- Lead Cloud Security Assessments using the Agentic AI Platform and provide CloudSec domain inputs for development and augmentation of the platform.
- Design, implement, and enforce security controls & guardrails for new application and platform onboarding to Azure.
- Design and maintain Azure security policies across tenants and subscriptions
- Conduct cloud security reviews of JPL applications hosted in independent tenants, including Omni AI and CloudStaff
- Coordinate Azure resource tag correction across 500+ subscription owners and maintain tagging governance
- Monitor Azure cost governance for Infosec resources and optimize cloud security spend
- Administer PIM (Privileged Identity Management) and architect Conditional Access policies across the Azure workplace.
- Perform SaaS/PaaS security reviews and compliance monitoring across all connected applications and cloud platforms.
Qualification and Work Experience Qualification: BE / BTech / MTech
or equivalent cloud security certifications.(Preferred*)
Work experience: Hands-on experience in cloud security architecture, with at least 5 years specifically on Microsoft Azure at enterprise scale.
- Proven experience managing Azure security policy enforcement across multiple tenants and large-scale subscription environments.
- Hands-on experience with Entra ID, PIM, Conditional Access, Azure Sentinel, Logic Apps, and Defender for Cloud.
- Solid understanding of cloud security architecture frameworks, including CIS Azure Benchmarks, NIST CSF, and ISO 27001 controls.
- Experience conducting security reviews of SaaS applications and cloud-native workloads in multi-tenant Azure environments.
- Experience with Agentic AI platforms or contributing security domain inputs to AI-driven security tooling is a strong advantage.
- Preferred: Experience in Azure cost governance, resource tagging strategy, and Infosec spend optimisation at scale.