17 Sep
|
Pi Square Technologies
|
Bengaluru
17 Sep
Pi Square Technologies
Bengaluru
Role & responsibilities
We are looking for a Senior solution architech, Azure Cloud to own and drive enterprise Azure infrastructure with a strong focus on architecture, resilience, security and compliance and alignment with Microsoft Well-Architected Framework and industry best practices. The ideal candidate brings 69 years of deep relavant Azure experience and has a track record of building well-governed, secure, and optimized cloud environments. This role requires someone who doesn’t just build infrastructure but continuously evaluates, hardens, and improves it.
Essential Duties and Responsibilities
- Architecture & Strategy
- Well-Architected Framework + Cloud Adoption Framework (CAF)
- Enterprise-Scale Landing Zones (MG hierarchy, subscription vending)
- Multi-region BCDR design (RTO/RPO, paired regions)
- Architecture Decision Records (ADRs) and design documentation
- Identity (Entra ID)
- Conditional Access (Zero Trust, risk-based)
- PIM, RBAC at scale, access reviews
- Hybrid identity (Entra Connect), B2B/B2C
- Managed identities + Workload Identity for AKS
- Networking
- Hub-spoke / Virtual WAN topologies
- Front Door, App Gateway, WAF, Azure Firewall
- ExpressRoute, VPN, Private Endpoints
- DDoS, Network Watcher, NSG flow logs
- DNS
- Azure Private DNS zones + Private Resolver
- Conditional forwarding, zone links (registration vs resolution)
- Split-horizon / hybrid name resolution
- Certificates & Secrets
- Key Vault — lifecycle, auto-rotation
- Internal CA integration, Managed HSM
- Secret rotation patterns for apps
- Compute & Containers
- AKS — networking modes, Workload Identity, ingress, upgrades
- VMs, VMSS, Bastion, Update Management
- App Service (slots, scaling), Azure Functions
- Container Apps, ACR (geo-replication)
- Integration & PaaS
- API Management (policies, products, versioning)
- Service Bus, Event Grid, Event Hubs
- Logic Apps (Standard / Consumption)
- Data
- Azure SQL / SQL MI, Cosmos DB
- PostgreSQL / MySQL Flexible Server
- Storage (Blob lifecycle, Files, NetApp), replication strategies
- AI & Analytics
- Azure OpenAI / AI Foundry with private endpoints
- RAG patterns, content safety
- AI Search; Synapse / Fabric if in scope
- Security & Compliance
- Defender for Cloud (CSPM/CWPP)
- Microsoft Sentinel (SIEM/SOAR)
- Azure Policy + initiatives, CIS/NIST compliance
- Observability
- Azure Monitor, Log Analytics, App Insights
- KQL for analysis, action groups, auto-remediation
- Azure Resource Graph for inventory
- Cost & FinOps
- Rightsizing, RI / Savings Plans
- Tagging, budgets, anomaly alerts
- FinOps practice (Inform Optimize Operate)
- BCDR
- Azure Site Recovery, immutable backups
- Geo-replication for SQL / Cosmos / Storage
- Regional failover runbooks and DR drills
- Hybrid & Migration
- Azure Arc (servers, K8s, data)
- Azure Migrate, DMS
- 6 R's — rehost / refactor / replatform / rearchitect
- IaC & DevOps
- Terraform + Bicep
- YAML pipelines (Azure DevOps / GitHub Actions)
- Policy-as-Code, security scanning (Checkov / tfsec)
- Automation
- PowerShell + Python (Azure SDK)
- Azure Automation (runbooks, hybrid worker)
- Event-driven via Functions / Logic Apps
Work Experience
- Minimum 5 years in the infrastructure Engineering and administering. Managing VMware/EMC Avamar/Data Domain products. required
Preferred Knowledge, Skills and Abilities
- Strong working knowledge of Cloud Adoption Framework and Well-Architected Framework, applied to design reviews and remediation
- Hands-on proficiency with Python, PowerShell, and Azure CLI for administration, identity management, and automation
- Deep understanding of Entra ID — authentication flows, token lifecycle, Conditional Access evaluation, directory synchronization
- Solid grasp of PKI — certificate chains, TLS handshake, formats (PFX, PEM, CER), and lifecycle management
- Experience designing DNS resolution strategies across hybrid environments (private zones, conditional forwarding, split-horizon)
- Working knowledge of hybrid Azure networking — hub-spoke topologies, ExpressRoute / VPN, Private Endpoints, NSG and routing fundamentals
- Proficiency in Infrastructure-as-Code — Terraform and/or Bicep, including module design and policy-as-code
- Baseline understanding of container platforms (AKS) — networking modes, ingress, workload identity
- Ability to translate Advisor, Defender for Cloud, and Cost Management insights into actionable optimization, security, and FinOps plans
- Solid communication skills — articulating technical trade-offs and driving consensus across engineering and leadership audiences
License and Certifications
- Desirable AZ-305 — Azure Solutions Architect Expert or other relevant
📌 Azure Solution Architect (Bengaluru)
🏢 Pi Square Technologies
📍 Bengaluru