08 Sep
|
StarZen
|
Gurugram
DevOps & Cloud Security Engineer Experience:
3–5 years |
Location
Gurugram |
Type
Full time Role Own our entire Azure and Microsoft stack end-to-end — infrastructure, containers, data platform, security and monitoring. You will design the architecture, keep it documented and current, and make sure nothing breaks silently. Responsibilities Architecture & Design
— Design the complete cloud architecture (network, compute, data, security layers), maintain up-to-date diagrams and documentation, and evolve the design as the stack grows. Azure Infrastructure
— Manage VMs, VNets, NSGs, App Gateway, Front Door, Entra ID/RBAC and cost optimisation. Infrastructure as Code via Terraform/Bicep. Containers
— Run and upgrade AKS / Container Apps and ACR; build hardened, minimal Docker images with CVE scanning in the pipeline. Databases
— Administer relational databases (Azure SQL / SQL Server, PostgreSQL / MySQL) : schema and index management, query performance tuning, high availability, replication, automated backups and tested point-in-time restores. Also manage MongoDB (replica sets, sharding, backups, restore testing). Search & Log Store
— Manage
Elasticsearch / OpenSearch clusters: index lifecycle and retention policies, shard and node sizing, snapshots, query performance, cluster health monitoring and secure access. Maintain the ELK/EFK stack used for centralised logging where applicable. Data Platform
— Own
Microsoft Fabric and OneLake : workspace setup, capacity management, access control, pipelines and data governance. Business Application Integrations
— Manage
Dynamics 365 and ERP environments and their APIs
— authentication, integration pipelines, data sync, error handling, rate limits, monitoring and environment refreshes.
Secrets Management
— Own Azure Key Vault. Enforce a scheduled secret, key and certificate rotation policy ; zero hardcoded credentials anywhere. 24×7 Monitoring & Alerting
— Set up full-stack observability (Azure Monitor, Log Analytics, App Insights, Grafana). Define SLIs/SLOs and configure alerts so that any anomaly triggers a notification immediately , routed to the right on-call channel with minimal noise. Log Retention & Governance
— Define and maintain retention policies per log type (application, security, audit, infra) with correct archival tiers and compliance alignment. Security & Vulnerability Management
— Continuous scanning across servers, containers and dependencies; triage and remediate CVEs within SLA. Operate Defender for Cloud / Sentinel. DDoS, WAF & Anti-Crawler
— Configure Azure DDoS Protection and WAF; implement rate limiting, geo/IP filtering, bot management, robots.txt policy and anti-scraping controls. Patch Management
— Keep all servers and container images current
— OS, kernel, runtimes and libraries — on a documented cadence, with emergency patching for critical CVEs. Automation & Cron Inventory
— Maintain CI/CD pipelines (Azure DevOps / GitHub Actions) and a documented register of every cron and scheduled job: what it does, why it exists, schedule, owner and failure alerting. Backup & DR
— Own backup strategy across all workloads with regular tested restores and a drilled DR plan (defined RTO/RPO). Documentation
— Keep runbooks, SOPs, change logs and asset inventory accurate and current. Undocumented infrastructure is treated as incomplete work.
Must-Have Skills Azure (3+ yrs) ·
Microsoft Fabric & OneLake
·
Dynamics 365 APIs
·
ERP APIs and integrations
·
Relational databases (Azure SQL / SQL Server, PostgreSQL or MySQL)
incl. query tuning and HA ·
Elasticsearch / OpenSearch cluster administration · MongoDB ·
Effective use of AI assistants (Claude / ChatGPT)
for scripting, IaC generation, log analysis, debugging and documentation · Linux administration incl. kernel patching · Docker & Kubernetes/AKS · Terraform or Bicep · Networking, DNS, TLS, Nginx · WAF / DDoS / bot protection · Vulnerability management · Azure Key Vault · REST / OData API integration and troubleshooting · Bash / PowerShell / Python · CI/CD pipelines · Monitoring and alerting stacks
Note on AI tools
We expect you to actively use Claude/ChatGPT to work faster — but with judgement. You must be able to review, test and take full ownership of anything AI-generated before it touches our infrastructure.
Good to Have Basic working knowledge of
AWS
(EC2, S3, IAM) and
GCP
· Microsoft Sentinel / SIEM · Cloudflare · Power Platform / Dataverse · Azure Data Factory or Synapse · ISO 27001 / SOC 2 exposure Certifications (Preferred) AZ-104, AZ-400, AZ-500, CKA/CKS
What We Look For Ownership mindset, disciplined documentation habits, security-first thinking, and calm handling of production incidents. Willingness to be on-call.
📌 DevOps & Cloud Security Engineer (Gurugram)
🏢 StarZen
📍 Gurugram