Z

Cloud Security Engineer(Azure & GCP)

Job Description - Cloud Security Engineer(Azure & GCP)

Job Summary


We are looking for a hands-on Cloud Security Architect with strong engineering expertise in securing enterprise workloads across Microsoft Azure and Google Cloud Platform (GCP). This is an implementation-focused role requiring extensive experience configuring cloud-native security services, automating security controls, and securing cloud infrastructure using Infrastructure as Code (IaC).


The ideal candidate should possess equal hands-on expertise in Azure and GCP, be proficient in Terraform, and work closely with Platform Engineering, DevOps, and Product teams to build secure, scalable cloud environments.


Key Responsibilities Cloud Security Engineering



  • Configure and manage Microsoft Defender for Cloud (Servers, Containers, Storage, Key Vault, DNS, Resource Manager).

  • Implement and manage Azure Firewall, Network Security Groups (NSGs), Azure WAF, Private Link, and Private Endpoints.

  • Administer Azure Key Vault, certificate lifecycle, and workload integration.

  • Configure Microsoft Entra ID (Azure AD) including Conditional Access, Privileged Identity Management (PIM), RBAC, Workload Identities, and Service Principal security.

  • Manage Google Security Command Center (SCC), including Security Health Analytics, Event Threat Detection, and Container Threat Detection.

  • Design and secure GCP VPC architectures, firewall rules, Shared VPC, Private Google Access, and VPC Service Controls.

  • Secure BigQuery environments using row/column-level security, authorized views, data masking, and VPC Service Controls.

  • Harden Cloud Run deployments with ingress controls, Binary Authorization, service identities, and secret management.

  • Implement and manage GCP IAM, custom roles, Organization Policies, Workload Identity Federation, and service account governance.


Cloud Security Architecture



  • Design and evolve enterprise cloud security architecture across Azure and GCP.

  • Evaluate security implications of new cloud services before adoption.

  • Ensure compliance with ISO 27001, ISO 27017, GDPR, and SOC 2.

  • Collaborate with Microsoft and Google technical teams on security best practices.

  • Monitor cloud security posture using Secure Score, Defender for Cloud, and Google SCC dashboards.


Automation & DevSecOps



  • Develop reusable Terraform modules for Azure and GCP security configurations.

  • Automate security provisioning using Infrastructure as Code.

  • Integrate security scanning into CI/CD pipelines, including:

    • Infrastructure as Code scanning

    • Container image scanning

    • Dependency vulnerability scanning



  • Implement Policy-as-Code using Azure Policy, GCP Organization Policies, OPA, Sentinel, Checkov, and tfsec.


Collaboration



  • Partner with DevOps and Product Engineering teams to implement security controls.

  • Design scalable IAM models and enforce least-privilege access.

  • Support Security Champion initiatives and internal cloud security knowledge sharing.

  • Translate security requirements into practical engineering solutions.


Required Skills Mandatory



  • 5+ years of hands-on experience securing Microsoft Azure environments.

  • 3+ years of hands-on experience securing Google Cloud Platform (GCP) environments.

  • Strong expertise with:

    • Microsoft Defender for Cloud

    • Azure Firewall

    • Azure WAF

    • Azure Key Vault

    • Microsoft Entra ID

    • Azure Monitor / Microsoft Sentinel

    • Google Security Command Center (SCC)

    • GCP IAM

    • VPC Networking

    • Organization Policies

    • BigQuery Security

    • Cloud Run Security



  • Strong experience with Terraform for Azure and GCP.

  • Experience triaging and remediating findings from Defender for Cloud and Google SCC.

  • Expertise in cloud networking security:

    • Firewalls

    • Private Connectivity

    • DNS Security

    • DDoS Protection



  • Strong knowledge of Identity & Access Management:

    • RBAC

    • Conditional Access

    • Workload Identity

    • Service Account Governance



  • Experience securing Kubernetes environments (AKS/GKE) and container workloads.


Preferred Skills



  • Microsoft Sentinel or Google Chronicle.

  • Azure DDoS Protection.

  • Azure Front Door WAF.

  • Google Cloud Armor.

  • Azure Confidential Computing.

  • GCP Assured Workloads.

  • Policy-as-Code frameworks:

    • OPA

    • Sentinel

    • Checkov

    • tfsec




Certifications (Preferred)



  • Microsoft Certified: AZ-500

  • Microsoft Certified: SC-100

  • Google Professional Cloud Security Engineer

Original job Cloud Security Engineer(Azure & GCP) posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar Cloud Security Engineer Jobs in India

GrabJobs is the no1 job portal in India, connecting you to thousands of jobs fast! Find the best jobs in India, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.