DevSecOps Engineer (Azure)
Title: DevSecOps Engineer (Azure)Location: Chicago, IL 3 days HybridDuration: 04 MonthsRole description:We are building a cloud-native immutable evidencing platform to ingest compliance artifacts, audit evidence, and control attestations from a wide range of internal tools via API, store them with cryptographic integrity guarantees, and expose querying and retrieval capabilities to downstream GRC and audit workflows. The contractor will help design, build, and harden this platform on Azure in alignment with PCI-DSS, SOX, and GLBA requirements.ResponsibilitiesDesign and implement API ingestion pipelines via Azure API Management (APIM) with OAuth2/JWT validation, rate limiting, and schema enforcementBuild event-driven ingestion workflows using Azure Service Bus and Azure Functions (durable, fan-out patterns)Implement immutable artifact storage using Azure Blob Storage with WORM policies (time-based retention locks) and Azure Cosmos DB for tamper-evident metadata indexingArchitect Redis Cache for high-throughput query caching while preserving source-of-truth immutability guaranteesIntegrate Azure Key Vault for envelope encryption of stored artifacts (customer-managed keys, automated rotation)Build Log Analytics Workspace telemetry pipelines covering ingestion events, access audit trails, and integrity verification logsWrite Terraform IaC for all infrastructure — no click-ops; all resources policy-as-code compliantImplement third-party tool integrations (connector APIs) to ingest evidence artifacts from source systemsSkills:5+ years building production workloads on Azure; demonstrated experience with event-driven and API-first architecturesStrong APIM experience: policies (inbound/outbound XML), backends, named values, developer portal, versioningExperience implementing immutable/append-only storage patterns — WORM blob policies, Cosmos DB change feed auditing, or equivalentDeploy and Manage NoSQL and CosmosDB database experienceSolid Terraform skills: modules, remote state, Azure Provider, CI/CD integration via GitHub Actions or Azure DevOpsStrong coding experience in Python and NodeFamiliarity with envelope encryption patterns using Key Vault (CMK, key rotation, purge protection)Understanding of zero-trust network design: Private Endpoints, VNet integration, NSG/UDR patternsAbility to write KQL for operational queries, alerting rules, and audit log analysisExperience integrating with third-party tool APIs (GRC platforms, vulnerability scanners, ticketing systems, or similar)Hands-on proficiency with integrated testing toolsEffective written and verbal communication skills to collaborate with cross-functional teamsDesired certifications such as Azure Security Engineer Associate certification, and AWS-certified security – Specialty, CISSP and CCSPDegree in Computer Science, Information Management, or related field preferredApplicant Notices & DisclaimersFor information on benefits, equal opportunity employment, and location-specific applicant notices, click hereAt SPECTRAFORCE, we are committed to maintaining a workplace that ensures fair compensation and wage transparency in adherence with all applicable state and local laws.This position''s pay range is $70.00/hr - $78.00/hr.