Senior Azure DevSecOps Engineer
3Core Systems , Inc
- Location
- Onsite (Chicago, Illinois)
- Employment
- Contract
- Level
- Senior Level
About the Role
3Core Systems is seeking a Senior Azure DevSecOps Engineer to design and implement a secure, immutable cloud platform for compliance and audit evidence ingestion. The role focuses on building event-driven API pipelines and infrastructure-as-code solutions aligned with PCI-DSS, SOX, and GLBA standards.
Skills
Full job details
Job Title: Senior Azure DevSecOps Engineer
Location: Chicago, IL, 60603, USA
Duration: Long-term contract
Senior Azure DevSecOps Engineer Compliance and Immutable
Cloud Platform
Must Have Skills/Attributes: ADO, Azure, GitHub, NodeJs, NoSQL, Python, Ticketing
Systems, XML
Experience Desired: Building production workloads on Azure (5 yrs); Azure
API Management (APIM) policies, backends, named values, developer portal,
versioning (5 yrs); Immutable/append-only storage patterns (WORM blob policies,
Cosmos DB change feed auditing) (5 yrs); NoSQL and CosmosDB deployment and
management (5 yrs); Terraform modules, remote state, Azure Provider, CI/CD
integration (5 yrs); Python and Node.js (strong coding) (5 yrs)
Preferred Certifications (Nice to Have):
• Azure Security Engineer Associate
• AWS Certified Security – Specialty
• CISSP, CCSP
Job Description
Required Experience, Knowledge & Skills:
• 5+ years building production workloads on Azure with event-driven and
API-first architectures.
• Strong APIM experience: policies (inbound/outbound XML), backends, named
values, developer portal, versioning.
• Experience implementing immutable/append-only storage patterns (WORM blob
policies, Cosmos DB change feed auditing, or equivalent).
• Deploy and manage NoSQL and CosmosDB databases.
• Familiarity with envelope encryption patterns using Key Vault (CMK, key
rotation, purge protection).
• Understanding of zero-trust network design: Private Endpoints, VNet
integration, NSG/UDR patterns.
• Solid Terraform skills: modules, remote state, Azure Provider, CI/CD
integration via GitHub Actions or Azure DevOps.
• Strong coding experience in Python and Node.js.
• Hands-on proficiency with integrated testing tools.
• Ability to write KQL for operational queries, alerting rules, and audit log
analysis.
• Experience integrating with third-party tool APIs (GRC platforms,
vulnerability scanners, ticketing systems, or similar).
Required Soft Skills:
• Effective written and verbal communication skills to collaborate with
cross-functional teams.
We are building a cloud-native, immutable evidence platform to ingest
compliance artifacts, audit evidence, and control attestations from a wide
range of internal tools via APIs, store them with cryptographic integrity
guarantees, and expose querying and retrieval capabilities to downstream GRC
and audit workflows. The contractor will help design, build, and harden this
platform on Azure in alignment with PCI-DSS, SOX, and GLBA requirements.
Key Responsibilities:
• Design and implement API ingestion pipelines via Azure API Management (APIM)
with OAuth2/JWT validation, rate limiting, and schema enforcement.
• Build event-driven ingestion workflows using Azure Service Bus and Azure
Functions (durable, fan-out patterns).
• Implement immutable artifact storage using Azure Blob Storage with WORM
policies (time-based retention locks) and Azure Cosmos DB for tamper-evident
metadata indexing.
• Architect Redis Cache for high-throughput query caching while preserving
source-of-truth immutability guarantees.
• Integrate Azure Key Vault for envelope encryption of stored artifacts
(customer-managed keys, automated rotation).
• Build Log Analytics Workspace telemetry pipelines covering ingestion events,
access audit trails, and integrity verification logs.
• Write Terraform IaC for all infrastructure — no click-ops; all resources
policy-as-code compliant.
• Implement third-party tool integrations (connector APIs) to ingest evidence
artifacts from source systems.
Appreciate
if you can send me the following information needed for above mentioned
position: