Senior Azure Security Architect – Remote in USA

Near Shore Cyber

United States

Remote

USD 131,000 - 152,000

Part time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Nearshore Cyber is seeking a senior security architect for a part-time, hourly engagement to design and secure a Microsoft Azure environment for a healthcare-focused MSP. You will own identity, infrastructure, networking, governance, logging, and monitoring across hybrid Azure/VMware environments.

The role emphasizes ransomware resilience, immutable backups, and alignment with HIPAA BAAs. Remote, US-based candidates with strong Azure expertise are encouraged to apply.

Qualifications

  • Seven+ years in information security, with 3+ years designing and hardening production Azure environments.
  • Azure network security design including hub-and-spoke, NSGs, private endpoints, ExpressRoute.
  • Experience with Azure governance: management groups, subscriptions, RBAC, Azure Policy, landing zone baselines.
  • Familiarity with Defender for Cloud, Sentinel or SIEM platforms and Azure Policy.
  • Backup, recovery, and DR design for ransomware, including immutability and isolated recovery.
  • Healthcare regulatory exposure (HIPAA) and BAAs; strong English for live discussions.
  • Availability for 1–2 hours overlap with US Pacific time.

Responsibilities

  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging, and monitoring.
  • Design Microsoft Entra ID, CA, PIM, and RBAC for least-privilege access.
  • Harden AVS, Azure VMs, and supporting services to baseline security.
  • Define segmentation and traffic controls across ExpressRoute, firewalls, and clinic connectivity.
  • Shape management group/subscription structure, security baselines, and policy assignments.
  • Define logging sources, retention, and detection coverage in Defender for Cloud and Sentinel or MSSP platform.
  • Advise on ransomware resilience with Azure as primary and hosted site as secondary; outline RPO/RTO and recovery testing.
  • Mentor delivery engineers to embed security into the build process.

Skills

Information security
Azure security design
English fluency
HIPAA/compliance
Time overlap with US Pacific

Education

Microsoft AZ-500
CISSP
CCSP
HCISPP

Tools

Azure Defender for Cloud
Microsoft Sentinel
Palo Alto VM-Series
VMware NSX
Azure ExpressRoute

Job description

Healthcare Cloud | Part-Time Hourly Contract | Remote
About the Engagement

A Microsoft-focused cloud services firm is seeking a senior security architect to join its delivery team on a part-time, hourly basis. The firm is the managed services provider (MSP) for a multi-clinic US healthcare organization and is leading the migration of the organization’s clinical and business applications to Microsoft Azure. The client places a strong emphasis on ransomware resilience, and a healthcare-focused managed security services provider (MSSP) is integrating the new environment into its monitoring service. The core need is a comprehensive security design for the Azure environment.

