Security Lead Consultant
Scope of Services
The Security Lead Consultant will perform the following activities:
Security Engineering & Implementation (Within OTI Environment)
- Implement and configure security controls within OTI-managed Azure and SaaS environments for OpenRecords
- Configure identity, access management, and role-based access controls (RBAC) for applications and infrastructure
- Implementation of security configurations for encryption, logging, monitoring, and audit controls
- Review and validate secure configurations across Azure resources (networking, compute, storage, and application services)
Identity & Access Management (IAM) Implementation
- Configure and validate SSO, MFA, and Active Directory integrations for OpenRecords
- Implement role-based access models and least privilege access controls
- Configure privileged access workflows and administrative access controls
- User provisioning and access lifecycle processes
- Perform access validation testing and remediation of identity-related issues
Vulnerability Management & Security Operations
- Configure and operate vulnerability scanning and assessment tools for OpenRecords environments
- Review vulnerability scan results and coordinate remediation with infrastructure and application teams
- Configure and validate security logging, alerting, and dashboarding as part of system implementation
- Configure SIEM, monitoring, and alerting rules for OpenRecords system
- Track and validate closure of security findings and misconfigurations
Security Architecture Implementation
- Participate in technical implementation and design sessions for OpenRecords
- Review and validate security architecture for cloud, SaaS, APIs, and integrations
- Ensure security-by-design principles are implemented during development and deployment phases
- Validate implementation of secure network architecture (segmentation, private endpoints, firewalls)
- Review vendor security configurations and ensure alignment with approved security requirements
Security Tooling & Platform Configuration
- Configure security tools used in the OpenRecords environment
- Implementation of endpoint protection, monitoring, and vulnerability management tools
- Configure logging, alerting, and security telemetry collection in Log Analytics and SIEM platforms
- Integration of Microsoft security tooling (Defender, Sentinel, M365 security stack where applicable)
- Configure alerts
Technical Documentation
As-built documentation for documenting all configurations made
Deliverables
- Configured identity and access management controls (SSO, MFA, RBAC) for OpenRecords
- Configure security related monitoring, logging, and alerting for OpenRecords system
- Security configuration baselines for Azure and integrated SaaS components
- Security readiness assessment and go-live validation report
Duration: 240 Hours • Location: New York, NY
Mandatory Skills/Experience: Azure Security (Defender for Cloud, Sentinel, security baselines); Identity & Access Management (Azure AD, SSO, MFA, RBAC, PAM); Vulnerability management tools (e.g., Rapid7, Qualys, or equivalent); SIEM and log analytics (Microsoft Sentinel, Log Analytics Workspace); Cloud security architecture (Azure networking, private endpoints, segmentation); Security tooling: CrowdStrike, Microsoft 365 Security Stack, Cisco security tools; Incident response and security operations (SOC processes, triage, escalation); DevSecOps practices and secure CI/CD integration (Azure DevOps, pipelines); Encryption, key management (Key Vault), and data protection controls; Strong hands-on implementation and troubleshooting experience in cloud environments