Senior Azure Security Architect
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Al continuar, aceptas nuestros Términos & Política de Privacidad.
A Microsoft-focused cloud services firm is seeking a senior security architect to join its delivery team on a part-time, hourly basis. The firm is the managed services provider (MSP) for a multi-clinic US healthcare organization and is leading the migration of the organization's clinical and business applications to Microsoft Azure. The client places a strong emphasis on ransomware resilience, and a healthcare-focused managed security services provider (MSSP) is integrating the new environment into its monitoring service. The core need is a comprehensive security design for the Azure environment.
The Environment- A hybrid environment spanning a hosted VMware private cloud and Microsoft Azure, connected by two Azure ExpressRoute circuits.
- Palo Alto Networks VM-Series firewalls and Prisma SD-WAN ION appliances deployed as native virtual machines at both sites.
- An Azure VMware Solution (AVS) deployment receiving the full data center migration. Azure becomes the primary site and the hosted private cloud becomes the secondary site.
- More than 40 clinician-facing and business applications in scope, including laboratory, dental, radiology, and IT systems.
- A vendor-hosted electronic health record (EHR) platform, reached through vendor-specified, customer-managed connectivity hardware in a colocation facility, with integrations to the in-scope applications.
- Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging, and monitoring.
- Identity and access control: design Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), and role-based access control (RBAC) for least-privilege administrator and third-party access.
- Infrastructure: harden AVS, Azure virtual machines, and supporting services against recognized baselines, and review the live build as it progresses.
- Networking: define segmentation and traffic flow controls across the ExpressRoute circuits, the Palo Alto firewalls and ION appliances, clinic and VPN connectivity, and internet egress.
- Governance and policies: shape the management group and subscription structure, Azure Policy assignments, security baselines, and written security standards.
- Logging and monitoring: define log sources, retention, and detection coverage in Microsoft Defender for Cloud and Microsoft Sentinel or the MSSP's platform.
- Advise on ransomware resilience with Azure as primary and the hosted site as secondary: immutable and isolated backups, recovery point and recovery time objectives (RPO and RTO), and recovery testing.
- Join working sessions with the client's MSSP, assess its requests, and recommend what telemetry Azure and the firewalls should provide.
- Map controls to the HIPAA Security Rule and recognized frameworks, and document decisions clearly for the client, its insurer, and auditors.
- Mentor the delivery engineers so security practice becomes part of how the team builds.
- Seven or more years in information security, including at least three years designing and hardening Microsoft Azure environments in production.
- Hands-on depth in Azure network security: hub-and-spoke design, Network Security Groups, private endpoints, ExpressRoute, route control, and firewall insertion.
- Experience designing Azure governance: management groups, subscriptions, RBAC, Azure Policy, and landing zone security baselines.
- Working knowledge of Microsoft Defender for Cloud, Microsoft Sentinel or another security information and event management (SIEM) platform, and Azure Policy.
- Practical experience designing backup, recovery, and DR for ransomware scenarios, including immutability and isolated recovery.
- Experience in regulated environments, ideally healthcare under HIPAA, and comfort working under a Business Associate Agreement (BAA).
- Professional English fluency for live technical discussions with US stakeholders.
- Consistent availability for one to two hours per business day with overlap during US Pacific business hours.
- Palo Alto Networks experience, especially VM-Series firewalls and Prisma SD-WAN ION appliances running as virtual machines in Azure and hosted environments.
- Azure VMware Solution, VMware NSX (including distributed firewall micro-segmentation), and VMware HCX experience.
- Exposure to Epic or comparable EHR platforms and their connectivity and integration security patterns.
- Experience working alongside or inside an MSSP, including log source onboarding and alert tuning.
- Familiarity with the NIST Cybersecurity Framewor