Turn this role into an interview — a resume and cover letter built around what this employer wants.
Simply Source Outsourcing is seeking a Senior Azure cloud/DevSecOps specialist to design and operate the isolated Azure foundation for the External Exposure Scanner. You will build infrastructure as code, configure CI/CD pipelines, manage secrets, and implement robust observability and security controls.
The role emphasizes secure egress, cost monitoring, and deployment reliability across Azure services, with focus on guardrails, governance, and incident response in a production environment.
Build and operate the isolated Azure foundation for the External Exposure Scanner, including infrastructure as code, dedicated network egress, secrets/identity, CI/CD, observability, temporary storage, security controls, and deployment reliability.
Design and implement Azure scanner topology using approved services such as Container Apps, Service Bus, VNet, NAT Gateway, Managed Identity, Key Vault, Blob Storage, Azure Monitor, and Application Insights.
Provide dedicated static egress for scanning with no overlap with Guardare platform egress.
Build infrastructure as code, environment configuration, CI/CD pipelines, container registry controls, and deployment gates.
Implement secure secret management and credential-free service access where practical.
Configure encrypted temporary storage and lifecycle deletion according to approved retention policy.
Implement logging, metrics, tracing, alerts, dashboards, and operational observability for scan jobs and infrastructure.
Support SBOM/container scanning, pinned dependencies, image governance, and controlled release processes.
Implement network and runtime safeguards supporting blocked targets, concurrency controls, emergency stop, and incident response.
Monitor Azure cost observations and identify infrastructure efficiency opportunities without compromising security.
Senior Azure cloud/DevSecOps experience with networking, containers, identity, secrets, messaging, monitoring, and IaC.
Hands‑on knowledge of Azure VNet, NAT Gateway, Container Apps or Kubernetes/container runtimes, Service Bus, Key Vault, Managed Identity, Blob Storage, Monitor/Application Insights, or equivalents.
Strong CI/CD, Git, container security, infrastructure-as-code, and environment‑management skills.
Understanding of secure network egress, IP allowlisting, observability, encryption, retention, and least privilege.
Experience supporting security‑sensitive or externally exposed services.
Ability to troubleshoot production infrastructure and communicate operational risk clearly.