31 Jul
|
BrightClaim
|
Gurugram
31 Jul
BrightClaim
Gurugram
Manager - Cloud Technologies S
Ready to turn bold ideas into real-world impact?
At Genpact, we don’t just adapt to change, we lead it. AI and digital innovation are transforming the way businesses work, and we’re at the forefront of it. Genpact’s AI Gigafactory, our industry-first accelerator, exemplifies how we scale advanced technology solutions to help global enterprises work smarter, grow faster, and transform at scale.
Whether tackling complex challenges through large-scale models or agentic AI, our breakthrough solutions tackle companies’ most complex challenges. If you thrive in a fast-moving, innovation-driven environment, love building and deploying cutting-edge AI solutions, and want to push the boundaries of what’s possible, this is your moment. Genpact (NYSE: G) is an agentic and advanced technology solutions company.
We leverage process intelligence and artificial intelligence to deliver measurable outcomes. With a strong partner ecosystem and decades of client trust, we provide innovative solutions that transform how businesses run. Powered by a team with an active learning mindset and client centricity at its core, we deliver lasting value for the world’s leading enterprises.
Get to know us at genpact.com and on LinkedIn, YouTube, X, and Facebook.
Key Responsibilities
Bring-Your-Own Storage (BYOS) Management
Own the complete lifecycle and security posture of NH2030-supplied Azure Storage Accounts registered as Unity Catalog external locations in ADP Databricks
Configure storage firewall rules, Private Endpoints, and IP allowlists for BYOS storage accounts
Set up and manage geo-replication and failover decisions for BYOS storage
Enable and configure Defender for Storage on all BYOS accounts
Manage Customer-Managed Keys (CMK) for BYOS storage encryption
Configure container-level ACLs, SAS token policies, and key rotation schedules
Enable immutability (WORM) locks and resource locks on BYOS storage containers as required by data classification
Enable and manage Malware Scanning on BYOS storage accounts
Own BYOS storage cost management, capacity planning, Azure Monitor alerts, and operational runbooks
Key Vault & Secret Management
Coordinate with AzTech for provisioning of ADP-managed Key Vaults (minimum 1 per OE per stage)
Configure Databricks KV-backed secret scopes using the provisioned Key Vaults
Store and manage initial secrets required for storage access, external service connections, and API keys
Implement and enforce secret rotation policies; ensure no credentials are stored in notebooks or code
Configure Key Vault access policies and RBAC for the NH2030 Service Principals and team members
Manage BYOS-specific Key Vault for CMK: RSA 4096, automated rotation, purge protection
Service Principal (SP) Lifecycle – Entra ID
Create Service Principals in Entra ID (via GIAM) for CI/CD pipelines, automated jobs, data ingestion, and integration services
Coordinate GIAM group membership for SPs (currently limited by SCIM sync; follow Automatic Identity Management roadmap)
Support IAM Specialist in registering SPs in the Databricks account and assigning to workspace groups
Generate and securely store SP credentials in KV-backed secret scopes for CI/CD pipeline use
Monitor SP access and rotate credentials on schedule; immediately revoke on programme offboarding
Private Endpoint & Network Connectivity
Identify and document all private endpoint requirements for NH2030 workloads (BYOS storage, Key Vault, external services)
Raise requests with ADP Platform Team (AzTech)
for additional private endpoints beyond default transitional zone connectivity
Prepare and submit FQDN whitelisting requests via ServiceNow for both classic compute (to FCP firewall) and serverless compute (to ADP network policies)
Identify all egress FQDNs required by NH2030 workloads: external APIs, data sources, PyPI/Nexus, container registries
Validate private connectivity is functioning correctly post-provisioning for all required endpoints
BYOS Backup & Disaster Recovery
Enable soft delete and blob versioning on all BYOS storage accounts
Provision and configure Azure Backup Vault for BYOS storage backup
Define and implement retention policies per NH2030 data retention and regulatory requirements
Document and test restore procedures for BYOS storage accounts
Contribute to the NH2030 DR runbook for BYOS storage failover and recovery
Infrastructure Planning & Request Coordination
Document Key Vault and storage account requirements upfront (number of vaults per stage, ADP-managed vs BYOS breakdown)
Confirm environment naming and tagging conventions with ADP Platform Team prior to SNOW request submission
Monitor SNOW tickets for AzTech provisioning completion (subscription, VNET, storage, workspace)
Act as technical interface for infrastructure queries during ADP/SPM review of SNOW provisioning requests
ADP-Specific Activities (from Operational Responsibility Matrix)
Primary Activities
Supporting Activities
BYOS storage security controls (Defender, CMK, ACLs, SAS, WORM) – P5-07
BYOS storage network config (firewall, PEs, geo-replication) – P6-04
