Posted on: 25/07/2026
Job Summary:
We are looking for a hands-on Cloud Security Architect with strong engineering expertise in securing enterprise workloads across Microsoft Azure and Google Cloud Platform (GCP).
This is an implementation-focused role requiring extensive experience configuring cloud-native security services, automating security controls, and securing cloud infrastructure using Infrastructure as Code (IaC).
The ideal candidate should possess equal hands-on expertise in Azure and GCP, be proficient in Terraform, and work closely with Platform Engineering, DevOps, and Product teams to build secure, scalable cloud environments.
Key Responsibilities:
Cloud Security Engineering:
- Configure and manage Microsoft Defender for Cloud (Servers, Containers, Storage, Key Vault, DNS, Resource Manager).
- Implement and manage Azure Firewall, Network Security Groups (NSGs), Azure WAF, Private Link, and Private Endpoints.
- Administer Azure Key Vault, certificate lifecycle, and workload integration.
- Configure Microsoft Entra ID (Azure AD) including Conditional Access, Privileged Identity Management (PIM), RBAC, Workload Identities, and Service Principal security.
- Manage Google Security Command Center (SCC), including Security Health Analytics, Event Threat Detection, and Container Threat Detection.
- Design and secure GCP VPC architectures, firewall rules, Shared VPC, Private Google Access, and VPC Service Controls.
- Secure BigQuery environments using row/column-level security, authorized views, data masking, and VPC Service Controls.
- Harden Cloud Run deployments with ingress controls, Binary Authorization, service identities, and secret management.
- Implement and manage GCP IAM, custom roles, Organization Policies, Workload Identity Federation, and service account governance.
Cloud Security Architecture:
- Design and evolve enterprise cloud security architecture across Azure and GCP.
- Evaluate security implications of new cloud services before adoption.
- Ensure compliance with ISO 27001, ISO 27017, GDPR, and SOC 2.
- Collaborate with Microsoft and Google technical teams on security best practices.
- Monitor cloud security posture using Secure Score, Defender for Cloud, and Google SCC dashboards.
Automation & DevSecOps:
- Develop reusable Terraform modules for Azure and GCP security configurations.
- Automate security provisioning using Infrastructure as Code.
- Integrate security scanning into CI/CD pipelines, including:
1. Infrastructure as Code scanning.
2. Container image scanning.
3. Dependency vulnerability scanning.
- Implement Policy-as-Code using Azure Policy, GCP Organization Policies, OPA, Sentinel, Checkov, and tfsec.
Collaboration:
- Partner with DevOps and Product Engineering teams to implement security controls.
- Design scalable IAM models and enforce least-privilege access.
- Support Security Champion initiatives and internal cloud security knowledge sharing.
- Translate security requirements into practical engineering solutions.
Required Skills:
- 5+ years of hands-on experience securing Microsoft Azure environments.
- 3+ years of hands-on experience securing Google Cloud Platform (GCP) environments.
- Strong expertise with:
1. Microsoft Defender for Cloud.
2. Azure Firewall.
3. Azure WAF.
4. Azure Key Vault.
5. Microsoft Entra ID.
6. Azure Monitor / Microsoft Sentinel.
7. Google Security Command Center (SCC).
8. GCP IAM.
9. VPC Networking.
10. Organization Policies.
11. BigQuery Security.
12. Cloud Run Security.
- Strong experience with Terraform for Azure and GCP.
- Experience triaging and remediating findings from Defender for Cloud and Google SCC.
- Expertise in cloud networking security:
1. Firewalls.
2. Private Connectivity.
3. DNS Security.
4. DDoS Protection.
- Strong knowledge of Identity & Access Management:
1. RBAC.
2. Conditional Access.
3. Workload Identity.
4. Service Account Governance.
- Experience securing Kubernetes environments (AKS/GKE) and container workloads.
Preferred Skills:
- Microsoft Sentinel or Google Chronicle.
- Azure DDoS Protection.
- Azure Front Door WAF.
- Google Cloud Armor.
- Azure Confidential Computing.
- GCP Assured Workloads.
- Policy-as-Code frameworks:
1. OPA.
2. Sentinel.
3. Checkov.
4. tfsec.
Certifications (Preferred):
- Microsoft Certified: AZ-500.
- Microsoft Certified: SC-100.
- Google Professional Cloud Security Engineer.
Skills:
- cloud security, azure, gcp.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1657810