Azure (Mumbai)

Azure (Mumbai)

24 Sep
|
Olevea Nxt
|
Mumbai

24 Sep

Olevea Nxt

Mumbai

– Azure Cloud & Network Security Engineer

Job Title: Azure Cloud & Network Security Engineer

Department: Cloud / Infrastructure & Security

Experience: 5+ years

Location: Mumbai

Employment Type: Full-time

About the Role

We are looking for an experienced Azure Cloud & Network Security Engineer to support the migration and transformation of Azure workloads into a secure, standardized landing-zone environment.

The role will focus on Azure networking, network security, firewall implementation, routing, traffic inspection, secure administrative access, identity and access controls, and cloud security operations.

The project involves approximately 42 Azure subscriptions and follows a Secure-First / Zero Trust approach, with inbound, outbound, east-west, and administrative traffic inspected, controlled, logged, and monitored through Azure-native security capabilities.

Key Responsibilities

- Design, implement, and maintain secure Azure network and security architecture aligned with Zero Trust principles.
- Deploy, configure, and manage Azure Firewall as the centralized security inspection point.
- Configure Network Rule Collections, Application Rule Collections, DNAT rules, Threat Intelligence, DNS Proxy, FQDN/URL filtering, and diagnostic logging.
- Configure and maintain User Defined Routes (UDRs) across workload subnets.
- Ensure workload subnet traffic is routed through the centralized Azure Firewall for inspection.
- Configure secure inbound traffic flows using Azure Application Gateway / Load Balancer with WAF.
- Configure outbound traffic inspection and ensure approved external connectivity is routed through the native firewall.
- Implement network segmentation and secure spoke-to-spoke VNet connectivity through approved firewall and routing architecture.
- Implement secure administrative access using Azure Bastion.
- Ensure workload VMs do not have unnecessary public IP addresses.
- Configure Network Security Groups (NSGs) to restrict management traffic and application access.
- Support Azure networking components including VNet, route tables, Azure Load Balancer, Application Gateway, and API Management.
- Support Azure security controls including RBAC, PAM, ZTNA, SIEM, SOAR, EDR/XDR, CNAPP, CASB, DLP, and IPS/IDS.
- Support Azure WAF deployment and hardening for web applications.
- Implement and maintain logging and monitoring for firewall and network security controls.
- Troubleshoot Azure networking, routing, firewall, connectivity, and security-related issues.
- Support Azure landing-zone implementation, cloud migration, security integration, governance, and operational handover.
- Maintain documentation covering network architecture, routing, firewall policies, security controls, and implementation procedures.
- Support implementation, testing, UAT, rollback, and post-implementation validation.




- Work closely with cloud, security, infrastructure, application, and business teams during migration and transformation activities.

Required Technical SkillsAzure
- Microsoft Azure
- Azure Virtual Network (VNet)
- Azure Firewall
- Azure Application Gateway
- Azure Load Balancer
- Azure Web Application Firewall (WAF)
- Azure Bastion
- Azure Route Tables / User Defined Routes (UDRs)
- Network Security Groups (NSGs)
- Azure API Management
- Azure RBAC
- Azure networking and security services

Networking & Security
- VNet architecture and subnetting
- User Defined Routes
- Network routing
- Network segmentation
- Firewall rule configuration
- Network Rule Collections
- Application Rule Collections
- DNAT
- Threat Intelligence
- DNS Proxy
- FQDN and URL filtering
- Network traffic inspection
- IPS/IDS
- WAF
- DDoS protection
- Secure administrative access
- Zero Trust security principles
- Cloud network security architecture

Identity & Security The candidate should have exposure to:
- Azure RBAC
- Privileged Access Management (PAM)
- Zero Trust Network Access (ZTNA)
- SIEM
- SOAR
- EDR/XDR
- CNAPP
- CASB
- DLP
- IPS/IDS
- Azure WAF
- Azure Firewall

These security controls are specifically included in the SOW's Azure landing-zone scope.

Positive to Have

- Experience with enterprise Azure migration projects
- Experience implementing Azure landing zones
- Experience with hub-and-spoke Azure architecture
- Experience with Azure Firewall deployment and hardening
- Experience with Azure WAF deployment and hardening
- Knowledge of Azure governance and policy enforcement
- Experience with ServiceNow / CMDB integration
- Experience with F5 Load Balancers
- Knowledge of DDoS protection
- Experience with third-party / next-generation firewalls
- Experience with backup and disaster recovery
- Knowledge of threat intelligence and security operations
- Experience working in enterprise 24x7 cloud environments
- Experience with cloud security governance and compliance

Qualifications
- Bachelor's degree in Computer Science, Information Technology, Networking, Cybersecurity, or a related field.
- 5+ years of relevant experience in Azure infrastructure, cloud networking, network security, or a related field.
- Strong hands-on experience with Azure networking and security services.
- Experience working on enterprise cloud migration, security implementation, or landing-zone projects.
- Strong troubleshooting and problem-solving skills.





Key Responsibilities During Implementation1. Inbound Traffic Security Route internet traffic through Application Gateway / Load Balancer with WAF, followed by the native firewall before reaching approved application workloads such as VMs, AKS, or App Service.

1. Outbound Traffic Security

Configure workload subnets with a default route through the native Azure Firewall and inspect outbound traffic before allowing approved external connectivity. High-risk destinations and unauthorized services will be blocked based on defined security policies.

1. User Defined Routes

Configure UDRs for spoke VNets/VNets so that applicable traffic is routed through the centralized firewall. For spoke-to-spoke connectivity, configure the required UDRs and firewall routing.

1. Secure Administrative Access

Implement Azure Bastion for administrative access and ensure workload VMs do not require public IP addresses. Configure NSGs to allow management traffic only through approved Bastion access paths.

1. Centralized Azure Firewall

Deploy and operationalize Azure Firewall as the centralized security inspection point and configure workload subnet UDRs to use the firewall as the next hop.

1. Firewall Security Controls

Implement and maintain:
- Network Rule Collections
- Application Rule Collections
- DNAT Rules
- Threat Intelligence
- DNS Proxy
- TLS Inspection, where approved
- FQDN & URL Filtering
- Diagnostic Logging

1. Migration & Transformation

Support controlled migration waves, Azure governance and policy enforcement, CMDB/inventory normalization, security integration, compliance alignment, and operational handover. Project Context The project involves standardizing DFS Azure workloads within the BTIS-GIT native landing zone, covering approximately 42 Azure subscriptions. The architecture follows a Secure-First / Zero Trust approach.

The target architecture requires appropriate inbound, outbound, east-west, and administrative traffic to be inspected, controlled, logged, and monitored through Azure-native security capabilities.

Project Timeline

Phase I – Secure First: Target completion 30 November 2026

Phase II – Transformation & Operationalization: Target completion 30 November 2027

Candidate Profile

We are looking for a candidate with strong hands-on experience in Azure networking and cloud security, particularly someone who can independently work on:

- Azure Firewall
- UDRs and routing
- VNet architecture
- Application Gateway and WAF
- Azure Bastion
- NSGs
- Network traffic inspection
- Azure security controls
- Troubleshooting
- Enterprise Azure migration

The role requires practical implementation experience, rather than only theoretical knowledge of Azure security and networking.

Work Location: In person

📌 Azure (Mumbai)
🏢 Olevea Nxt
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: azure (mumbai) / mumbai