Cloud Engineer
Tata Consultancy Services
2 - 5 years
Chennai
Posted: 23/12/2025
Getting a referral is 5x more effective than applying directly
Job Description
ROLES AND RESPONSIBILITIES
Location : Chennai
- Design Azure landing zones and security reference architectures aligned to Zero Trust.
- Establish enterprise guardrails using Azure Policy, Management Groups, and RBAC with Privileged Identity Management (PIM).
- Own CSPM posture via Microsoft Defender for Cloud
- Operate and optimize Microsoft Defender XDR for end-to-end detection and response.
- Manage Microsoft Sentinel (SIEM/SOAR): KQL analytics, hunting, UEBA, playbooks (Logic Apps), and incident workflows.
- Lead incident response: triage, containment, forensics (Log Analytics, snapshots), root cause analysis, stakeholder communication.
- Administer Microsoft Defender for Cloud Apps (MDCA) for app discovery, OAuth app governance, session controls, DLP, and data protection.
- Implement Conditional Access + MDCA session policies for inline control across key SaaS applications.
- Secure workloads using Defender for Cloud plans (VMs, Storage, SQL, AKS, App Services): hardening, vulnerability management, agent coverage.
- Drive AKS security: network policies, identity, secrets, image scanning, admission controls; secure ACR and supply chain flows.
- Implement controls: Azure Firewall, NSGs, DDoS Protection, Bastion, JIT VM access.
- Protect applications via Azure WAF (App Gateway/Front Door), TLS cert lifecycle, and bot management.
- Administer Entra ID (Azure AD): Conditional Access, MFA, CAE, Identity Protection, PIM, workload identities/managed identities.
- Enforce encryption and secrets management via Azure Key Vault (HSM-backed keys, CMK, rotation).
- Implement DLP across M365/MDCA; label/classify sensitive data and enforce policies.
- Build policy-as-code and IaC guardrails: Bicep/ARM, Terraform modules, drift detection.
- Automate operations using PowerShell, Azure CLI, and Python; integrate security telemetry and auto-remediation via Logic Apps/Functions.
- Map controls to CIS/NIST/ISO/PCI; maintain audit evidence and control attestation.
- Provide posture dashboards, metrics (Secure Score, incident MTTR), and executive reporting.
Author standards, playbooks, and decision records; mentor teams and lead design reviews.
Services you might be interested in
Improve Your Resume Today
Boost your chances with professional resume services!
Get expert-reviewed, ATS-optimized resumes tailored for your experience level. Start your journey now.
