Senior Azure Security Architect

Hace 5 horas

Mexico, chihuahua Nearshore Cyber Jornada completa
Healthcare Cloud | Part-Time Hourly Contract | RemoteAbout the Engagement

A Microsoft-focused cloud services firm is seeking a senior security architect to join its delivery team on a part-time, hourly basis. The firm is the managed services provider (MSP) for a multi-clinic US healthcare organization and is leading the migration of the organization's clinical and business applications to Microsoft Azure. The client places a strong emphasis on ransomware resilience, and a healthcare-focused managed security services provider (MSSP) is integrating the new environment into its monitoring service. The core need is a comprehensive security design for the Azure environment.

The Environment
  • A hybrid environment spanning a hosted VMware private cloud and Microsoft Azure, connected by two Azure ExpressRoute circuits.
  • Palo Alto Networks VM-Series firewalls and Prisma SD-WAN ION appliances deployed as native virtual machines at both sites.
  • An Azure VMware Solution (AVS) deployment receiving the full data center migration. Azure becomes the primary site and the hosted private cloud becomes the secondary site.
  • More than 40 clinician-facing and business applications in scope, including laboratory, dental, radiology, and IT systems.
  • A vendor-hosted electronic health record (EHR) platform, reached through vendor-specified, customer-managed connectivity hardware in a colocation facility, with integrations to the in-scope applications.
What You Will Do
  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging, and monitoring.
  • Identity and access control: design Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), and role-based access control (RBAC) for least-privilege administrator and third-party access.
  • Infrastructure: harden AVS, Azure virtual machines, and supporting services against recognized baselines, and review the live build as it progresses.
  • Networking: define segmentation and traffic flow controls across the ExpressRoute circuits, the Palo Alto firewalls and ION appliances, clinic and VPN connectivity, and internet egress.
  • Governance and policies: shape the management group and subscription structure, Azure Policy assignments, security baselines, and written security standards.
  • Logging and monitoring: define log sources, retention, and detection coverage in Microsoft Defender for Cloud and Microsoft Sentinel or the MSSP's platform.
  • Advise on ransomware resilience with Azure as primary and the hosted site as secondary: immutable and isolated backups, recovery point and recovery time objectives (RPO and RTO), and recovery testing.
  • Join working sessions with the client's MSSP, assess its requests, and recommend what telemetry Azure and the firewalls should provide.
  • Map controls to the HIPAA Security Rule and recognized frameworks, and document decisions clearly for the client, its insurer, and auditors.
  • Mentor the delivery engineers so security practice becomes part of how the team builds.
Required Qualifications
  • Seven or more years in information security, including at least three years designing and hardening Microsoft Azure environments in production.
  • Hands-on depth in Azure network security: hub-and-spoke design, Network Security Groups, private endpoints, ExpressRoute, route control, and firewall insertion.
  • Experience designing Azure governance: management groups, subscriptions, RBAC, Azure Policy, and landing zone security baselines.
  • Working knowledge of Microsoft Defender for Cloud, Microsoft Sentinel or another security information and event management (SIEM) platform, and Azure Policy.
  • Practical experience designing backup, recovery, and DR for ransomware scenarios, including immutability and isolated recovery.
  • Experience in regulated environments, ideally healthcare under HIPAA, and comfort working under a Business Associate Agreement (BAA).
  • Professional English fluency for live technical discussions with US stakeholders.
  • Consistent availability for one to two hours per business day with overlap during US Pacific business hours.
Preferred Qualifications
  • Palo Alto Networks experience, especially VM-Series firewalls and Prisma SD-WAN ION appliances running as virtual machines in Azure and hosted environments.
  • Azure VMware Solution, VMware NSX (including distributed firewall micro-segmentation), and VMware HCX experience.
  • Exposure to Epic or comparable EHR platforms and their connectivity and integration security patterns.
  • Experience working alongside or inside an MSSP, including log source onboarding and alert tuning.
  • Familiarity with the NIST Cybersecurity Framewor