Senior Azure Cloud Security Engineer, 40 hrs/wk, 13 Weeks, Immediate Start

Posted last week

Only freelancers located in the U.S. may apply.U.S. located freelancers only

Summary

We are staffing a senior Azure security engineer onto a 13-week implementation engagement with a large enterprise client. This is hands-on build work, not assessment or strategy. You will be writing policy, wiring federation, and shipping infrastructure-as-code alongside the client's own engineering teams. Start date is August 17, 2026. Please only apply if you can commit to that date and to 40 hours per week through mid-November. WHAT YOU WILL BE DOING: Credential elimination. You will inventory service principals, client secrets, and long-lived credentials across the Azure estate, then retire them. That means standing up workload identity federation and OIDC trust patterns for CI/CD and Kubernetes workloads, migrating applications onto managed identities in partnership with the teams that own them, and putting preventive controls in place so that net-new static secrets cannot be created after you leave. Blast radius reduction. Private Endpoint and Private Link architecture for data-plane services, network access rules on storage and Key Vault and other PaaS, Azure Policy enforced at the management group scope, and RBAC tightening with custom roles where the built-ins are too permissive. The goal is that a compromised identity or workload cannot reach data it has no business reaching, regardless of what a role assignment says. Audit logging and exfiltration visibility. Diagnostic settings deployed at scale through policy rather than by hand, Entra ID sign-in and audit log routing, activity logs, AKS control plane and audit logging, and closing data-plane logging gaps on storage and other exfiltration-relevant services. You will work with the client detection team to confirm the telemetry actually supports their use cases. External attack surface. Discovery and inventory of internet-facing Azure resources, assessment of permissive NSG rules and unnecessary public IPs and exposed PaaS endpoints, then remediation execution. Everything you build gets documented as a reusable pattern. The client intends to adopt these organization-wide after the initial engagement, so the quality of your Terraform modules and runbooks matters as much as the controls themselves. WHAT WE NEED YOU TO HAVE Five or more years in cloud security engineering, with the majority of that time in Azure. Production depth in Entra ID, specifically managed identities, workload identity federation, app registrations and service principals, conditional access, and RBAC including custom role design. Azure Policy at enterprise scale. Management group hierarchy design, deny and deployIfNotExists effects, and remediation tasks. Azure network security for data protection. Private Link and Private Endpoints, NSGs, service endpoints, and the DNS design implications that come with each. Diagnostic settings, Log Analytics, and log delivery into a SIEM such as Sentinel or Splunk. Terraform or Bicep in production, not just in a lab. You will be writing modules that other people consume. A track record of driving security changes through engineering teams who did not ask for your controls, do not report to you, and have their own deadlines. This is the part most candidates underestimate. STRONG PLUSES AKS security depth including workload identity, network policy, audit logging, and admission control. GitHub Actions OIDC federation into Azure. PowerShell or Python automation against Microsoft Graph and Azure Resource Manager. Certifications such as AZ-500, SC-100, or SC-300, or equivalent demonstrated capability. Prior consulting or staff augmentation experience.

  • More than 30 hrs/week
    Hourly
  • 3-6 months
    Duration
  • Expert
    Experience Level
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
Microsoft Azure
Network Security
Activity on this job
  • Proposals:50+
  • Last viewed by client:last week
  • Interviewing:
    0
  • Invites sent:
    6
  • Unanswered invites:
    6
About the client
Member since May 4, 2020
  • United States
    Iowa City7:20 AM
  • $15K total spent
    9 hires, 3 active
  • 177 hours

Explore similar jobs on Upwork

Identify Root Cause of Assembly IssueHourly‐ Posted 4 weeks ago
Network Security
Network Administration
Computer Network
Linux System Administration
Cybersecurity Professional for Account SecurityFixed-price‐ Posted 4 weeks ago
Network Security
Information Security
Internet Security
Security Analysis

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo