Senior Azure Security Architect - Remote in Colombia

Nearshore Cyber

Colombia

A distancia

COP 272.828.000 - 545.656.000

A tiempo parcial

Hace 8 días
Generador de candidaturas

Destaca en este puesto — crea un currículum adaptado y una carta de presentación en aproximadamente un minuto.

Supera los filtros ATS

Descripción de la vacante

Nearshore Cyber is seeking a senior security architect to lead the security design for a Microsoft Azure environment in a remote, hourly contract. You will own identity, infrastructure, networking, governance, and monitoring, advising on ransomware resilience and working with an MSSP to align telemetry and controls.

You will collaborate with an experienced Azure team, map controls to HIPAA and other standards, and mentor delivery engineers to embed security into engineering practices.

Formación

  • Seven or more years in information security, including Azure design in production.
  • Hands-on depth in Azure network security and governance.
  • Experience with Defenders/SentinelSIEM, Azure Policy, and HIPAA context.
  • Backup, recovery, and DR design for ransomware scenarios.
  • Professional English fluency for live technical discussions with US stakeholders.
  • Availability for 1–2 hours daily with overlap to US Pacific hours.

Responsabilidades

  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging and monitoring.
  • Design Entra ID, Conditional Access, PIM and RBAC for least-privilege access.
  • Harden AVS, Azure VMs and supporting services against baselines and review live builds.
  • Define segmentation and traffic flow controls across ExpressRoute, firewalls, and VPN connectivity.
  • Shape management group and subscription structure, Azure Policy assignments and security baselines.
  • Define log sources, retention and detection coverage in Defender for Cloud and Sentinel.
  • Advise on ransomware resilience with immutable backups, RTO/RPO and testing.
  • Mentor delivery engineers to embed security into build processes.
  • Map controls to HIPAA and recognized frameworks; document decisions for client, insurer, and auditors.

Conocimientos

Azure security design
SIEM experience
HIPAA compliance
English fluency
Azure governance
ExpressRoute security
Risk assessment

Herramientas

Palo Alto VM-Series
Prisma SD-WAN
Azure VMware Solution
VMware NSX
HCX

Descripción del empleo

Healthcare Cloud | Part-Time Hourly Contract | Remote
About the Engagement

A Microsoft-focused cloud services firm is seeking a senior security architect to join its delivery team on a part-time, hourly basis. The firm is the managed services provider (MSP) for a multi-clinic US healthcare organization and is leading the migration of the organization's clinical and business applications to Microsoft Azure. The client places a strong emphasis on ransomware resilience, and a healthcare-focused managed security services provider (MSSP) is integrating the new environment into its monitoring service. The core need is a comprehensive security design for the Azure environment.

You will be the security voice on an experienced Azure team: reviewing and hardening the architecture as it is built, advising on resilience and recovery, and joining working sessions with the MSSP to separate the questions that matter from the noise in real time.

