28 Aug
|
Theomnihire
|
Mumbai
28 Aug
Theomnihire
Mumbai
Job Title: Senior Cloud Automation Engineer
Location: Navi Mumbai
Working Hours: 9:00 AM – 6:00 PM
Mode of Interview: Face-to-Face at Navi Mumbai
Headcount: 2 Positions
Position Summary
The Senior Cloud Automation Engineer is an individual contributor role focused on building end-to-end automation that actively strengthens the enterprise cyber-security posture. The incumbent will write Terraform to deploy security controls, build Logic Apps for automated SOAR workflows, develop custom Sentinel connectors and Azure Monitor-based applications, and contribute to multi-cloud CSPM and asset-discovery pipelines across Azure, GCP, and AWS environments.
Requirements
Key Responsibilities
- Terraform & Infrastructure-as-Code (IaC):
- Write and maintain reusable, production-grade Terraform modules for Azure security controls—including NSGs, Azure Firewall, App Gateway / WAF, Key Vault, Private Endpoints, and Defender for Cloud.
- Manage Terraform state, workspaces, automated plan reviews, and policy-as-code enforcement using tools like Checkov and tfsec.
- Sentinel Connectors, Logic Apps & SOAR Automation:
- Develop custom Microsoft Sentinel data connectors utilizing Codeless Connector Platform (CCP), Logs Ingestion API, Function App pollers, and Event Hub / Storage pipelines.
- Build Logic Apps (Standard & Consumption) for SOAR to handle real-time alert enrichment, ITSM ticketing (ServiceNow, Jira), Teams/email notifications, and automated containment actions.
- Engineer Sentinel-as-Code content—including Analytics Rules written in KQL, custom Workbooks, and Watchlists—delivered seamlessly via Terraform.
- Azure Monitor & Web Applications:
- Design and implement Azure Monitor dashboards, Log Analytics workspaces, Data Collection Rules (DCRs), Azure Monitor Agent (AMA) onboarding, custom alerts, action groups, and Application Insights.
- Deploy and operate Azure Web Apps, App Services, and Azure Functions using modern deployment frameworks (ZIP, Run-from-Package, container deployments, and deployment slots with swap).
- Embed robust App Service security using Managed Identities, Key Vault references, Private Endpoints, and Easy Auth (Microsoft Entra ID integration).
- Multi-Cloud CSPM & Asset Discovery:
- Contribute to Cloud Security Posture Management (CSPM) pipelines assessing Azure, GCP, and AWS against CIS benchmarks, NIST standards, and internal security frameworks.
- Develop automated asset-discovery tools to aggregate subscriptions, projects, accounts, identities, networks, storage, and PaaS inventories.
- Centralize security findings from Defender for Cloud, GCP Security Command Center (SCC), and AWS Security Hub into a unified triage workflow.
Candidate Profile & Qualifications
- Experience: 6 to 9 years of hands-on experience in cloud security engineering, infrastructure-as-code automation, and cloud-native security development.
- Education: B.Tech or M.Tech in Computer Science, Information Technology, Cyber Security, or a related field.
- Core Technical Competencies:
- Expert-level Terraform skills along with policy-as-code tools (Checkov, tfsec).
- Solid mastery of Microsoft Sentinel, KQL, custom data connector development, and Logic Apps for automated threat response.
- Practical experience with Azure Monitor, App Services, Azure Functions, and Python/PowerShell/Shell scripting.
- Deep understanding of multi-cloud environments (Azure, GCP, AWS) and security posture management frameworks.
- Certifications:
- HashiCorp Certified: Terraform Associate
- AZ-204: Developing Solutions for Microsoft Azure
- AZ-500: Microsoft Azure Security Technologies
- SC-200: Microsoft Security Operations Analyst
- AWS Certified Security – Specialty OR Google Associate Cloud Engineer
📌 Senior Cloud Automation Engineer (Mumbai)
🏢 Theomnihire
📍 Mumbai