Key Skills: Microsoft Entra, Azure, Azure Devops, Identity Access Management, Azurecloud, Azure Governance, Policy, IAC, Terraform, Pipeline
Roles and Responsibilities:
- Implement and manage Azure security controls using Azure Defender for Cloud, governance policies, and security baselines.
- Configure and support identity and access security using Entra ID, IAM, and Privileged Identity Management (PIM).
- Design and enforce Azure governance, policy, and compliance controls across enterprise platforms.
- Integrate security controls into CI/CD pipelines and DevOps workflows, including SAST, DAST, and container image scanning.
- Review and secure Infrastructure as Code (Terraform) with embedded security controls and policy enforcement.
- Support vulnerability management, remediation tracking, security posture assessments, and compliance requirements.
- Develop security automation scripts and tooling using Python, Bash, or PowerShell to improve security operations efficiency.
- Partner with platform, DevOps, and security teams to improve cloud security posture and support audits, documentation, and security runbooks.
Skills Required:
- Strong hands-on experience with Microsoft Azure cloud security and governance practices.
- Good understanding of Microsoft Entra ID, IAM, and Privileged Identity Management (PIM).
- Experience implementing Azure Governance, Azure Policy, and compliance management controls.
- Expertise in DevSecOps practices including SAST, DAST, container image scanning, and secure CI/CD pipelines.
- Strong knowledge of Terraform and Infrastructure as Code security practices.
- Experience with Microsoft Defender for Cloud and vulnerability management processes.
- Proficiency in scripting and automation using Python, Bash, or PowerShell.
- Understanding of secrets management and secure access control mechanisms.
- Familiarity with cloud security best practices, risk management, and security compliance frameworks.
- Ability to collaborate effectively with cross-functional platform, DevOps, and security teams.
Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.