Company Name: VARITE India Private Limited
About The Client
An Indian multinational information technology (IT) consulting company headquartered in Noida, The company has offices in 52 countries and over 225,944 employees. The Client is a global IT services and consulting company that offers a wide range of services and products across various industries like IT Infrastructure Services, Cybersecurity Services, Cloud Services, Big Data and Analytics, Internet of Things (IoT) Solutions, Semiconductor Services and Enterprise Software Products. About The Job:
- Implement central Azure governance capabilities for Web Application Firewall, workload isolation, and egress traffic filtering based on an approved architectural design.
- The role focuses on developing reusable Terraform modules, CI/CD pipelines, policy automation, diagnostics, monitoring enablement, and operational guardrails for Azure Front Door WAF, Application Gateway WAF, network segmentation, and controlled outbound connectivity across the cloud estate.
Essential Job Functions:
- Develop reusable Terraform modules for Azure Front Door WAF, Application Gateway WAF v2, WAF policies, managed rule sets, custom rules, exclusions, diagnostics, and policy associations.
- Develop Terraform components for workload isolation and egress filtering, including virtual networks, subnets, NSGs, route tables, Azure Firewall integration, private connectivity, and controlled outbound access.
- Implement platform-level governance capabilities from architectural designs, including automation, configuration standards, policy enforcement, compliance reporting, and onboarding workflows.
- Build CI/CD pipelines for Terraform validation, deployment, testing, release management, and controlled rollout across environments.
- Integrate governance modules with Azure landing zones, management groups, subscriptions, hub-and-spoke or Virtual WAN patterns, naming conventions, tagging standards, and platform automation.
- Implement Resource Graph queries and reporting to detect, govern, and enforce WAF usage, workload isolation, and egress controls.
- Enable diagnostics, Log Analytics, monitoring workbooks, alert foundations, and SIEM data forwarding for WAF, network security, Azure Firewall, and egress use cases.
- Support application onboarding, parameterization, environment-specific configuration, rule tuning inputs, egress allow-listing, testing, troubleshooting, and operational handover.
- Collaborate with architecture, platform engineering, network, security, operations, and application teams to ensure implementation matches the target architecture and operating model.
Qualifications:
Must-Have Skills
Terraform, IaC & DevOps Engineering
- Strong hands-on experience developing reusable, parameterized, versioned,
and documented Terraform modules for Azure resources.
- Terraform state management, provider configuration, environment separation, module testing, and release versioning.
- CI/CD implementation with Azure DevOps, GitHub Actions, or comparable tooling, including validation, linting, approvals, and controlled rollout patterns.
- Git-based collaboration, branching strategies, pull requests, code reviews, and release documentation.
- Ability to translate architectural designs and governance requirements into maintainable automation components.
Azure WAF, Front Door & Application Gateway Implementation
- Hands-on implementation experience with Azure Web Application Firewall policies for Azure Front Door Premium and Application Gateway WAF v2.
- Knowledge of managed rule sets, OWASP rule groups, custom rules, exclusions, rule overrides, bot protection, rate limiting, and detection versus prevention mode.
- Experience with WAF diagnostics, Log Analytics, Azure Monitor, workbooks, alert foundations, and Microsoft Sentinel data requirements.
- Ability to support onboarding patterns, environment-specific configuration, WAF policy assignment models, and deployment troubleshooting.
Azure Workload Isolation & Egress Filtering
- Hands-on experience implementing workload isolation with virtual networks, subnets, NSGs, route tables, private endpoints, service endpoints, and private DNS.
- Experience with centralized egress filtering using Azure Firewall, firewall policies, application rules, network rules, FQDN filtering, threat intelligence mode, and forced tunneling.
- Understanding of hub-and-spoke, secured virtual hub, Virtual WAN, and landing zone network architectures.
- Ability to implement governance guardrails for segmentation, controlled outbound traffic, private connectivity, exception handling, diagnostics, and SIEM integration.
Azure Platform Engineering & Governance Automation
- Azure Policy implementation, initiatives, assignments, exemptions, remediation tasks, and policy-as-code patterns.
- Azure Resource Graph queries for estate discovery, compliance reporting, and governance monitoring across WAF, segmentation, private connectivity, and egress controls.
- Integration with Azure management groups, subscriptions, landing zones, virtual networks, naming conventions, tagging standards, and platform automation.
- Implementation of guardrails for mandatory WAF usage, workload isolation,
diagnostics, monitoring, egress filtering, and configuration consistency.
- Ability to clarify implementation details, identify dependencies, and raise technical constraints early.
Collaboration, Documentation & Delivery
- Robust collaboration with cloud architects, platform engineering, network, security, operations, and application teams.
- Ability to turn architecture and governance requirements into implementation tasks, technical designs, and user stories.
- Clear documentation of Terraform modules, deployment examples, onboarding instructions, runbooks, and operational handover material.
- Structured delivery mindset with attention to quality, maintainability, security, and operational usability.
Preferred Skills
- Experience with enterprise Azure landing zones, Azure Firewall Manager, Virtual WAN, secured virtual hubs, private endpoints at scale, and DNS governance.
- Experience with Azure Policy as Code or comparable testing and compliance tooling.
- Knowledge of OWASP Top 10, API protection, bot protection, Microsoft Sentinel, and security monitoring use cases.
- Experience with large-scale onboarding, reusable platform services, central governance rollout programs, ITIL, and operational handover.
How to Apply: Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit Jobs In India – VARITE.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral: 0-2 years INR 5,000 2-6 years INR 7,500 6+ years INR 10,000
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
📌 Azure WAF Governance DevOps Engineer (India)
🏢 VARITE
📍 India