Senior DevSecOps Engineer
Apex Systems · Chicago, IL · 3 wk ago
EngineeringContract
Location: Chicago, Illinois (Partial Remote)
About the role
We are seeking a Senior DevSecOps Engineer to help design, build, and harden a cloud-native immutable evidencing platform. This platform is built to ingest compliance artifacts, audit evidence, and control attestations from various internal tools. The role involves ensuring the platform, built on Azure, aligns with PCI-DSS, SOX, and GLBA requirements by storing data with cryptographic integrity and exposing capabilities to GRC and audit workflows.
Responsibilities
- Design and implement API ingestion pipelines via Azure API Management (APIM) with OAuth2/JWT validation, rate limiting, and schema enforcement.
- Build event-driven ingestion workflows using Azure Service Bus and Azure Functions.
- Implement immutable artifact storage using Azure Blob Storage with WORM policies and Azure Cosmos DB for metadata indexing.
- Architect Redis Cache for high-throughput query caching.
- Integrate Azure Key Vault for envelope encryption of stored artifacts, including customer-managed keys and automated rotation.
- Build Log Analytics Workspace telemetry pipelines for ingestion events, access audits, and integrity logs.
- Write Terraform Infrastructure as Code (IaC) for all infrastructure resources.
- Implement third-party tool integrations via APIs to ingest evidence artifacts.
Requirements
- 5+ years building production workloads on Azure, with demonstrated experience in event-driven and API-first architectures.
- Experience with immutable/append-only storage patterns is required.
Skills
- Strong experience with Azure API Management (APIM), including policies, backends, and versioning.
- Proficiency in deploying and managing NoSQL and CosmosDB databases.
- Solid Terraform skills, including modules, remote state, and CI/CD integration.
- Strong coding experience in Python and Node.
- Familiarity with envelope encryption patterns using Key Vault.
- Understanding of zero-trust network design (Private Endpoints, VNet integration, NSG/UDR).
- Ability to write KQL for operational queries, alerting, and audit log analysis.
- Experience integrating with third-party tool APIs.
- Hands-on proficiency with integrated testing tools.
- Effective written and verbal communication skills.
Qualifications
- A degree in Computer Science, Information Management, or a related field is preferred.
- Azure Security Engineer Associate certification (preferred).
- AWS Certified Security – Specialty certification (preferred).
- CISSP or CCSP certification (preferred).
Benefits
- Medical, dental, vision, life, and disability insurance plans.
- Employee Stock Purchase Program (ESPP).
- 401K program with company match after 12 months of tenure.
- Health Savings Account (HSA) on the HDHP plan.
- SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions.
- Corporate discount savings program and other discounts.
- On-demand training program.
- Access to certification prep, technical and leadership courses/books/seminars after 6+ months of tenure.
- Certification discounts and association perks (e.g., CompTIA, IIBA).
- Dedicated customer service team for benefits and resources.
- Access to a certified Career Coach.