The Environment
  • A hybrid environment spanning a hosted VMware private cloud and Microsoft Azure, connected by two Azure ExpressRoute circuits.
  • Palo Alto Networks VM-Series firewalls and Prisma SD-WAN ION appliances deployed as native virtual machines at both sites.
  • An Azure VMware Solution (AVS) deployment receiving the full data center migration. Azure becomes the primary site and the hosted private cloud becomes the secondary site.
  • More than 40 clinician-facing and business applications in scope, including laboratory, dental, radiology, and IT systems.
  • A vendor-hosted electronic health record (EHR) platform, reached through vendor-specified, customer-managed connectivity hardware in a colocation facility, with integrations to the in-scope applications.
What You Will Do
  • Produce and own the security design for the Azure environment across identity, infrastructure, networking, governance, policies, access control, logging, and monitoring.
  • Identity and access control: design Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), and role-based access control (RBAC) for least-privilege administrator and third-party access.
  • Infrastructure: harden AVS, Azure virtual machines, and supporting services against recognized baselines, and review the live build as it progresses.
  • Networking: define segmentation and traffic flow controls across the ExpressRoute circuits, the Palo Alto firewalls and ION appliances, clinic and VPN connectivity, and internet egress.
  • Governance and policies: shape the management group and subscription structure, Azure Policy assignments, security baselines, and written security standards.
  • Logging and monitoring: define log sources, retention, and detection coverage in Microsoft Defender for Cloud and Microsoft Sentinel or the MSSP’s platform.
  • Advise on ransomware resilience with Azure as primary and the hosted site as secondary: immutable and isolated backups, recovery point and recovery time objectives (RPO and RTO), and recovery testing.
  • Join working sessions with the client’s MSSP, assess its requests, and recommend what telemetry Azure and the firewalls should provide.
  • Map controls to the HIPAA Security Rule and recognized frameworks, and document decisions clearly for the client, its insurer, and auditors.
  • Mentor the delivery engineers so security practice becomes part of how the team builds.
Required Qualifications
  • Seven or more years in information security, including at least three years designing and hardening Microsoft Azure environments in production.
  • Hands-on depth in Azure network security: hub-and-spoke design, Network Security Groups, private endpoints, ExpressRoute, route control, and firewall insertion.
  • Experience designing Azure governance: management groups, subscriptions, RBAC, Azure Policy, and landing zone security baselines.
  • Working knowledge of Microsoft Defender for Cloud, Microsoft Sentinel or another security information and event management (SIEM) platform, and Azure Policy.
  • Practical experience designing backup, recovery, and DR for ransomware scenarios, including immutability and isolated recovery.
  • Experience in regulated environments, ideally healthcare under HIPAA, and comfort working under a Business Associate Agreement (BAA).
  • Professional English fluency for live technical discussions with US stakeholders.
  • Consistent availability for one to two hours per business day with overlap during US Pacific business hours.
Preferred Qualifications
  • Palo Alto Networks experience, especially VM-Series firewalls and Prisma SD-WAN ION appliances running as virtual machines in Azure and hosted environments.
  • Azure VMware Solution, VMware NSX (including distributed firewall micro-segmentation), and VMware HCX experience.
  • Exposure to Epic or comparable EHR platforms and their connectivity and integration security patterns.
  • Experience working alongside or inside an MSSP, including log source onboarding and alert tuning.
  • Familiarity with the NIST Cybersecurity Framework (CSF) 2.0, the Microsoft cloud security benchmark, CIS Benchmarks, and the HHS 405(d) Health Industry Cybersecurity Practices (HICP).
  • Certifications such as Microsoft AZ-500 or SC-100, Palo Alto PCNSE, CISSP, CCSP, or HCISPP.
  • Bilingual English and Spanish; the team works comfortably in both.
Engagement Details
  • Engagement type: Hourly independent contract, starting on a trial basis with room to grow.
  • Time commitment: One to two hours per business day, flexible scheduling.
  • Start: As soon as possible, ideally the week of September 28, 2026.
  • Location: Remote, for candidates based in the United States and already authorized to work here.
  • Languages: English required; Spanish a plus.
  • Compensation: $95 to $110 per hour, depending on experience, on a 1099 or corp-to-corp (C2C) basis, engaged through Nearshore Cyber. No benefits are provided.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Azure Security Architect - Remote in USA
Senior Azure Security Architect - Remote in USA

Near Shore Cyber • United States

Remote
USD 131,000 - 152,000
Senior Azure Security Architect - Remote in USA
Senior Azure Security Architect - Remote in USA

Nearshore Cyber • Northern (KY)

Hybrid
USD 131,000 - 152,000
Remote Part-Time Senior Azure Security Architect
Remote Part-Time Senior Azure Security Architect

Near Shore Cyber • United States

Remote
USD 131,000 - 152,000
Azure Security Architect — Healthcare, Remote, Part-Time
Azure Security Architect — Healthcare, Remote, Part-Time

Near Shore Cyber • United States

Remote
USD 131,000 - 152,000
Remote Azure Security Architect — Healthcare Compliance
Remote Azure Security Architect — Healthcare Compliance

Nearshore Cyber • Northern (KY)

Hybrid
USD 131,000 - 152,000
Azure Security Consultant
Azure Security Consultant

Randstad Digital Americas • Conyers (GA)

On-site
USD 75,768 - 84,033
Comprehensive benefits package
401(k) plan (based on eligibility)
Medical, dental, and vision insurance
Security Engineer II – Hybrid Cloud
Security Engineer II – Hybrid Cloud

Patient First • Glen Allen (VA)

On-site
USD 125,000 - 150,000
Health, Dental and Vision insurance
Disability, Life and Long Term care
401(k) Retirement Plan with employer  
+4
Cloud Security Architect
Cloud Security Architect

TalentRemedy • Washington

On-site
USD 150,000 - 170,000
Azure System Engineer
Azure System Engineer

FTS, Inc. • Marietta (GA)

On-site
USD 85,000 - 125,000
CyberSecurity Solutions Architect - Azure
CyberSecurity Solutions Architect - Azure

Prestige Staffing • New York (NY)

Hybrid
USD 124,000 - 138,000