Job ID: NC-809185 (915090828)

Hybrid/Local NCDMV Azure Security Architect (15+) with NIST 800 53/800 171, PCI DSS, FIPS, Key Vault, Monitor, Log Analytics, DNS, PKI, IAM, Cloudflare, Palo Alto, ARM/Bicep, Terraform, GitHub/DevOps experience

Location: Raleigh, NC (NCDOT)
Duration: 12 Months
The candidate will need to come on-site on the first day to collect equipment.
All candidates must be local to the Triangle region of North Carolina.
This position may require on-site attendance when business needs warrantin-person participation, such as scheduled meetings or other task-specific activities.

Skills:
Design and maintain secure Azure architectures across identity, networking, data protection, logging/monitoring, and governance.    Required    5     Years
Develop and enforce Azure security standards, policies, and reference architectures aligned to organizational and regulatory requirements.      Required    5     Years
Lead threat modeling, risk assessments, and security reviews for the Azure cloud environment and NCDMV Modernization efforts. Required    5     Years
Provide expert guidance on Azure-native security tooling (e.g., Defender for Cloud, Sentinel, Azure Policy, Key Vault, Monitor, Log Analytics)  Required    5     Years
Deep expertise with Azure security services     Required    5     Years
Strong understanding of cloud networking security: Zero Trust, routing, segmentation, firewalls, DNS, PKI, IAM, and secure landing zone architectures.      Required    5     Years
Knowledge of compliance frameworks and mapping security controls (NIST 800 53, NIST 800 171, PCI DSS, FIPS, state security standards).    Required    5     Years
Experience designing and evaluating secure multi tenant architectures and enterprise governance models in Microsoft Azure.    Required    5     Years
Expertise integrating third party solutions (Cloudflare, Palo Alto, etc.) with Azure security and monitoring.     Required    5     Years
Proficiency with automation and IaC: ARM/Bicep, Terraform, GitHub/Azure DevOps pipelines, and policy as code.     Required    5     Years
Ability to translate security requirements into actionable architectural and technical guidance and configurations.     Required    5     Years
Strong documentation skills for security standards, baselines, and system security plans. Required    5     Years
Experience and strong skills in identifying options for security assessments of the Azure environment and producing detailed and executive summary sec      Required    5     Years

Supplemental Staffing is needed to support the NCDOT Microsoft Azure cloud tenant build and configuration, specifically focusing on security compliance design, implementation, operations, and assessment.
The role is for a Cloud Security Architect – Expert that will support the ongoing NCDOT DMV Modernization Microsoft Azure cloud infrastructure build, security compliance design, security compliance configuration, and security compliance assessment and reporting.
The primary focus is to lead NCDIT-T in security architecture, configuration, operations, and compliance assessment of the environment and be a bridge between NCDIT, NCDOT DMV, and vendors in delivery of a Microsoft Azure cloud environment that meets security regulatory, organizational, industry security compliance requirements and compliance reporting, balanced with functional requirements.
The complexity of these responsibilities are essential to NCDIT-T to support the build of the Azure tenant so that NCDOT DMV systems can be placed in the cloud securely and meet compliance requirements. NCDIT-T and NCDOT DMV have an aggressive schedule to complete NCDOT DMV modernization efforts.

NC-809185-SM.docx

NC-RTR-809185.docx

Hybrid/Local NCDMV Azure Security Architect (15+) with NIST 800 53/800 171, PCI DSS, FIPS, Key Vault, Monitor, Log Analytics, DNS, PKI, IAM, Cloudflare, Palo Alto, ARM/Bicep, Terraform, GitHub/DevOps experience

Leave a Reply

Your email address will not be published. Required fields are marked *

Discover more from innoSoul

Subscribe now to keep reading and get access to the full archive.

Continue reading