02 Aug
|
Zorba consulting
|
Bengaluru
02 Aug
Zorba consulting
Bengaluru
Role Overview
- We are seeking a hands-on Cloud Security Architect with proven engineering experience securing workloads directly in Microsoft Azure and Google Cloud Platform (GCP).
- This is not a traditional cybersecurity governance role
- we need someone who configures security controls, troubleshoots cloud-native security tooling, and builds secure infrastructure daily.
- You will design, implement, and operate security across enterprise-scale Azure and GCP environments, working shoulder-to-shoulder with platform engineering, DevOps, and product teams in a fast-paced, agile environment.
- Important: This role requires equal, demonstrable hands-on experience in both Azure and GCP.
- Candidates must be able to navigate both cloud consoles, configure security services, write infrastructure-as-code, and respond to security findings without relying on other teams for implementation.
- Key Responsibilities Hands-On Cloud Security Engineering Configure and manage Microsoft Defender for Cloud (Defender for Servers, Containers, Storage, Key Vault, DNS, Resource Manager)
- including policy assignments, adaptive controls, and alert remediation.
- Operate and tune Azure Firewall, NSGs, Azure WAF, and Private Link/Private Endpoints.
- Manage Azure Key Vault access policies, certificate rotation, and integration with workloads.
- Configure Azure AD/Entra ID Conditional Access, PIM, workload identities, and service principal hardening.
- Administer Google Security Command Center (SCC)
- triage findings, configure Security Health Analytics, Event Threat Detection, and Container Threat Detection.
- Design and secure GCP VPC architectures including firewall rules, VPC Service Controls, Private Google Access, and Shared VPC configurations.
- Secure BigQuery environments
- column/row-level security, authorized views, data masking, VPC Service Controls perimeters.
- Harden Cloud Run deployments
- ingress controls, service identity, Binary Authorization, and secret management.
- Implement and govern GCP IAM
- custom roles, organization policies, workload identity federation, and service account key elimination.
- Architecture & Governance Define and evolve the cloud security architecture roadmap for both Azure and GCP.
- Assess security implications of recent cloud services before adoption.
- Align security controls with regulatory requirements (GDPR, ISO 27001/27017, SOC Partner with Microsoft and Google technical account teams on security roadmap alignment.
- Enable visibility into security posture through dashboards, Secure Score, and SCC metrics.
- Automation & DevSecOps Automate security configurations using Terraform (Azure and GCP providers).
- Build and maintain security-hardened Terraform modules consumed by product teams.
- Integrate security scanning into CI/CD pipelines (container scanning, IaC scanning, dependency checks).
- Implement policy-as-code using Azure Policy, GCP Organization Policies, and OPA/Sentinel.
- Collaboration & Enablement Work directly with product teams to implement security controls
- not just advise.
- Act as a security enabler who unblocks teams while maintaining security posture.
- Design IAM models and enforce least privilege across both platforms.
- Contribute to Security Champions networks and internal cloud security knowledge bases.
- Translate security requirements into practical, deployable engineering solutions.
- Required Skills &
Experience Mandatory 5+ years hands-on experience securing workloads in Azure
- must demonstrate practical use of Defender for Cloud, Azure Firewall, NSGs, Key Vault, Entra ID, and Azure Monitor/Sentinel.
- 3+ years hands-on experience securing workloads in GCP
- must demonstrate practical use of SCC, VPC networking, IAM, Organization Policies, and at least two of: BigQuery, Cloud Run, GKE, Cloud Functions.
- Proven Terraform experience for both Azure and GCP security automation.
- Experience triaging and remediating findings from Defender for Cloud and Google SCC.
- Strong understanding of cloud networking security (firewalls, private connectivity, DNS security, DDoS protection) in both platforms.
- Experience implementing IAM at scale
- RBAC, conditional access, workload identity, service account governance.
- Working knowledge of container security (AKS/GKE hardening, image scanning, runtime protection).
- Strongly Preferred Experience with Azure Sentinel or Google Chronicle for security operations.
- Hands-on experience with Azure DDoS Protection, Azure Front Door WAF, or GCP Cloud Armor.
- Familiarity with GCP Assured Workloads or Azure Confidential Computing.
- Certifications: AZ-500, SC-100, Google Professional Cloud Security Engineer.
- Experience with policy-as-code frameworks (OPA, Sentinel, Checkov, tfsec).
- Location: Delhi NCR,Bangalore,Chennai,Pune,Kolkata,Ahmedabad,Mumbai,Hyderabad
📌 Cloud Security Architect - Azure & GCP Platforms (Bengaluru)
🏢 Zorba consulting
📍 Bengaluru