Senior Azure Security Architect - Remote in Mexico

Nearshore Cyber

México

A distancia

MXN 1.466.000 - 2.933.000

A tiempo parcial

Hace 9 días
Generador de candidaturas

Transforma esta oferta en una entrevista — un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Nearshore Cyber is seeking a senior security architect for a part-time, hourly remote engagement centered on securing a Microsoft Azure environment for a U.S. healthcare context.

The candidate will own the security design across identity, infrastructure, networking, governance, and monitoring, while aligning with HIPAA requirements and an MSSP integration. Required are 7+ years in information security including Azure production design, strong Azure governance and network security expertise, and

Formación

  • Seven+ years in information security, incl. 3+ years designing and hardening Azure in production.
  • Hands-on depth in Azure network security: hub-and-spoke, NSGs, private endpoints, ExpressRoute, routing, firewall insertion.
  • Experience designing Azure governance: management groups, subscriptions, RBAC, Policy, landing zone baselines.
  • Knowledge of Defender for Cloud, Sentinel or SIEM, and Azure Policy.
  • Backup, recovery, and DR design for ransomware with immutability and isolated recovery.
  • Experience in healthcare security under HIPAA, BAAs.
  • Professional English fluency for live US stakeholder discussions.
  • Availability for 1–2 hours per business day with US Pacific overlap.

Responsabilidades

  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging and monitoring.
  • Design Entra ID, CA, PIM and RBAC for least-privilege admin and third-party access.
  • Harden AVS, Azure VMs and supporting services against baselines and review live build progress.
  • Define segmentation and traffic controls across ExpressRoute, firewalls, and VPN connectivity.
  • Shape the management group and subscription structure, Azure Policy assignments and security baselines.
  • Define log sources, retention and detection coverage in Defender for Cloud and Sentinel or MSSP platform.
  • Advise on ransomware resilience with immutable backups, RPO/RTO and testing.
  • Mentor delivery engineers to embed security into pipelines.

Conocimientos

Azure security architecture
IAM / RBAC design
HIPAA / BAA
SIEM/Defender/Sentinel
English fluency
US-Pacific overlap hours
Azure governance
Threat modelling

Herramientas

Palo Alto VM-Series
Azure ExpressRoute
Azure Policy
Azure VMware Solution

Descripción del empleo

Healthcare Cloud | Part-Time Hourly Contract | Remote
About the Engagement

A Microsoft-focused cloud services firm is seeking a senior security architect to join its delivery team on a part-time, hourly basis. The firm is the managed services provider (MSP) for a multi-clinic US healthcare organization and is leading the migration of the organization's clinical and business applications to Microsoft Azure. The client places a strong emphasis on ransomware resilience, and a healthcare-focused managed security services provider (MSSP) is integrating the new environment into its monitoring service. The core need is a comprehensive security design for the Azure environment.

