1

Azure Devsecops Jobs in Pennsylvania (NOW HIRING)

... DevSecOps, or product security experience * Strong experience in threat modeling, security architecture, and cloud-native technologies * Expertise in AWS, Azure, Kubernetes, CI/CD security, and ...

... AWS, Azure, onprem) Certifications • CompTIA Security+ (or DoD 8570 IAT Level 2 equivalent) preferred • AWS certification nice to have but not required • Kubernetes or Linux certifications ...

Cloud Security Engineer

Malvern, PA · On-site

$54.75 - $73/hr

Cloud engineering devsecops which will include design, implementation, and managing cloud ... AWS, Azure, GCP * Bug Tracking Tools Atlassian JIRA, ServiceNow * Operating Systems LINUX (RHEL 6 ...

... AWS, Azure, on-prem) Certifications • CompTIA Security+ (or DoD 8570 IAT Level 2 equivalent) preferred • AWS certification nice to have but not required • Kubernetes or Linux certifications ...

... AWS, Azure, on-prem) Certifications • CompTIA Security+ (or DoD 8570 IAT Level 2 equivalent) preferred • AWS certification nice to have but not required • Kubernetes or Linux certifications ...

Showing results 21-40

Azure Devsecops information

What are the roles and responsibilities of an Azure DevSecOps engineer?

Azure DevSecOps professionals are responsible for integrating security practices into the DevOps process on Microsoft Azure. Their key tasks include automating security checks, managing secure code deployments, configuring security policies, and monitoring systems for vulnerabilities. They collaborate closely with development, operations, and security teams to ensure applications are secure throughout the entire lifecycle. Azure DevSecOps engineers also use tools like Azure Security Center, Azure Policy, and Azure DevOps pipelines to enforce compliance and security standards.

What skills and qualifications are needed to thrive as an Azure DevSecOps engineer?

To thrive as an Azure DevSecOps Engineer, you need expertise in cloud computing, software development, security best practices, and experience with Microsoft Azure services, often supported by certifications like Microsoft Certified: Azure DevOps Engineer Expert. Familiarity with tools such as Azure DevOps, Terraform, CI/CD pipelines, and security scanning tools is typically required. Strong problem-solving, collaboration, and communication skills help professionals navigate complex environments and work effectively across teams. These competencies are crucial for building secure, scalable solutions and ensuring rapid, reliable software delivery in a cloud-first world.

What are common challenges faced by Azure DevSecOps professionals when integrating security into the CI/CD pipeline?

Azure DevSecOps professionals often encounter challenges such as ensuring consistent security policies across various development teams, automating security checks without slowing down deployments, and keeping up with evolving cloud security threats. Balancing the need for rapid delivery with comprehensive security testing can be tricky, especially when integrating tools like Azure Security Center, Azure Policy, and third-party solutions. Effective collaboration with development, operations, and security teams is crucial to address vulnerabilities early and foster a security-first culture throughout the software lifecycle.

What is the difference between Azure Devsecops vs Azure Security Engineer?

AspectAzure DevsecopsAzure Security Engineer
Primary FocusIntegrating security into DevOps processes, automation, and CI/CD pipelinesImplementing security measures, monitoring, and managing security in Azure environments
CertificationsAzure DevOps, Security certifications, Azure certificationsAzure Security Engineer Associate, CompTIA Security+
Work EnvironmentDevOps teams, development pipelines, automation toolsSecurity operations, incident response, Azure security tools
Industry UsageDevOps-focused organizations adopting security practicesOrganizations prioritizing security management in Azure

Azure Devsecops focuses on embedding security into the development and deployment process, emphasizing automation and integration within DevOps workflows. In contrast, Azure Security Engineers primarily manage and implement security measures, monitor security posture, and respond to threats within Azure environments. Both roles require overlapping certifications and work closely in organizations aiming for secure, efficient cloud operations.

What cities in Pennsylvania are hiring for Azure Devsecops jobs?

Cities in Pennsylvania with the most Azure Devsecops job openings:

Lead Security Engineer - 26-10666

Compu-Vision - IT

Philadelphia, PA • Hybrid

$30/hr

Full-time

Posted 4 days ago


Job description

Lead Security Engineer

Duration: 2 Months
Location: New York, NY
Work Arrangement: Hybrid – 3 Days Onsite / 2 Days Remote per Week

Job Description

The Lead Security Engineer will be responsible for implementing, configuring, validating, and documenting security controls across Azure and SaaS environments. The role will focus on identity and access management, vulnerability management, security monitoring, cloud security architecture, and security tooling.