BYOS backup and retention configuration – P8-03
Key Vault-backed secret scope configuration – P4-07
Service Principal creation in Entra ID – P3-03
FQDN whitelisting requests (Classic & Serverless) – P5-02
Environment naming and tagging convention – P0-04
Key Vault and storage requirements documentation – P0-05
SNOW infrastructure provisioning monitoring – P2-01, P2-02, P2-03
Private endpoint requests and validation – P2-01
BYOS integration with Unity Catalog (external location) – P6-04
DR runbook contribution for BYOS storage – P8-03, P8-04
Required Skills & Experience
Core Technical Skills
Supporting Skills
3+ years Azure cloud engineering in enterprise environments
Azure Storage (ADLS Gen2): lifecycle, networking, firewall, geo-replication
Azure Key Vault: RBAC, secret management, CMK, key rotation, purge protection
Azure Private Endpoints, Private DNS Zones, VNet integration
Entra ID (Azure AD): Service Principal creation, GIAM interaction, PIM
Azure Defender for Storage and Malware Scanning configuration
WORM/immutability policies and resource locks for compliance
Databricks Access Connectors and Unity Catalog external locations
Azure networking fundamentals: VNet, NSG, UDR, peering, DNS
RBAC design on Azure resources (Storage Blob Data Reader/Contributor, Key Vault roles)
ServiceNow for infrastructure request management
Azure Monitor alerts and operational runbook development
Terraform (advantageous – ADP team uses for infrastructure deployment)
Azure Backup Vault and storage-level disaster recovery
Understanding of Azure Firewall FQDN allowlisting processes
Experience working in regulated financial services environments
Certifications
AZ-104 Microsoft Azure Administrator (required)
AZ-305 Microsoft Azure Solutions Architect Expert (desirable)
SC-300 Microsoft Identity and Access Administrator (desirable)
AZ-500 Microsoft Azure Security Technologies (desirable)
Key Interfaces
ADP Platform Team (AzTech): SNOW requests, BYOS external location registration, Private Endpoint provisioning, FQDN firewall rules
FCP (Allianz Networking): Private DNS zones, hub routing for BYOS in FCP-connected subscriptions
GIAM Team: Service Principal creation in Entra ID, group membership coordination
Lead Databricks Platform Engineer: Secret scope setup, BYOS integration in Unity Catalog, SP workspace assignment
Security / DevSecOps Engineer: BYOS security controls alignment, CMK configuration, Defender for Storage
Qualifications
Bachelors - Cloud Computing, Bachelors - Computer Science, Bachelors - Information Technology, Bachelors - Network Engineering, Masters - Computer Science
Certifications
AWS Certified Solutions Architect - Professional - Amazon Web Services (AWS)Amazon Web Services (AWS), Certified Information Security Manager (CISM) - ISACA – Information Systems Audit and Control AssociationISACA – Information Systems Audit and Control Association, Certified Information Systems Security Professional (CISSP) - Workforce Academy OnlineWorkforce Academy Online, Red Hat Certified Engineer (RHCE) - Red HatRed Hat
Required Skills
Agile Methodology, Change Management, Client Relations, Cloud Computing, Collaboration Tools, Design Thinking, Executive Presence, Inclusion, Information Technology (IT) Infrastructure, IT Service Management (ITSM), Modernizing Operations, People Leadership, Personal Effectiveness, Risk Management, Storytelling
Language
English (Required), English (Required)
Language Proficiency - Advanced - C1
Additional Job Location - Job Type
Regular
Master Skill List - Cloud Technologies S
Remote Type - Hybrid
Work Shift - Flex Time (India)
Why join Genpact?
- Lead AI-powered transformation – Drive innovation and solve real-world business challenges that matter
- Make an impact – Help global enterprises solve business challenges that matter • Accelerate your career – Gain hands-on experience, mentorship, and world-class learning opportunities to stay ahead
- Work with the best – Join 140,000+ bold thinkers and problem-solvers who push boundaries every day • Thrive in a values-driven culture – Our courage, curiosity, and incisiveness - built on a foundation of integrity and inclusion - allow your ideas to fuel progress Come join the 140,000+ coders, tech shapers, and growth makers at Genpact and take your career in the only direction that matters: Up. Let’s build tomorrow together. Genpact is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, religion or belief, sex, age, national origin, citizenship status, marital status, military/veteran status, genetic information, sexual orientation, gender identity, physical or mental disability or any other characteristic protected by applicable laws. Genpact is committed to creating a agile work environment that values respect and integrity, customer focus, and innovation. Furthermore, please do note that Genpact does not charge fees to process job applications and applicants are not required to pay to participate in our hiring process in any other way. Examples of such scams include purchasing a 'starter kit,' paying to apply, or purchasing equipment or training.
📌 Manager - Cloud Technologies S 4D (Gurugram)
🏢 BrightClaim
📍 Gurugram