Job Summary
We are looking for a
hands-on Cloud Security Architect with strong engineering expertise in securing enterprise workloads across
Microsoft Azure and Google Cloud Platform (GCP). This is an implementation-focused role requiring extensive experience configuring cloud-native security services, automating security controls, and securing cloud infrastructure using Infrastructure as Code (IaC).
The ideal candidate should possess equal hands-on expertise in
Azure and GCP, be proficient in
Terraform, and work closely with Platform Engineering, DevOps, and Product teams to build secure, scalable cloud environments.
Key Responsibilities Cloud Security Engineering
- Configure and manage Microsoft Defender for Cloud (Servers, Containers, Storage, Key Vault, DNS, Resource Manager).
- Implement and manage Azure Firewall, Network Security Groups (NSGs), Azure WAF, Private Link, and Private Endpoints.
- Administer Azure Key Vault, certificate lifecycle, and workload integration.
- Configure Microsoft Entra ID (Azure AD) including Conditional Access, Privileged Identity Management (PIM), RBAC, Workload Identities, and Service Principal security.
- Manage Google Security Command Center (SCC), including Security Health Analytics, Event Threat Detection, and Container Threat Detection.
- Design and secure GCP VPC architectures, firewall rules, Shared VPC, Private Google Access, and VPC Service Controls.
- Secure BigQuery environments using row/column-level security, authorized views, data masking, and VPC Service Controls.
- Harden Cloud Run deployments with ingress controls, Binary Authorization, service identities, and secret management.
- Implement and manage GCP IAM, custom roles, Organization Policies, Workload Identity Federation, and service account governance.
Cloud Security Architecture
- Design and evolve enterprise cloud security architecture across Azure and GCP.
- Evaluate security implications of new cloud services before adoption.
- Ensure compliance with ISO 27001, ISO 27017, GDPR, and SOC 2.
- Collaborate with Microsoft and Google technical teams on security best practices.
- Monitor cloud security posture using Secure Score, Defender for Cloud, and Google SCC dashboards.
Automation & DevSecOps
- Develop reusable Terraform modules for Azure and GCP security configurations.
- Automate security provisioning using Infrastructure as Code.
- Integrate security scanning into CI/CD pipelines, including:
- Infrastructure as Code scanning
- Container image scanning
- Dependency vulnerability scanning
- Implement Policy-as-Code using Azure Policy, GCP Organization Policies, OPA, Sentinel, Checkov, and tfsec.
Collaboration
- Partner with DevOps and Product Engineering teams to implement security controls.
- Design scalable IAM models and enforce least-privilege access.
- Support Security Champion initiatives and internal cloud security knowledge sharing.
- Translate security requirements into practical engineering solutions.
Required Skills Mandatory- 5+ years of hands-on experience securing Microsoft Azure environments.
- 3+ years of hands-on experience securing Google Cloud Platform (GCP) environments.
- Strong expertise with:
- Microsoft Defender for Cloud
- Azure Firewall
- Azure WAF
- Azure Key Vault
- Microsoft Entra ID
- Azure Monitor / Microsoft Sentinel
- Google Security Command Center (SCC)
- GCP IAM
- VPC Networking
- Organization Policies
- BigQuery Security
- Cloud Run Security
- Strong experience with Terraform for Azure and GCP.
- Experience triaging and remediating findings from Defender for Cloud and Google SCC.
- Expertise in cloud networking security:
- Firewalls
- Private Connectivity
- DNS Security
- DDoS Protection
- Strong knowledge of Identity & Access Management:
- RBAC
- Conditional Access
- Workload Identity
- Service Account Governance
- Experience securing Kubernetes environments (AKS/GKE) and container workloads.
Preferred Skills- Microsoft Sentinel or Google Chronicle.
- Azure DDoS Protection.
- Azure Front Door WAF.
- Google Cloud Armor.
- Azure Confidential Computing.
- GCP Assured Workloads.
- Policy-as-Code frameworks:
Certifications (Preferred)
- Microsoft Certified: AZ-500
- Microsoft Certified: SC-100
- Google Professional Cloud Security Engineer
Skills: cloud security,azure,gcp