Lead DevSecOps / Azure Architect

Reposted 24 Days Ago
Be an Early Applicant
Johannesburg, City of Johannesburg, Gauteng, ZAF
In-Office
Senior level
Information Technology • Pet • Professional Services
The Role
Lead design and implement secure, scalable Azure architectures and migrations. Drive DevSecOps across CI/CD with IaC (Bicep/ARM/Terraform), integrate SAST/DAST and pipeline security, configure API gateway and identity (Azure APIM, Azure AD), and implement monitoring, disaster recovery, and governance.
Summary Generated by Built In

We are seeking a highly skilled DevSecOps / Azure Architect to lead the design, implementation, and governance of secure cloud-native architectures on Microsoft Azure. The role will be instrumental in driving secure DevOps practices, infrastructure automation, and enterprise-grade API platform modernization (including Azure API Management).

The ideal candidate will combine deep Azure architecture expertise with strong DevSecOps practices, ensuring scalability, resilience, and security by design.



Requirements

Key Responsibilities

Azure Architecture & Cloud Design

  • Design secure, scalable, and high-availability Azure architectures.
  • Lead cloud migration initiatives (on-prem / legacy platform → Azure).
  • Architect solutions using Azure APIM, App Services, Functions, AKS, Service Bus, and related services.
  • Implement multi-region and disaster recovery strategies.
  • Define landing zones and governance models aligned with enterprise standards.

DevSecOps Implementation

  • Implement DevSecOps practices across CI/CD pipelines.
  • Integrate security controls into build and deployment workflows.
  • Automate infrastructure using Infrastructure as Code (Bicep / ARM / Terraform).
  • Embed security scanning tools (SAST, DAST, container scanning, dependency checks).
  • Implement secure release management and environment promotion strategies.

Security Architecture & Compliance

  • Design zero-trust architecture patterns.
  • Implement secure API gateway configurations (Azure APIM policies).
  • Configure OAuth2, OpenID Connect, Azure AD (Entra ID).
  • Ensure compliance with OWASP API Security Top 10.
  • Manage certificate lifecycle, mTLS, and key vault integration.
  • Define cloud security posture management practices.

Automation & CI/CD

  • Architect CI/CD pipelines using Azure DevOps or GitHub Actions.
  • Implement blue-green / canary deployment strategies.
  • Enable automated policy validation for APIs.
  • Design pipeline governance and approval gates.

Monitoring & Observability

  • Implement Azure Monitor, Log Analytics, Application Insights, ELK, Prometheus and Grafana
  • Define logging, tracing, and alerting strategies.
  • Enable proactive anomaly detection and SLA monitoring.

Technical Skills – Mandatory

Azure Expertise

  • Azure APIM (architecture & policy configuration)
  • Azure AD / Entra ID
  • Azure App Services / Functions
  • AKS (preferred)
  • Azure Key Vault
  • Azure Networking (VNet, NSG, Private Endpoints)

Security & DevSecOps

  • DevSecOps implementation experience
  • CI/CD pipeline security
  • SAST/DAST tools integration
  • Identity & access management
  • Secure coding practices
  • API security frameworks

Automation

  • Azure DevOps / GitHub Actions
  • Infrastructure as Code (Bicep / ARM / Terraform)
  • YAML pipelines
  • Containerization (Docker, Kubernetes preferred)

 

Key Responsibilities

Azure Architecture & Cloud Design

 

Design secure, scalable, and high-availability Azure architectures.

 

Lead cloud migration initiatives (on-prem / legacy platform → Azure).

 

Architect solutions using Azure APIM, App Services, Functions, AKS, Service Bus, and related services.

 

Implement multi-region and disaster recovery strategies.

 

Define landing zones and governance models aligned with enterprise standards.

 

DevSecOps Implementation

 

Implement DevSecOps practices across CI/CD pipelines.

 

Integrate security controls into build and deployment workflows.

 

Automate infrastructure using Infrastructure as Code (Bicep / ARM / Terraform).

 

Embed security scanning tools (SAST, DAST, container scanning, dependency checks).

