Key Skills: Microsoft Entra, Azure, Azure Cloud, Azure Devops, Azure Governance, Policy, Identity Access Management, Terraform
Roles and Responsibilities:
- Implement and manage Azure security controls using Azure Defender for Cloud, governance policies, and security baselines.
- Configure and support identity and access security using Entra ID, IAM, and Privileged Identity Management (PIM).
- Design and enforce Azure governance, policy, and compliance controls across enterprise platforms.
- Integrate security controls into CI/CD pipelines and DevOps workflows, including SAST, DAST, and container image scanning.
- Review and secure Infrastructure as Code (Terraform) with embedded security controls and policy enforcement.
- Support vulnerability management, remediation tracking, security posture assessments, and compliance requirements.
- Develop security automation scripts using Python, Bash, or PowerShell to improve security operations efficiency.
- Partner with platform and engineering teams to embed security into cloud-native deployments and support audits, documentation, and security runbooks.
Skills Required:
- Strong hands-on experience with Microsoft Azure cloud security and governance frameworks.
- Strong understanding of Microsoft Entra ID, IAM, PIM, and identity security best practices.
- Experience implementing Azure Policy, Azure Governance, and compliance management controls.
- Expertise in DevSecOps practices including SAST, DAST, container image scanning, and secure CI/CD pipelines.
- Proficiency in Terraform and Infrastructure as Code security practices.
- Experience with Microsoft Defender for Cloud and vulnerability management processes.
- Strong scripting and automation experience using Python, Bash, or PowerShell.
- Good understanding of secrets management and secure access controls.
- Familiarity with cloud security best practices, risk management, and security compliance frameworks.
- Ability to work collaboratively with cross-functional engineering and platform teams.
Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field