Review and assess existing and new Azure services, resources, architectures, and configurations for security risks, compliance requirements,
vulnerabilities, and misconfigurations.
Develop, test, deploy, and maintain Azure Policy definitions, initiatives, assignments, guardrails, exemptions, and approved allow policies;
evaluate policy impacts and troubleshoot deployment or operational issues.
Develop and maintain Terraform modules and security controls, using Terraform as the primary infrastructure-as code (laC) tool for Azure security
and policy deployment.
Work with JSON-based configurations and templates, including those supporting Azure service certifications and security requirements.
Use Git and GitHub to manage infrastructure-as-code and security policy changes, including validating GitHub Actions workflows and pull requests
(PRs) as needed.
Monitor Azure environments for security findings, vulnerabilities, misconfigurations, and policy violations; recommend remediation actions and
partner with application and engineering teams to track findings through resolution
Support cloud security operations, incident investigations, and troubleshooting, collaborating with cloud engineering, architecture, risk,
compliance, cybersecurity, and CSE teams as needed.
Apply cloud security principles across a multi-cloud environment, with Azure as the primary focus and AWS, Google Cloud Platform, and OCT as secondary platforms.
Maintain clear documentation for security policies, standards, service certifications, exceptions, guardrails, and operational procedures.
Strong knowledge of Microsoft Azure, including Azure security, networking, identity, resource management, and security best practices.
Hands-on experience with Azure Policy, including policy definitions, initiatives, assignments, exemptions, compliance evaluation, and remediation.
Experience securing and supporting enterprise-scale Azure environments.
Strong understanding of cloud security, risk, governance, and compliance concepts.
Hands-on experience with Terraform for infrastructure-as-code, security controls, and policy deployment.
Familiarity with JSON for cloud configurations, policy definitions, templates, and service certification requirements.
Familiarity with Git and GitHub, including source control, pull requests, and GitHub Actions.