Senior Azure Security/DevOps Engineer

Posted 3 days ago

Only freelancers located in the U.S. may apply.U.S. located freelancers only

Summary

We are looking for a Senior Azure Security / DevOps Engineer for a hands-on engagement focused on hardening a production Azure environment and establishing security patterns that can be rolled out organization-wide. This is not an advisory-only role. You’ll be expected to assess the existing Azure estate, identify security gaps, design the right controls, and then implement them using Terraform/Bicep, Azure Policy, Entra ID, networking, and native Azure security services. What you’ll work on Credential elimination Inventory service principals, client secrets, certificates, and other long-lived credentials across Azure. Replace static credentials with Managed Identities wherever possible. Implement Workload Identity Federation / OIDC for CI/CD pipelines and Kubernetes/AKS workloads. Work with application teams to migrate existing workloads safely. Put preventive controls in place so new long-lived credentials cannot quietly creep back into the environment. Blast-radius reduction Design and implement Private Endpoint / Private Link patterns for Azure PaaS and data-plane services. Lock down Storage Accounts, Key Vault, databases, and other sensitive services. Tighten Entra ID / Azure RBAC, including custom roles where built-in roles are too broad. Implement Azure Policy at the Management Group level using deny, audit, modify, and deployIfNotExists patterns. Reduce unnecessary lateral access between workloads, identities, and data. Audit logging & exfiltration visibility Deploy diagnostic settings at scale through Azure Policy rather than configuring resources manually. Route Entra ID sign-in/audit logs, Azure Activity Logs, AKS control-plane/audit logs, Storage logs, and other relevant data-plane telemetry into Log Analytics and the client’s SIEM. Identify logging gaps around services that could be used for data exfiltration. Partner with the detection/security team to make sure the telemetry actually supports their detection and investigation use cases. External attack surface Discover and inventory internet-facing Azure resources. Review permissive NSGs, public IPs, public PaaS endpoints, and unnecessary external exposure. Prioritize findings based on actual risk and execute remediation rather than simply producing an assessment report. Infrastructure as Code & documentation Build reusable Terraform or Bicep modules for the security patterns introduced during the engagement. Produce practical runbooks and architecture documentation so the client's internal teams can continue applying the controls after the engagement. Keep implementations maintainable and realistic for a large Azure environment. What we need 5+ years of cloud security engineering experience, with the majority of that experience in Microsoft Azure. Strong production experience with Entra ID, including Managed Identities, Workload Identity Federation, OIDC, App Registrations, Service Principals, Conditional Access, and RBAC. Deep experience with Azure Policy at enterprise scale, including Management Groups, initiatives, deny policies, deployIfNotExists, and remediation tasks. Strong Azure networking/security knowledge including Private Link, Private Endpoints, NSGs, service endpoints, VNet integration, private DNS, and public network access controls. Experience designing and operating Diagnostic Settings, Log Analytics, Azure Monitor, and SIEM integrations such as Microsoft Sentinel or Splunk. Strong hands-on Terraform or Bicep experience in real production environments. Experience securing AKS/Kubernetes workloads and implementing workload identity patterns. Comfortable working directly with application, platform, networking, and security/detection teams. Nice to have Experience with large multi-subscription Azure estates, enterprise landing zones, CI/CD security, GitHub Actions or Azure DevOps OIDC federation, Microsoft Defender for Cloud, Sentinel, and security remediation programs is a strong plus. Engagement 30–40 hours per week We’re looking for someone senior enough to work independently, explain tradeoffs clearly, and actually implement the controls rather than handing the client a list of recommendations. When applying, please briefly describe a production Azure security engagement where you worked on identity/credential elimination, Azure Policy, Private Link/Private Endpoints, or organization-wide security controls. Please also mention whether you primarily use Terraform or Bicep and your weekly availability.

  • More than 30 hrs/week
    Hourly
  • 3-6 months
    Duration
  • Expert
    Experience Level
  • $75.00

    -

    $100.00

    Hourly
  • Remote Job
  • Ongoing project
    Project Type

Contract-to-hire opportunity

This lets talent know that this job could become full time.
Learn more
Skills and Expertise
Mandatory skills
Microsoft Azure
DevOps
Activity on this job
  • Proposals:20 to 50
  • Last viewed by client:yesterday
  • Interviewing:
    2
  • Invites sent:
    3
  • Unanswered invites:
    1
About the client
Member since Aug 1, 2026
  • United States
    North Pompano Beach11:03 AM
  • 2 hires, 2 active

Explore similar jobs on Upwork

Apache and PHP-FPM Configuration ExpertHourly‐ Posted 2 months ago
Ubuntu
Apache HTTP Server
Senior DevOps & SRE / Infrastructure EngineerFixed-price‐ Posted 3 weeks ago
DevOps

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo