Padmi

Azure network and security architect

HyderabadPosted 2 months ago
Infrastructure And DatabasesSeniorFull Time; Regular
Apply at ValueLabs

Opens the source posting on shine.com

Source description

About the role

View original

Role Overview: You will be responsible for designing and implementing enterprise-grade Azure Landing Zones aligned with Microsoft Cloud Adoption Framework (CAF), Azure Enterprise-Scale Architecture, and Zero Trust Security Model. You will define and implement Management Groups hierarchy, Subscription strategy, Resource organization standards, Naming conventions, tagging strategy, RBAC, identity governance, and Policy-driven governance and compliance. Additionally, you will establish multi-subscription, multi-environment architecture and architect secure and scalable network topologies in Azure. Key Responsibilities: - Design and implement enterprise-grade Azure Landing Zones aligned with Microsoft Cloud Adoption Framework (CAF), Azure Enterprise-Scale Architecture, and Zero Trust Security Model - Define and implement Management Groups hierarchy, Subscription strategy, Resource organization standards, Naming conventions, tagging strategy, RBAC, identity governance, and Policy-driven governance and compliance - Establish multi-subscription, multi-environment (Prod/Non-Prod/Sandbox) architecture - Architect secure and scalable network topologies including Hub-and-Spoke / Virtual WAN architectures, ExpressRoute, Site-to-Site VPN connectivity, Private Endpoints, Private DNS Zones, Azure Firewall, NSGs, ASGs, Route Tables, Load Balancers, Application Gateway, and Front Door - Implement network security controls, traffic inspection models, IP addressing strategy, and network segmentation - Implement enterprise security posture using Microsoft Defender for Cloud, Azure Policy, Initiative assignments, Azure Blueprints, Conditional Access, Identity Protection, Privileged Identity Management (PIM) - Design secure identity architecture using Azure AD, RBAC models, Managed Identities - Ensure compliance with regulatory standards (ISO, SOC2, CIS, NIST) - Develop reusable, modular Infrastructure-as-Code using Terraform and/or Bicep - Create standardized deployment pipelines using Azure DevOps / GitHub Actions - Implement CI/CD practices for infrastructure delivery and enforce version control, peer reviews, testing, and promotion pipelines - Automate provisioning, governance, security baselines, and guardrails - Design for high availability, disaster recovery, backup and recovery, scalability, and performance optimization - Implement observability using Azure Monitor, Log Analytics, Application Insights - Enable cost governance through Cost Management + Billing, budgeting, chargeback/showback models, and rightsizing Qualification Required: - Strong hands-on expertise with Microsoft Azure platform, Azure Landing Zone design, Enterprise networking architectures, Identity and access management, Azure security tooling and governance - Expert-level proficiency in Terraform and/or Bicep, Git-based workflows, CI/CD pipelines for infrastructure - Deep knowledge of TCP/IP, DNS, routing, firewall concepts, Hybrid connectivity models, Cloud security best practices, Infrastructure automation patterns - Experience working in multi-subscription, enterprise environments Additional Company Details: Omit this section as no additional details of the company are present in the provided job description. Role Overview: You will be responsible for designing and implementing enterprise-grade Azure Landing Zones aligned with Microsoft Cloud Adoption Framework (CAF), Azure Enterprise-Scale Architecture, and Zero Trust Security Model. You will define and implement Management Groups hierarchy, Subscription strategy, Resource organization standards, Naming conventions, tagging strategy, RBAC, identity governance, and Policy-driven governance and compliance. Additionally, you will establish multi-subscription, multi-environment architecture and architect secure and scalable network topologies in Azure. Key Responsibilities: - Design and implement enterprise-grade Azure Landing Zones aligned with Microsoft Cloud Adoption Framework (CAF), Azure Enterprise-Scale Architecture, and Zero Trust Security Model - Define and implement Management Groups hierarchy, Subscription strategy, Resource organization standards, Naming conventions, tagging strategy, RBAC, identity governance, and Policy-driven governance and compliance - Establish multi-subscription, multi-environment (Prod/Non-Prod/Sandbox) architecture - Architect secure and scalable network topologies including Hub-and-Spoke / Virtual WAN architectures, ExpressRoute, Site-to-Site VPN connectivity, Private Endpoints, Private DNS Zones, Azure Firewall, NSGs, ASGs, Route Tables, Load Balancers, Application Gateway, and Front Door - Implement network security controls, traffic inspection models, IP addressing strategy, and network segmentation - Implement enterprise security posture using Microsoft Defender for Cloud, Azure Policy, Initiative assignments, Azure Blueprints, Conditional Access, Identity Protection, Privileged Identity Management (PIM) - Design secure identity architecture using Azure AD,

One address, no account. We’ll tell you when matching roles go live.

More at ValueLabs

Related open roles

View all roles