Security Engineering & Implementation
  • Implement and configure security controls within Azure and SaaS environments.
  • Configure identity, access management, and role-based access controls (RBAC).
  • Implement encryption, logging, monitoring, and audit controls.
  • Review and validate secure configurations across Azure networking, compute, storage, and application services.
  • Ensure security configurations meet established organizational standards.
Identity & Access Management
  • Configure and validate SSO, MFA, and Active Directory/Azure AD integrations.
  • Implement role-based access models and least-privilege access controls.
  • Configure privileged access workflows and administrative access controls.
  • Support user provisioning and access lifecycle management.
  • Perform access validation testing and remediate identity-related issues.
Vulnerability Management & Security Operations
  • Configure and operate vulnerability scanning and assessment tools.
  • Review vulnerability scan results and coordinate remediation with infrastructure and application teams.
  • Configure and validate security logging, alerting, and dashboards.
  • Configure SIEM, monitoring, and alerting rules.
  • Track security findings and validate remediation and closure of vulnerabilities and misconfigurations.
Security Architecture Implementation
  • Participate in technical implementation and security design sessions.
  • Review and validate security architecture for cloud, SaaS, APIs, and integrations.
  • Apply security-by-design principles throughout development and deployment.
  • Validate secure network architecture, including:
    • Network segmentation
    • Private endpoints
    • Firewalls
    • Secure connectivity
  • Review vendor security configurations and ensure alignment with approved security requirements.
Security Tooling & Platform Configuration
  • Configure security tools across cloud and enterprise environments.
  • Implement endpoint protection, monitoring, and vulnerability management solutions.
  • Configure logging, alerting, and security telemetry collection.
  • Work with Log Analytics and SIEM platforms.
  • Integrate and configure Microsoft security technologies, including:
    • Microsoft Defender
    • Microsoft Sentinel
    • Microsoft 365 Security
  • Configure security alerts and monitoring rules.
Technical Documentation
  • Create and maintain as-built security documentation.
  • Document security configurations, implementation activities, and operational procedures.
  • Maintain security configuration baselines and technical documentation.
Deliverables
  • Configured SSO, MFA, RBAC, and IAM controls.
  • Security monitoring, logging, and alerting configurations.
  • Security configuration baselines for Azure and integrated SaaS environments.
  • Security readiness assessment and go-live validation documentation.
  • Comprehensive security configuration and as-built documentation.
Mandatory Skills & Experience

5+ years of experience in the following areas:

  • Azure Security, including:
    • Microsoft Defender for Cloud
    • Microsoft Sentinel
    • Security baselines
  • Identity & Access Management, including:
    • Azure AD / Microsoft Entra ID
    • SSO
    • MFA
    • RBAC
    • PAM
  • Vulnerability Management using tools such as:
    • Rapid7
    • Qualys
    • Equivalent enterprise vulnerability management platforms
  • SIEM and Log Analytics, including:
    • Microsoft Sentinel
    • Log Analytics Workspace
  • Cloud Security Architecture, including:
    • Azure networking
    • Private endpoints
    • Network segmentation
    • Firewalls
  • Security Tooling, including:
    • CrowdStrike
    • Microsoft 365 Security Stack
    • Cisco security technologies
  • Incident Response & Security Operations, including:
    • SOC processes
    • Security triage
    • Escalation
    • Security incident investigation
  • DevSecOps and secure CI/CD integration.
  • Experience with Azure DevOps and CI/CD pipelines.
  • Encryption and Key Management, including Azure Key Vault and data protection controls.
  • Strong hands-on implementation, troubleshooting, and security engineering experience in cloud environments.
Core Skills
  • Azure Security
  • Microsoft Defender for Cloud
  • Microsoft Sentinel
  • Azure AD / Microsoft Entra ID
  • SSO / MFA / RBAC / PAM
  • Vulnerability Management
  • Rapid7 / Qualys
  • SIEM / SOC
  • Log Analytics
  • Azure Networking
  • Private Endpoints
  • Network Segmentation
  • CrowdStrike
  • Microsoft 365 Security
  • Cisco Security
  • Incident Response
  • DevSecOps
  • Azure DevOps / CI/CD
  • Encryption / Key Management
  • Azure Key Vault
  • Cloud Security Architecture
  • Security Monitoring & Alerting
  • Security Documentation