HamburgerMenu
hirist

Cloud Security Engineer - Azure & GCP

Zorba Consulting
5 - 10 Years
Bangalore

Posted on: 25/07/2026

Job Description

Job Summary:

We are looking for a hands-on Cloud Security Architect with strong engineering expertise in securing enterprise workloads across Microsoft Azure and Google Cloud Platform (GCP).

This is an implementation-focused role requiring extensive experience configuring cloud-native security services, automating security controls, and securing cloud infrastructure using Infrastructure as Code (IaC).

The ideal candidate should possess equal hands-on expertise in Azure and GCP, be proficient in Terraform, and work closely with Platform Engineering, DevOps, and Product teams to build secure, scalable cloud environments.

Key Responsibilities:

Cloud Security Engineering:

- Configure and manage Microsoft Defender for Cloud (Servers, Containers, Storage, Key Vault, DNS, Resource Manager).

- Implement and manage Azure Firewall, Network Security Groups (NSGs), Azure WAF, Private Link, and Private Endpoints.

- Administer Azure Key Vault, certificate lifecycle, and workload integration.

- Configure Microsoft Entra ID (Azure AD) including Conditional Access, Privileged Identity Management (PIM), RBAC, Workload Identities, and Service Principal security.

- Manage Google Security Command Center (SCC), including Security Health Analytics, Event Threat Detection, and Container Threat Detection.

- Design and secure GCP VPC architectures, firewall rules, Shared VPC, Private Google Access, and VPC Service Controls.

- Secure BigQuery environments using row/column-level security, authorized views, data masking, and VPC Service Controls.

- Harden Cloud Run deployments with ingress controls, Binary Authorization, service identities, and secret management.

- Implement and manage GCP IAM, custom roles, Organization Policies, Workload Identity Federation, and service account governance.

Cloud Security Architecture:

- Design and evolve enterprise cloud security architecture across Azure and GCP.

- Evaluate security implications of new cloud services before adoption.

- Ensure compliance with ISO 27001, ISO 27017, GDPR, and SOC 2.

- Collaborate with Microsoft and Google technical teams on security best practices.

- Monitor cloud security posture using Secure Score, Defender for Cloud, and Google SCC dashboards.

Automation & DevSecOps:

- Develop reusable Terraform modules for Azure and GCP security configurations.

- Automate security provisioning using Infrastructure as Code.

- Integrate security scanning into CI/CD pipelines, including:

1. Infrastructure as Code scanning.

2. Container image scanning.

3. Dependency vulnerability scanning.

- Implement Policy-as-Code using Azure Policy, GCP Organization Policies, OPA, Sentinel, Checkov, and tfsec.

Collaboration:

- Partner with DevOps and Product Engineering teams to implement security controls.

- Design scalable IAM models and enforce least-privilege access.

- Support Security Champion initiatives and internal cloud security knowledge sharing.

- Translate security requirements into practical engineering solutions.

Required Skills:

- 5+ years of hands-on experience securing Microsoft Azure environments.

- 3+ years of hands-on experience securing Google Cloud Platform (GCP) environments.

- Strong expertise with:

1. Microsoft Defender for Cloud.

2. Azure Firewall.

3. Azure WAF.

4. Azure Key Vault.

5. Microsoft Entra ID.

6. Azure Monitor / Microsoft Sentinel.

7. Google Security Command Center (SCC).

8. GCP IAM.

9. VPC Networking.

10. Organization Policies.

11. BigQuery Security.

12. Cloud Run Security.

- Strong experience with Terraform for Azure and GCP.

- Experience triaging and remediating findings from Defender for Cloud and Google SCC.

- Expertise in cloud networking security:

1. Firewalls.

2. Private Connectivity.

3. DNS Security.

4. DDoS Protection.

- Strong knowledge of Identity & Access Management:

1. RBAC.

2. Conditional Access.

3. Workload Identity.

4. Service Account Governance.

- Experience securing Kubernetes environments (AKS/GKE) and container workloads.

Preferred Skills:

- Microsoft Sentinel or Google Chronicle.

- Azure DDoS Protection.

- Azure Front Door WAF.

- Google Cloud Armor.

- Azure Confidential Computing.

- GCP Assured Workloads.

- Policy-as-Code frameworks:

1. OPA.

2. Sentinel.

3. Checkov.

4. tfsec.

Certifications (Preferred):

- Microsoft Certified: AZ-500.

- Microsoft Certified: SC-100.

- Google Professional Cloud Security Engineer.

Skills:

- cloud security, azure, gcp.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...