Experience
10 - 15 yrs
Job Location
Hyderabad, India
Vacancy
1
Designation
Security Engineer
Job Type
Not specified
Job Description
Job Summary
Principal Cybersecurity Engineer
Responsibilities
- Design, implement, and own the Azure Landing Zone security architecture, including:
- Azure Policies and Policy Initiatives
- Guardrails, RBAC models, management groups, and subscription architecture
- Lead implementation and day-to-day management of enterprise security platforms, including:
- CrowdStrike (endpoint protection, detection, and response)
- Proofpoint (email security, phishing protection, and threat intelligence)
- Rapid7 (vulnerability management, exposure analytics, and threat detection)
- Checkmarx (SAST, DAST, SCA, code security governance)
- Wiz (CNAPP / CSPM / workload and cloud risk visibility)
- Implement and operationalize Azure Policy for:
- Resource tagging, region restrictions, SKU allowlists
- Encryption, data residency, and compliance guardrails
- Deploy, tune, and manage:
- Microsoft Defender for Cloud (CSPM/CWPP)
- Defender for Identity
- Container and AKS security controls
- Stand up and evolve Microsoft Sentinel (SIEM/SOAR) :
- Data connectors, analytics rules, UEBA
- Threat enrichment and automated response playbooks
- Implement Policy-as-Code and Security Baselines-as-Code using GitOps practices.
- Maintain enterprise risk register, report security KPIs to leadership, and partner with risk, compliance, and audit teams.
- Run purple-team style control validation, lead incident response runbooks, and drive post-incident improvements.
- Establish and govern network security architectures :
- Hub-spoke / vWAN
- Private Endpoints, Azure Firewall, WAF, DDoS
What would your day look like
- Partner with Engineering, Network, and Platform teams to design and operate a secure, compliant Azure platform and Snowflake tenant.
- Analyze and audit platform and application codebases using Checkmarx and related tooling to identify vulnerabilities and compliance gaps.
- Act as a security authority on the Architecture Review Board, shaping approved application and cloud design patterns.
- Collaborate with vendors and partners on security assessments and remediation strategies (CrowdStrike, Proofpoint, Rapid7, Wiz).
- Continuously monitor threats and alerts; define SOPs and train L1/L2 teams for effective triage and escalation.
- Drive sprint delivery for security initiatives with high quality and on-time execution.
Who are we looking for
- 10+ years of cybersecurity experience with 5+ years focused on Azure cloud security architecture.
- Deep expertise in:
Azure RBAC, Microsoft Entra ID, Conditional Access
PIM / PIM for Groups, Identity Governance
Strong hands-on experience with:
CrowdStrike, Proofpoint, Rapid7, Checkmarx, Wiz
Defender for Cloud, Microsoft Sentinel, Azure Firewall, WAF
- Proven experience delivering Azure Landing Zones aligned to Microsoft Cloud Adoption Framework and Well-Architected principles.
- Strong identity federation knowledge (SAML, OAuth2/OIDC), SCIM provisioning, and B2B integrations.
- Automation-first mindset with PowerShell, Python, Terraform, Bicep, Git, YAML, and CI/CD workflows.
Required Skills
- Expert-level Microsoft Entra ID, Conditional Access, PIM, RBAC, and identity governance
- Enterprise-scale Azure network security and private connectivity design
- Deep experience implementing CNAPP, EDR, email security, vuln management, and code security platforms
- Strong DevSecOps background including SAST/DAST, IaC scanning, and API security
- Mature incident response, observability, and alert tuning experience
- Familiarity with AI/LLM security patterns (Azure OpenAI, RAG architectures)
- Strong experience with Azure network security, including VNet architecture, private endpoints, DDoS, WAF, and Azure Firewall
- Hands-on experience implementing Defender for Cloud, Sentinel SIEM/SOAR, and cloud threat-detection pipelines
- Demonstrated ability to design Azure Policy, policy-as-code
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.