 

Implement secure release management and environment promotion strategies.

 

Security Architecture & Compliance

 

Design zero-trust architecture patterns.

 

Implement secure API gateway configurations (Azure APIM policies).

 

Configure OAuth2, OpenID Connect, Azure AD (Entra ID).

 

Ensure compliance with OWASP API Security Top 10.

 

Manage certificate lifecycle, mTLS, and key vault integration.

 

Define cloud security posture management practices.

 

Automation & CI/CD

 

Architect CI/CD pipelines using Azure DevOps or GitHub Actions.

 

Implement blue-green / canary deployment strategies.

 

Enable automated policy validation for APIs.

 

Design pipeline governance and approval gates.

 

Monitoring & Observability

 

Implement Azure Monitor, Log Analytics, Application Insights.

 

Define logging, tracing, and alerting strategies.

 

Enable proactive anomaly detection and SLA monitoring.

 

Technical Skills – Mandatory

Azure Expertise

 

Azure APIM (architecture & policy configuration)

 

Azure AD / Entra ID

 

Azure App Services / Functions

 

AKS (preferred)

 

Azure Key Vault

 

Azure Networking (VNet, NSG, Private Endpoints)

 

Security & DevSecOps

 

DevSecOps implementation experience

 

CI/CD pipeline security

 

SAST/DAST tools integration

 

Identity & access management

 

Secure coding practices

 

API security frameworks

 

Automation

 

Azure DevOps / GitHub Actions

 

Infrastructure as Code (Bicep / ARM / Terraform)

 

YAML pipelines

 

Containerization (Docker, Kubernetes preferred)

 



Skills Required

  • Azure API Management (APIM) architecture and policy configuration
  • Azure AD / Entra ID configuration and OAuth2 / OpenID Connect
  • Design and implement Azure App Services and Functions
  • AKS experience
  • Azure Key Vault and certificate/key lifecycle management, mTLS
  • Azure networking (VNet, NSG, Private Endpoints)
  • DevSecOps implementation across CI/CD pipelines
  • CI/CD pipeline security and pipeline governance (Azure DevOps or GitHub Actions)
  • SAST/DAST tools integration and container scanning/dependency checks
  • Infrastructure as Code using Bicep, ARM, or Terraform
  • YAML pipeline authoring and automated release strategies (blue-green/canary)
  • Containerization (Docker); Kubernetes experience preferred
  • Design zero-trust architecture and ensure OWASP API Security compliance
  • Monitoring and observability with Azure Monitor, Log Analytics, Application Insights, ELK, Prometheus, Grafana
  • Experience defining landing zones, governance, and multi-region DR strategies
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
22 Employees
Year Founded: 2013

What We Do

Blue Pearl is a market-leading CLOUD Solutions developer with extensive knowledge and insight into the latest technologies, standardised processes, advanced technical capabilities and consulting processes available, ensuring wholistic success for our clientele. We offer professional consulting to compliment your business strategy and overall management and make it our priority to add value to any business by listening, analysing and creating a conducive solution that will empower our client. We implement a Data Analysis Process that includes inspecting, cleansing, transforming, and modelling data with the end-goal of discovering useful information, informing conclusions, and relevant information to support your decision-making. Your business cannot afford not to engage with us, allowing our data analysis to play a role in making your business decisions more scientific and helping your business achieve effective operation. Blue Pearl’s team of experts include BI strategists, BI analysts, Data Warehouse Architects, Data Scientists, Implementation and Development experts. With the use of BI, Analytics and Big Data, we effectively partner with our customers on their mission to achieve a competitive business advantage and real ROI from the structured information we collect.

Similar Jobs

In-Office
Johannesburg, City of Johannesburg, Gauteng, ZAF
3386 Employees

TransUnion Logo TransUnion

Bilingual Consumer Admin II L

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
2 Locations
13000 Employees

TransUnion Logo TransUnion

Bilingual Consumer Admin II E

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
2 Locations
13000 Employees

TransUnion Logo TransUnion

Human Resources Business Partner

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Remote or Hybrid
Johannesburg, Gauteng, ZAF
13000 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account