Zuven Tech
Please find the JD
Senior DevOps Engineer/Architect
Chicago, IL (Locals only)
only H4 EAD, USC, TN, E3, L2
Required Education
• Degree in Computer Science, Information Management, or related field 
Preferred Certifications (Nice to Have)
• Azure Security Engineer Associate
• AWS Certified Security – Specialty
• CISSP, CCSP
Required Skills
• 5+ years building production workloads on Azure with event-driven and API-first architectures.
• Strong APIM experience: policies (inbound/outbound XML), backends, named values, developer portal, versioning.
• Experience implementing immutable/append-only storage patterns (WORM blob policies, Cosmos DB change feed auditing, or equivalent).
• Deploy and manage NoSQL and CosmosDB databases.
• Familiarity with envelope encryption patterns using Key Vault (CMK, key rotation, purge protection).
• Understanding of zero-trust network design: Private Endpoints, VNet integration, NSG/UDR patterns.
• Solid Terraform skills: modules, remote state, Azure Provider, CI/CD integration via GitHub Actions or Azure DevOps.
• Strong coding experience in Python and Node.js.
• Hands-on proficiency with integrated testing tools.
• Ability to write KQL for operational queries, alerting rules, and audit log analysis.
• Experience integrating with third-party tool APIs (GRC platforms, vulnerability scanners, ticketing systems, or similar).
Soft Skills
• Effective written and verbal communication skills to collaborate with cross-functional teams.
We are building a cloud-native immutable evidencing platform to ingest compliance artifacts, audit evidence, and control attestations from a wide range of internal tools via API, store them with cryptographic integrity guarantees, and expose querying and retrieval capabilities to downstream GRC and audit workflows. The contractor will help design, build, and harden this platform on Azure in alignment with PCI-DSS, SOX, and GLBA requirements.
Key Responsibilities:
• Design and implement API ingestion pipelines via Azure API Management (APIM) with OAuth2/JWT validation, rate limiting, and schema enforcement.
• Build event-driven ingestion workflows using Azure Service Bus and Azure Functions (durable, fan-out patterns).
• Implement immutable artifact storage using Azure Blob Storage with WORM policies (time-based retention locks) and Azure Cosmos DB for tamper-evident metadata indexing.
• Architect Redis Cache for high-throughput query caching while preserving source-of-truth immutability guarantees.
• Integrate Azure Key Vault for envelope encryption of stored artifacts (customer-managed keys, automated rotation).
• Build Log Analytics Workspace telemetry pipelines covering ingestion events, access audit trails, and integrity verification logs.
• Write Terraform IaC for all infrastructure — no click-ops; all resources policy-as-code compliant.
• Implement third-party tool integrations (connector APIs) to ingest evidence artifacts from source systems.
To apply for this job email your details to gopi@zuventech.com