The Environment
  • A hybrid environment spanning a hosted VMware private cloud and Microsoft Azure, connected by two Azure ExpressRoute circuits.
  • Palo Alto Networks VM-Series firewalls and Prisma SD-WAN ION appliances deployed as native virtual machines at both sites.
  • An Azure VMware Solution (AVS) deployment receiving the full data center migration. Azure becomes the primary site and the hosted private cloud becomes the secondary site.
  • More than 40 clinician-facing and business applications in scope, including laboratory, dental, radiology, and IT systems.
  • A vendor-hosted electronic health record (EHR) platform, reached through vendor-specified, customer-managed connectivity hardware in a colocation facility, with integrations to the in-scope applications.
What You Will Do
  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging, and monitoring.
  • Identity and access control: design Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), and role-based access control (RBAC) for least-privilege administrator and third-party access.
  • Infrastructure: harden AVS, Azure virtual machines, and supporting services against recognized baselines, and review the live build as it progresses.
  • Networking: define segmentation and traffic flow controls across the ExpressRoute circuits, the Palo Alto firewalls and ION appliances, clinic and VPN connectivity, and internet egress.
  • Governance and policies: shape the management group and subscription structure, Azure Policy assignments, security baselines, and written security standards.
  • Logging and monitoring: define log sources, retention, and detection coverage in Microsoft Defender for Cloud and Microsoft Sentinel or the MSSP's platform.
  • Advise on ransomware resilience with Azure as primary and the hosted site as secondary: immutable and isolated backups, recovery point and recovery time objectives (RPO and RTO), and recovery testing.
  • Join working sessions with the client's MSSP, assess its requests, and recommend what telemetry Azure and the firewalls should provide.
  • Map controls to the HIPAA Security Rule and recognized frameworks, and document decisions clearly for the client, its insurer, and auditors.
  • Mentor the delivery engineers so security practice becomes part of how the team builds.
Required Qualifications
  • Seven or more years in information security, including at least three years designing and hardening Microsoft Azure environments in production.
  • Hands-on depth in Azure network security: hub-and-spoke design, Network Security Groups, private endpoints, ExpressRoute, route control, and firewall insertion.
  • Experience designing Azure governance: management groups, subscriptions, RBAC, Azure Policy, and landing zone security baselines.
  • Working knowledge of Microsoft Defender for Cloud, Microsoft Sentinel or another security information and event management (SIEM) platform, and Azure Policy.
  • Practical experience designing backup, recovery, and DR for ransomware scenarios, including immutability and isolated recovery.
  • Experience in regulated environments, ideally healthcare under HIPAA, and comfort working under a Business Associate Agreement (BAA).
  • Professional English fluency for live technical discussions with US stakeholders.
  • Consistent availability for one to two hours per business day with overlap during US Pacific business hours.
Preferred Qualifications
  • Palo Alto Networks experience, especially VM-Series firewalls and Prisma SD-WAN ION appliances running as virtual machines in Azure and hosted environments.
  • Azure VMware Solution, VMware NSX (including distributed firewall micro-segmentation), and VMware HCX experience.
  • Exposure to Epic or comparable EHR platforms and their connectivity and integration security patterns.
  • Experience working alongside or inside an MSSP, including log source onboarding and alert tuning.
  • Familiarity with the NIST Cybersecurity Framework (CSF) 2.0, the Microsoft cloud security benchmark, CIS Benchmarks, and the HHS 405(d) Health Industry Cybersecurity Practices (HICP).
  • Certifications such as Microsoft AZ-500 or SC-100, Palo Alto PCNSE, CISSP, CCSP, or HCISPP.
  • Bilingual English and Spanish; the team works comfortably in both.
Engagement Details
  • Engagement type: Hourly independent contract, starting on a trial basis with room to grow.
  • Time commitment: One to two hours per business day, flexible scheduling.
  • Start: As soon as possible, ideally the week of September 28, 2026.
  • Location: Remote, for candidates based in Mexico.
  • Languages: English required; Spanish a plus.
  • Compensation: Hourly rate commensurate with experience, as an independent contractor engaged through Nearshore Cyber.
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Azure Security Architect — Healthcare Cloud (Remote)
Azure Security Architect — Healthcare Cloud (Remote)

Nearshore Cyber • México

A distancia
MXN 1.466.000 - 2.933.000
Senior DevSecOps Engineer (Azure Experience) - Remote (Mexico)
Senior DevSecOps Engineer (Azure Experience) - Remote (Mexico)

Echelon Risk + Cyber • México

A distancia
MXN 900.000 - 1.700.000
Private medical insurance
Life insurance
30-day Christmas bonus
+6
Azure DevSecOps Engineer — Remote (Mexico)
Azure DevSecOps Engineer — Remote (Mexico)

Echelon Risk + Cyber • Ciudad de México

A distancia
MXN 900.000 - 1.700.000
Private medical insurance
Life insurance
30-day Christmas bonus
+6
Senior Associate – Cyber Operations (Incident Response)
Senior Associate – Cyber Operations (Incident Response)

EX Squared LATAM • Ciudad de México

Presencial
MXN 420.000 - 660.000
Meal/grocery vouchers
Savings fund
Vacation premium
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 • Santiago de Querétaro

Presencial
MXN 1.200.000 - 1.800.000
Biweekly Payment
IMSS
Christmas Bonus
+5
Azure Solution Architect | Remote
Azure Solution Architect | Remote

gsbsolutions1 • Ciudad de México

A distancia
MXN 1.654.000 - 2.238.000
Excellent superior benefits.
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 - Decode the future • Santiago de Querétaro

Presencial
MXN 700.000 - 1.100.000
Biweekly pay
IMSS
Christmas bonus
+6
Senior Cloud Engineer - Azure & GCP Architect (Remote)
Senior Cloud Engineer - Azure & GCP Architect (Remote)

Accendra Health • Ciudad de México

Híbrido
MXN 900.000 - 1.200.000
Medical, dental, and vision coverage
Paid time off plan
401(k) Plan
+6
Senior Azure Cloud Infrastructure & Security Engineer
Senior Azure Cloud Infrastructure & Security Engineer

Pyramid Consulting, Inc • México

Presencial
MXN 600.000 - 960.000
Global networks
Internal academies & mentorship
Well-being hub
Senior Risk Advisory Consultant - Remote (Mexico) Posted on Sep 09 / 2026
Senior Risk Advisory Consultant - Remote (Mexico) Posted on Sep 09 / 2026

Echelon Cyber • México

A distancia
MXN 1.200.000 - 1.600.000
Private medical insurance
Life insurance
30-day Christmas bonus
+7