Cloud, Sentinel, and security remediation programs is a strong plus. Engagement 30–40 hours per week We’re looking for someone senior enough to work independently, explain tradeoffs clearly, and actually implement the controls rather than handing the client a list of recommendations. When applying, please briefly describe a production Azure security engagement where you worked on identity/credential elimination, Azure Policy, Private Link/Private Endpoints, or organization-wide security controls. Please also mention whether you primarily use Terraform or Bicep and your weekly availability.
- More than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
$75.00
-
$100.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:yesterday
- Interviewing:2
- Invites sent:3
- Unanswered invites:1
About the client
- United StatesNorth Pompano Beach11:03 AM
- 2 hires, 2 active
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by