Azure Engineer
KellyMitchell Group · Chicago, IL · 3 wk ago
Engineering$60–$76/hrContract
Our client, a leading financial services provider, is building a cloud-native immutable evidencing platform to ingest compliance artifacts, audit evidence, and control attestations from a wide range of internal tools via API, store them with cryptographic integrity guarantees, and expose querying and retrieval capabilities to downstream GRC and audit workflows.
Responsibilities
- Design and implement API ingestion pipelines via Azure API Management (APIM) with OAuth2/JWT validation, rate limiting, and schema enforcement
- Build event-driven ingestion workflows using Azure Service Bus and Azure Functions (durable, fan-out patterns)
- Implement immutable artifact storage using Azure Blob Storage with WORM policies (time-based retention locks) and Azure Cosmos DB for tamper-evident metadata indexing
- Architect Redis Cache for high-throughput query caching while preserving source-of-truth immutability guarantees
- Integrate Azure Key Vault for envelope encryption of stored artifacts (customer-managed keys, automated rotation)
- Build Log Analytics Workspace telemetry pipelines covering ingestion events, access audit trails, and integrity verification logs
- Write Terraform IaC for all infrastructure — no click-ops; all resources policy-as-code compliant
- Implement third-party tool integrations (connector APIs) to ingest evidence artifacts from source systems
Requirements
- Degree in Computer Science, Information Management, or related field preferred
- 5+ years building production workloads on Azure; demonstrated experience with event-driven and API-first architectures
- Strong APIM experience: policies (inbound/outbound XML), backends, named values, developer portal, versioning
- Experience implementing immutable/append-only storage patterns — WORM blob policies, Cosmos DB change feed auditing, or equivalent
- Deploy and manage NoSQL and CosmosDB database experience
- Solid Terraform skills: modules, remote state, Azure Provider, CI/CD integration via GitHub Actions or Azure DevOps
- Strong coding experience in Python and Node
- Familiarity with envelope encryption patterns using Key Vault (CMK, key rotation, purge protection)
- Understanding of zero-trust network design: Private Endpoints, VNet integration, NSG/UDR patterns
- Ability to write KQL for operational queries, alerting rules, and audit log analysis
- Experience integrating with third-party tool APIs (GRC platforms, vulnerability scanners, ticketing systems, or similar)
- Hands-on proficiency with integrated testing tools
- Effective written and verbal communication skills to collaborate with cross-functional teams
Qualifications
- Desired certifications such as Azure Security Engineer Associate certification, AWS-certified security – Specialty, CISSP, and CCSP
Skills
- Architects Scalable & Secure Solutions
- Drives Technical Excellence
- Collaborates Across Technical Domains
Schedule
Hybrid 3 days onsite in Chicago, IL
Contract: ASAP – 12/31/2026
Pay
The approximate pay range for this position is between $60.00 and $76.00 per hour. Final compensation may vary based on factors including but not limited to background, knowledge, skills, and location.
Benefits
- Medical, Dental, & Vision Insurance Plans
- Employee-Owned Profit Sharing (ESOP)
- 401K offered