04 Sep
|
StarZen
|
Gurugram
DevOps & Cloud Security Engineer
Experience: 3–5 years | Location: Gurugram | Type: Full time
Role
Own our entire Azure and Microsoft stack end-to-end — infrastructure, containers, data platform, security and monitoring. You will design the architecture, keep it documented and current, and make sure nothing breaks silently.
Responsibilities
- Architecture & Design — Design the complete cloud architecture (network, compute, data, security layers), maintain up-to-date diagrams and documentation, and evolve the design as the stack grows.
- Azure Infrastructure — Manage VMs, VNets, NSGs, App Gateway, Front Door, Entra ID/RBAC and cost optimisation. Infrastructure as Code via Terraform/Bicep.
- Containers — Run and upgrade AKS / Container Apps and ACR; build hardened, minimal Docker images with CVE scanning in the pipeline.
- Databases — Administer relational databases (Azure SQL / SQL Server, PostgreSQL / MySQL): schema and index management, query performance tuning, high availability, replication, automated backups and tested point-in-time restores. Also manage MongoDB (replica sets, sharding, backups, restore testing).
- Search & Log Store — Manage Elasticsearch / OpenSearch clusters: index lifecycle and retention policies, shard and node sizing, snapshots, query performance, cluster health monitoring and secure access. Maintain the ELK/EFK stack used for centralised logging where applicable.
- Data Platform — Own Microsoft Fabric and OneLake: workspace setup, capacity management, access control, pipelines and data governance.
- Business Application Integrations — Manage Dynamics 365 and ERP environments and their APIs — authentication, integration pipelines, data sync, error handling, rate limits, monitoring and environment refreshes.
- Secrets Management — Own Azure Key Vault. Enforce a scheduled secret, key and certificate rotation policy; zero hardcoded credentials anywhere.
- 24×7 Monitoring & Alerting — Set up full-stack observability (Azure Monitor, Log Analytics, App Insights, Grafana). Define SLIs/SLOs and configure alerts so that any anomaly triggers a notification immediately, routed to the right on-call channel with minimal noise.
- Log Retention & Governance — Define and maintain retention policies per log type (application, security, audit, infra) with correct archival tiers and compliance alignment.
- Security & Vulnerability Management — Continuous scanning across servers, containers and dependencies; triage and remediate CVEs within SLA. Operate Defender for Cloud / Sentinel.
- DDoS, WAF & Anti-Crawler — Configure Azure DDoS Protection and WAF; implement rate limiting, geo/IP filtering, bot management, robots.txt policy and anti-scraping controls.
- Patch Management — Keep all servers and container images current — OS, kernel, runtimes and libraries — on a documented cadence, with emergency patching for critical CVEs.
- Automation & Cron Inventory — Maintain CI/CD pipelines (Azure DevOps / GitHub Actions) and a documented register of every cron and scheduled job: what it does, why it exists, schedule, owner and failure alerting.
- Backup & DR — Own backup strategy across all workloads with regular tested restores and a drilled DR plan (defined RTO/RPO).
- Documentation — Keep runbooks, SOPs, change logs and asset inventory accurate and current. Undocumented infrastructure is treated as incomplete work.
Must-Have Skills
- Azure (3+ yrs) · Microsoft Fabric & OneLake · Dynamics 365 APIs · ERP APIs and integrations · Relational databases (Azure SQL / SQL Server, PostgreSQL or MySQL) incl. query tuning and HA · Elasticsearch / OpenSearch cluster administration · MongoDB · Effective use of AI assistants (Claude / ChatGPT) for scripting, IaC generation, log analysis, debugging and documentation · Linux administration incl. kernel patching · Docker & Kubernetes/AKS · Terraform or Bicep · Networking, DNS, TLS, Nginx · WAF / DDoS / bot protection · Vulnerability management · Azure Key Vault · REST / OData API integration and troubleshooting · Bash / PowerShell / Python · CI/CD pipelines · Monitoring and alerting stacks
Note on AI tools: We expect you to actively use Claude/ChatGPT to work faster — but with judgement. You must be able to review, test and take full ownership of anything AI-generated before it touches our infrastructure.
Good to Have
Basic working knowledge of AWS (EC2, S3, IAM) and GCP · Microsoft Sentinel / SIEM · Cloudflare · Power Platform / Dataverse · Azure Data Factory or Synapse · ISO 27001 / SOC 2 exposure
Certifications (Preferred)
AZ-104, AZ-400, AZ-500, CKA/CKS
What We Look For
Ownership mindset, disciplined documentation habits, security-first thinking, and calm handling of production incidents. Willingness to be on-call.
📌 DevOps & Cloud Security Engineer (Gurugram)
🏢 StarZen
📍 Gurugram