04 Aug
|
Zorba AI
|
Kolkata
Job Summary We are looking for a hands-on Cloud Security Architect with strong engineering expertise in securing enterprise workloads across Microsoft Azure and Google Cloud Platform (GCP). This is an implementation-focused role requiring extensive experience configuring cloud-native security services, automating security controls, and securing cloud infrastructure using Infrastructure as Code (IaC). The ideal candidate should possess equal hands-on expertise in Azure and GCP, be proficient in Terraform, and work closely with Platform Engineering, DevOps, and Product teams to build secure, scalable cloud environments.
Key Responsibilities Cloud Security Engineering Configure and manage Microsoft Defender for Cloud (Servers, Containers, Storage, Key Vault, DNS, Resource Manager).
Implement and manage Azure Firewall, Network Security Groups (NSGs), Azure WAF, Private Link, and Private Endpoints.
Administer Azure Key Vault, certificate lifecycle, and workload integration.
Configure Microsoft Entra ID (Azure AD) including Conditional Access, Privileged Identity Management (PIM), RBAC, Workload Identities, and Service Principal security.
Manage Google Security Command Center (SCC), including Security Health Analytics, Event Threat Detection, and Container Threat Detection.
Design and secure GCP VPC architectures, firewall rules, Shared VPC, Private Google Access, and VPC Service Controls.
Secure BigQuery environments using row/column-level security, authorized views, data masking, and VPC Service Controls.
Harden Cloud Run deployments with ingress controls,
Binary Authorization, service identities, and secret management.
Implement and manage GCP IAM, custom roles, Organization Policies, Workload Identity Federation, and service account governance.
Cloud Security Architecture
Design and evolve enterprise cloud security architecture across Azure and GCP.
Evaluate security implications of new cloud services before adoption.
Ensure compliance with ISO 27001, ISO 27017, GDPR, and SOC 2.
Collaborate with Microsoft and Google technical teams on security best practices.
Monitor cloud security posture using Secure Score, Defender for Cloud, and Google SCC dashboards. Automation & DevSecOps Develop reusable Terraform modules for Azure and GCP security configurations.
Automate security provisioning using Infrastructure as Code.
Integrate security scanning into CI/CD pipelines, including:
Infrastructure as Code scanning
Container image scanning
Dependency vulnerability scanning
Implement Policy-as-Code using Azure Policy, GCP Organization Policies, OPA, Sentinel, Checkov, and tfsec.
Collaboration Partner with DevOps and Product Engineering teams to implement security controls.
Design scalable IAM models and enforce least-privilege access.
Support Security Champion initiatives and internal cloud security knowledge sharing.
Translate security requirements into practical engineering solutions.
Required Skills Mandatory 5+ years of hands-on experience securing Microsoft Azure environments.
3+ years of hands-on experience securing Google Cloud Platform (GCP) environments.
Strong expertise with
Microsoft Defender for Cloud
Azure Firewall
Azure WAF
Azure Key Vault
Microsoft Entra ID
Azure Monitor / Microsoft Sentinel
Google Security Command Center (SCC)
GCP IAM
VPC Networking
Organization Policies
BigQuery Security
Cloud Run Security
Strong experience with Terraform for Azure and GCP.
Experience triaging and remediating findings from Defender for Cloud and Google SCC.
Expertise in cloud networking security:
Firewalls
Private Connectivity
DNS Security
DDoS Protection
Robust knowledge of Identity & Access Management:
RBAC
Conditional Access
Workload Identity
Service Account Governance
Experience securing Kubernetes environments (AKS/GKE) and container workloads.
Preferred Skills Microsoft Sentinel or Google Chronicle.
Azure DDoS Protection.
Azure Front Door WAF.
Google Cloud Armor.
Azure Confidential Computing.
GCP Assured Workloads.
Policy-as-Code frameworks:
OPA
Sentinel
Checkov tfsec
Certifications (Preferred) Microsoft Certified: AZ-500
Microsoft Certified: SC-100
Google Professional Cloud Security Engineer Skills: cloud security,azure,gcp
📌 Cloud Security Engineer(Azure & GCP) (Kolkata)
🏢 Zorba AI
📍 Kolkata