07 Aug
|
Maaze Underwriting Solutions
|
New Delhi
07 Aug
Maaze Underwriting Solutions
New Delhi
Role Summary
You will serve as the lead Azure Cloud Architect responsible for designing and implementing a Zero Trustaligned security architecture across a multisubscription Azure enterprise environment. This role focuses on securing AI Foundry, Azure Kubernetes Service (AKS), Microsoft Fabric, and the broader Azure tenant using industry frameworks including NIST 80053, NIST CSF, ISO 27001, SOC 2, and Insurance Regulator (NAIC Model 668 / NYDFS 500) requirements.
You will define the security blueprint, enforce governance, design identity boundaries, implement policydriven controls, and ensure all AI and cloud workloads meet enterprise and regulatory standards.
Key Responsibilities
1. Azure Tenant & Zero Trust Architecture
- Architect and implement a Zero Trust security model across identity, network, data, and workload layers.
- Design Azure management group hierarchy, subscription strategy, and landing zones aligned to NIST/ISO controls.
- Implement Conditional Access, PIM, Identity Governance, and segmented identity boundaries for developers, admins, and workloads.
- Lead the rollout of Azure Policy, policy initiatives, RBAC, and custom role definitions for leastprivilege enforcement.
- Establish secure-by-default patterns for all cloud services.
2. AI Foundry Security & Governance
- Architect secure environments for AI Foundry, including:
- Model training and serving isolation, Data access governance, Key Vault integration
- Private endpoints and network isolation
- Implement AI safety, lineage, and audit controls aligned with regulatory expectations.
- Define secure patterns for prompt flows, agents,
vector stores, and model endpoints.
3. AKS Security Architecture
- Design hardened AKS clusters with:
- Azure CNI, network policies, pod identity, OPA/Gatekeeper, secretless workloads
- Workload identity with Entra ID
- Private cluster, Azure Firewall, WAF, DDoS Protection
- Implement Zero Trust for microservices, including: mTLS, API gateway patterns,Service mesh (Istio/Linkerd) optional
- Define secure CI/CD patterns using OIDC, GitHub Actions, and policydriven deployments.
4. Microsoft Fabric Security
- Architect secure Fabric workspaces, pipelines, and lakehouses.
- Implement:
- Data lineage, Purview integration, Row/column-level security
- Managed VNETs, Private endpoints
- Ensure Fabric aligns with data residency, retention, and insurance regulatory requirements.
5. Data Protection & Key Management
- Implement enterprisewide Key Vault, Managed HSM, and secret rotation patterns.
- Enforce encryption standards for:
- Data at rest, Data in transit, Model artifacts, AKS secrets and Fabric data
6. Logging, Monitoring & Threat Detection
- Architect endtoend observability using:
- Azure Monitor, Log Analytics
- Microsoft Defender for Cloud, Sentinel
- Build automated detection and response patterns for:
- Privilege escalation, Lateral movement
- Data exfiltration, AI model misuse or drift
7. Compliance & Regulatory Alignment
- Map Azure controls to:
- NIST 80053, NIST CSF
- ISO 27001, SOC 2
- NAIC Model 668, NYDFS 500
- Produce architecture documentation, control evidence, and auditready artifacts.
- Partner with risk, compliance, and internal audit teams.
Required Skills & Experience
- 15+ years in cloud architecture with deep expertise in Azure.
- Proven experience implementing Zero Trust in enterprise environments.
- Handson experience with:
- Azure AD/Entra ID, Azure Policy
- Azure Firewall / Private Link / NSGs
- AKS (production-grade)
- Microsoft Fabric
- AI Foundry or Azure ML
- Robust understanding of network segmentation, identity governance, and data protection.
- Experience with Bicep, Terraform, or ARM templates.
- Strong knowledge of NIST/ISO frameworks and regulatory controls.
Preferred Qualifications
- Azure certifications:
- AZ305 (Architect)
- AZ500 (Security)
- SC100 (Cybersecurity Architect)
- AI102 (AI Engineer)
- Experience in insurance, financial services, or other regulated industries.
- Experience with GitHub OIDC, DevSecOps, and policyascode.
Success Criteria
- Azure tenant fully aligned to Zero Trust principles.
- AI Foundry, AKS, and Fabric workloads fully secured and compliant.
- Automated governance and policy enforcement across all environments.
- Auditready documentation and evidence for regulators.
- Secure, scalable patterns adopted across engineering teams.
📌 Azure Cloud Architect (New Delhi)
🏢 Maaze Underwriting Solutions
📍 New Delhi