The Environment
  • A hybrid environment spanning a hosted VMware private cloud and Microsoft Azure, connected by two Azure ExpressRoute circuits.
  • Palo Alto Networks VM-Series firewalls and Prisma SD-WAN ION appliances deployed as native virtual machines at both sites.
  • An Azure VMware Solution (AVS) deployment receiving the full data center migration. Azure becomes the primary site and the hosted private cloud becomes the secondary site.
  • More than 40 clinician-facing and business applications in scope, including laboratory, dental, radiology, and IT systems.
  • A vendor-hosted electronic health record (EHR) platform, reached through vendor-specified, customer-managed connectivity hardware in a colocation facility, with integrations to the in-scope applications.
What You Will Do
  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging, and monitoring.
  • Identity and access control: design Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), and role-based access control (RBAC) for least-privilege administrator and third-party access.
  • Infrastructure: harden AVS, Azure virtual machines, and supporting services against recognized baselines, and review the live build as it progresses.
  • Networking: define segmentation and traffic flow controls across the ExpressRoute circuits, the Palo Alto firewalls and ION appliances, clinic and VPN connectivity, and internet egress.
  • Governance and policies: shape the management group and subscription structure, Azure Policy assignments, security baselines, and written security standards.
  • Logging and monitoring: define log sources, retention, and detection coverage in Microsoft Defender for Cloud and Microsoft Sentinel or the MSSP's platform.
  • Advise on ransomware resilience with Azure as primary and the hosted site as secondary: immutable and isolated backups, recovery point and recovery time objectives (RPO and RTO), and recovery testing.
  • Join working sessions with the client's MSSP, assess its requests, and recommend what telemetry Azure and the firewalls should provide.
  • Map controls to the HIPAA Security Rule and recognized frameworks, and document decisions clearly for the client, its insurer, and auditors.
  • Mentor the delivery engineers so security practice becomes part of how the team builds.
Required Qualifications
  • Seven or more years in information security, including at least three years designing and hardening Microsoft Azure environments in production.
  • Hands-on depth in Azure network security: hub-and-spoke design, Network Security Groups, private endpoints, ExpressRoute, route control, and firewall insertion.
  • Experience designing Azure governance: management groups, subscriptions, RBAC, Azure Policy, and landing zone security baselines.
  • Working knowledge of Microsoft Defender for Cloud, Microsoft Sentinel or another security information and event management (SIEM) platform, and Azure Policy.
  • Practical experience designing backup, recovery, and DR for ransomware scenarios, including immutability and isolated recovery.
  • Experience in regulated environments, ideally healthcare under HIPAA, and comfort working under a Business Associate Agreement (BAA).
  • Professional English fluency for live technical discussions with US stakeholders.
  • Consistent availability for one to two hours per business day with overlap during US Pacific business hours.
Preferred Qualifications
  • Palo Alto Networks experience, especially VM-Series firewalls and Prisma SD-WAN ION appliances running as virtual machines in Azure and hosted environments.
  • Azure VMware Solution, VMware NSX (including distributed firewall micro-segmentation), and VMware HCX experience.
  • Exposure to Epic or comparable EHR platforms and their connectivity and integration security patterns.
  • Experience working alongside or inside an MSSP, including log source onboarding and alert tuning.
  • Familiarity with the NIST Cybersecurity Framework (CSF) 2.0, the Microsoft cloud security benchmark, CIS Benchmarks, and the HHS 405(d) Health Industry Cybersecurity Practices (HICP).
  • Certifications such as Microsoft AZ-500 or SC-100, Palo Alto PCNSE, CISSP, CCSP, or HCISPP.
  • Bilingual English and Spanish; the team works comfortably in both.
Engagement Details
  • Engagement type: Hourly independent contract, starting on a trial basis with room to grow.
  • Time commitment: One to two hours per business day, flexible scheduling.
  • Start: As soon as possible, ideally the week of September 28, 2026.
  • Location: Remote, for candidates based in Colombia.
  • Languages: English required; Spanish a plus.
  • Compensation: Hourly rate commensurate with experience, as an independent contractor engaged through Nearshore Cyber.
Your Information

Nearshore Cyber handles applicant information under its privacy policy: https://nearshorecyber.com.mx/privacy. If you are shortlisted, your application, assessment, and interview recording will be shared with the hiring client for this role.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Azure Security Architect - Healthcare Cloud Lead
Senior Azure Security Architect - Healthcare Cloud Lead

Nearshore Cyber • Colombia

A distancia
COP 272.828.000 - 545.656.000
Senior DevOps Engineer
Senior DevOps Engineer

Publicis Sapient • Colombia

Presencial
COP 280.260.000 - 373.680.000
Senior Cloud Infrastructure Engineer, Talent Pipeline (Remote LATAM)
Senior Cloud Infrastructure Engineer, Talent Pipeline (Remote LATAM)

Atmosera • Colombia

A distancia
COP 186.840.000 - 280.260.000
Remote work
Travel opportunities
Cybersecurity Project Manager
Cybersecurity Project Manager

Hired Remoteli • Colombia

Presencial
COP 183.580.555 - 257.012.777
Competitive pay in USD
100% remote work
Flexible time-off
+2
8995 - Cybersecurity Cloud, Infrastructure and ITOps Senior, Lead Argentina, Colombia, Mexico, Paraguay, Bolivia, United Kingdom Published 7 days ago
8995 - Cybersecurity Cloud, Infrastructure and ITOps Senior, Lead Argentina, Colombia, Mexico, Paraguay, Bolivia, United Kingdom Published 7 days ago

Unosquare, Inc. • Colombia

A distancia
COP 186.840.000 - 280.260.000
Application Engineer
Application Engineer

Salvatech • Bogotá ciudad

Presencial
COP 185.117.000 - 277.675.000
Senior DevOps Engineer (Azure + Terraform)
Senior DevOps Engineer (Azure + Terraform)

Publicis Groupe Holdings B.V • Bogotá

Presencial
COP 120.000.000 - 180.000.000
Senior DevOps Engineer (Azure + Terraform)
Senior DevOps Engineer (Azure + Terraform)

Publicis Groupe ANZ • Bogotá ciudad

Presencial
COP 185.117.000 - 308.528.000
Site Reliability Engineer (Cloud)
Site Reliability Engineer (Cloud)

Sharesource Australia BPO Corporation • Norte

Presencial
COP 110.000.000 - 180.000.000
Remote + Hybrid
Work-life balance
Open culture
+3
Cloud Azure Security Engineer
Cloud Azure Security Engineer

Monks group • Colombia

Presencial
COP 60.000.000 - 110.000.000