Job Description Cloud Engineer
Position Details & Role Overview
Position Title: Cloud Engineer (Level 3 / Senior)
Department: Cloud Engineering & Technology
Experience: 10+years
Employment Type: Full-Time
Location : Hyderabad WFO (Preferred candidates must from Hyderabad)
The Cloud Engineer designs, builds, secures and supports the company's cloud and hybrid infrastructure, with Microsoft Azure as the primary platform. The role is the final technical escalation point for cloud infrastructure incidents and owns them through to a permanent fix.
Security is part of the job, not a separate function: the engineer builds identity, network and workload controls into every deployment, monitors for threats, and supports audits. Strong hands‑on skills in cloud networking, automation (Infrastructure as Code) and troubleshooting are essential.
Key Responsibilities
The work falls into eight areas: running cloud infrastructure, networking, identity, security monitoring, automation, recovery, incident ownership, and compliance.
1. Cloud Infrastructure & Operations
- Design, deploy and maintain cloud infrastructure on Microsoft Azure (VMs, storage, compute); AWS or GCP exposure is a plus.
- Act as Level 3 escalation for complex cloud incidents passed on by L1/L2, using logs and metrics to find root causes.
- Manage the lifecycle of cloud servers (Windows and Linux): provisioning, configuration, patching, upgrades and decommissioning.
- Support hybrid on-premises/cloud environments, including migrations and modernization projects.
- Monitor resource health, capacity and performance, and act before issues cause business impact.
2. Cloud Networking & Hybrid Connectivity
- Configure and maintain VNet/VPC, subnets, NSGs/security groups, route tables, firewalls, load balancers and DNS.
- Build and troubleshoot Site-to-Site VPN connectivity between on-premises sites and the cloud.
- Validate routing, firewall rules and network paths when diagnosing connectivity issues, working with network teams as needed.
3. Identity, Access & Data Protection
- Manage IAM, RBAC, MFA and Conditional Access, applying least‑privilege access across cloud resources.
- Implement encryption, key management, and secrets management.
- Apply server and workload hardening baselines.
4. Security Monitoring, Vulnerability & Incident Response
- Set up security monitoring, logging and alerting; watch for threats and suspicious activity (for example in Microsoft Defender for Cloud and Entra ID).
- Run vulnerability assessments and drive patching and remediation to closure.
- Investigate and respond to cloud security incidents, and support security teams with evidence and analysis.
- Secure cloud workloads, containers, APIs and databases where they are in scope.
5. Automation, IaC & DevSecOps
- Build and manage infrastructure with Infrastructure as Code (Terraform, Bicep/ARM or CloudFormation).
- Automate operations and security tasks with PowerShell, Python or Bash.
- Work with development teams to integrate security checks into CI/CD pipelines.
6. Backup, Recovery & Disaster Recovery
- Monitor and validate cloud backups (Azure Backup, plus Veeam or Backblaze where in use) and fix failed or incomplete jobs.
- Perform file, VM and server restores when needed.
- Take part in disaster recovery planning, testing and validation.
7. Incident, Problem & Change Management
- Own escalated incidents through to resolution, with timely technical updates and bridge‑call participation for major incidents.
- Run root‑cause analysis, find permanent fixes instead of workarounds, and support Problem Management.
- Implement approved changes under change‑management procedures, then validate and monitor.
- Mentor L1/L2 engineers and share knowledge.
8. Compliance, Documentation & Continuous Improvement
- Support security audits, compliance requirements and risk assessments, including evidence collection.
- Maintain cloud security standards, SOPs, KB articles, build documents, recovery procedures and architecture/network diagrams.
- Work with cloud providers, vendors and internal teams, and recommend improvements, including emerging cloud and security technologies.
Required Technical Skills
Candidates need hands‑on production experience in Azure, cloud networking, identity and access management, and automation.
Skills
Cloud platforms
Microsoft Azure (VMs, Storage, VNet, subnets, NSGs, route tables, Azure VPN, load balancers); working knowledge of AWS or GCP is an advantage
Operating systems
Windows Server and Linux administration, troubleshooting and patching
Networking
TCP/IP, DNS, VPN, routing, firewalls, load balancing, SSL/TLS and certificate management
Identity & security
IAM, RBAC, MFA, Conditional Access, Microsoft Entra ID, encryption, key and secrets management, server hardening
Monitoring & response
Security monitoring and logging tools, Microsoft Defender, vulnerability management, incident response
Automation & IaC
Terraform, Bicep/ARM or CloudFormation; scripting in PowerShell, Python or Bash
DevSecOps
CI/CD tools and pipeline security integration
Backup & DR
Azure Backup and Site Recovery; backup monitoring, VM/server restoration, disaster recovery testing
Hybrid infrastructure
On premises to cloud connectivity, migration and coexistence
Preferred Skills & Certifications
These are not mandatory, but they strengthen a candidacy.
Preferred skills
- Docker, Kubernetes and container security.
- Experience in an ITIL-based environment covering Incident, Problem, Change and Major Incident Management.
- Experience supporting 24x7 production environments, with monitoring and ticketing platforms.
- Familiarity with on-premises virtualization (VMware, Hyper‑V or Proxmox) in hybrid setups.
- Strong documentation skills and the ability to explain issues to technical and non‑technical stakeholders.
- Microsoft 365 and Exchange Online administration, including SharePoint and Power BI Pro licensing.
- Email DNS records (SPF, DKIM, DMARC) and mail‑flow troubleshooting.
- Day‑to‑day Active Directory, Group Policy (GPO) and DHCP administration in hybrid environments.
- File server and application server administration.
Preferred certifications
- Microsoft Certified: Azure Administrator Associate
- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Security Specialty or Google Professional Cloud Security Engineer
- Certified Cloud Security Professional (CCSP)
- CompTIA Security+
- ITIL Foundation
- Veeam certifications
- VMware certifications
- Certified Information Systems Security Professional (CISSP)
Qualifications & Experience
The role needs 58 years of hands‑on cloud or infrastructure experience, including time as a senior or escalation‑level engineer.
- Bachelor's degree (or equivalent) in Computer Science, Information Technology, Cyber Security or a related field.
- 5-8 years in cloud engineering, systems administration or infrastructure operations, with production Windows/Linux and cloud environments.
- Demonstrated experience at Level 3 / senior escalation level, owning complex incidents to resolution.
- Strong troubleshooting, root‑cause analysis and problem‑solving skills.
- Relevant cloud and security certifications are an added advantage.
Performance Expectations & Working Model
The engineer is measured on keeping cloud environments secure, available and compliant, and on how quickly and permanently incidents are resolved.
Performance measures
- Cloud environment availability and uptime
- SLA compliance and Mean Time to Resolve (MTTR)
- Critical incident resolution and reduction in recurring incidents
- Timely detection of, and response to, security incidents
- Patch compliance and vulnerability remediation
- Backup success rate and disaster recovery test success
- Change success rate
- Compliance with organizational and industry security standards
- Documentation and KB compliance
- Stakeholder satisfaction
Working model
- Work from office in Hyderabad.
- Take part in on‑call, weekend or after‑hours support for critical infrastructure when required.
- Join major incident bridges and planned maintenance windows.
- Collaborate with network, security, application, development and cloud provider teams.