Position-Cloud Platform Engineer - Infrastructure & Security
Location- Gurgaon(Hybrid)
Job Description
Division/Department: Technology, Platforms
Reports to: Cloud Platform Technical Team Lead (MGCC)
The Role
The Cloud Platform Engineer - Infrastructure & Security is a hands-on technical role within the Cloud Platformengineering capability. The role is focused on building, securing and operating hybrid cloud platform, bridgingMicrosoft Azure and on-premises data centres to support infrastructure services that must be reliable, secure, observable and recoverable.
Working under the day-to-day direction of the Cloud Platform Technical Team Lead (MGCC), the engineer will deliverinfrastructure and security engineering tasks across Azure IaaS/PaaS, Azure Local, Windows Server, identity, networking,vulnerability management and backup/recovery services.
The role reports to the Cloud Platform Technical Team Lead (MGCC), who provides day-to-day direction and coordinatesdelivery activities within MGCC. The role supports the delivery of cloud platform priorities, standards and engineeringobjectives defined by the wider Cloud Platform function. Technical recommendations, improvement opportunities andproposed changes are reviewed through the appropriate platform leadership, governance and change managementprocesses to ensure alignment with platform objectives and architectural standards.
The purpose of this role is to deliver against approved direction, work within agreed engineering standards and changecontrol, and help improve the platform through the proper channels. The role participates in a structured 24/7 on-callrotation to support critical infrastructure incidents and maintain platform SLA targets.
Duties and Responsibilities
Hybrid Infrastructure Engineering
- Deliver, configure and support Azure IaaS services including virtual machines, Virtual Networks, subnets, NSGs,route tables, load balancers, private endpoints, Storage Accounts and managed disks.
- Support Azure PaaS services including Azure SQL, App Services, AKS, Key Vault, Azure Monitor and related platformdependencies.
- Operate Azure Local environments deployed on HPE ProLiant/Apollo server platforms, including cluster health, nodelifecycle, capacity, firmware/driver awareness and operational monitoring.
- Use HPE iLO and HPE OneView for hardware monitoring, lifecycle visibility, remote management and coordination ofplanned maintenance activities.
- Support on-premises and hybrid infrastructure services including Windows Server, Hyper-V/virtualisation, VMwarewhere applicable, storage platforms, DFS, DNS, DHCP and core network dependencies.
Security & Vulnerability Management
- Operate vulnerability scanning, assessment and remediation processes using Tenable.io, Tenable.sc and/or TenableOne, working with platform teams to validate, prioritise and remediate findings.
- Support Microsoft Defender for Cloud posture management, secure score improvement, workload protectionrecommendations and remediation tracking across Azure and hybrid services.
- Implement and maintain Azure governance and security controls including Azure Policy, RBAC, Privileged IdentityManagement (PIM), Management Groups, subscription governance, tagging and resource organisation.
- Support Azure Key Vault implementation and operational controls for secrets, keys, certificates, rotation, accesspolicies/RBAC and auditability.
- Contribute to patching, hardening, baseline compliance and Cyber Essentials Plus remediation activities acrosscloud, hybrid and on-premises infrastructure.
Identity & Integration
- Support on-premises Active Directory Domain Controllers, sites and services, Group Policy Objects, OU structures,DNS integration and related authentication dependencies.
- Support Microsoft Entra ID and hybrid identity services, including Entra Connect synchronisation, identity lifecycledependencies, Conditional Access awareness and cloud/on-premises identity integration.
- Support secure integration patterns using OIDC, SAML, OAuth, service principals, managed identities, APIpermissions and certificate-based authentication.
- Support hybrid Exchange environments, including Exchange Server coexistence with Exchange Online, mail flowdependencies, connectors, certificates and related identity/security controls.
Automation, IaC & Engineering Improvement
- Develop and maintain automation using advanced PowerShell for Azure, Windows Server, Active Directory, Exchange,vulnerability remediation, monitoring, reporting and operational housekeeping.
- Build and support Infrastructure-as-Code using Terraform and Bicep, ensuring deployments are repeatable,reviewed, documented and aligned with approved standards.
- Contribute to Azure DevOps/Git-based delivery practices including source control, pull requests, CI/CD pipelines,deployment validation and release documentation.
- Identify opportunities to automate recurring operational checks, remediation tasks, reporting processes andevidence collection, raising proposals via the Team Lead for UK approval before implementation.
Operational Resilience, Backup & Service Management
- Design, support and test Business Continuity and Disaster Recovery (BCDR) capabilities across Azure and hybridinfrastructure services.
- Operate backup and recovery capabilities using Veeam Data Cloud for cloud/SaaS backup scenarios and Azure SiteRecovery (ASR) for infrastructure failover and recovery orchestration.
- Support disaster recovery exercises, restore testing, failover/failback planning, recovery time objective/recovery pointobjective validation and lessons learned actions.
- Provide 2nd/3rd line technical escalation for complex infrastructure and security incidents in an ITIL-alignedenvironment.
- Participate in a structured 24/7 on-call rotation for critical infrastructure incidents, major incidents and platform SLAprotection.
Skills/Experience
Essential
- Strong hands-on experience supporting hybrid cloud infrastructure across Microsoft Azure and on-premises datacentre environments.
- Deep experience with Azure IaaS including VMs, Virtual Networks, Storage Accounts, NSGs, routing, privateendpoints, load balancing, backup/recovery and monitoring.
- Good working knowledge of Azure PaaS services including Azure SQL, App Services, AKS, Key Vault, Azure Monitorand Log Analytics.
- Experience operating Azure Local / Azure Stack HCI or comparable hyperconverged infrastructure, ideally on HPEProLiant/Apollo hardware with HPE iLO and OneView management exposure.
- Strong Windows Server administration experience, including Active Directory, DNS, DHCP, GPO, DFS, certificates,clustering and enterprise server lifecycle management.
- Experience with hybrid identity using Microsoft Entra ID, Entra Connect, Conditional Access concepts, RBAC, PIMand secure access models.
- Experience supporting hybrid Exchange environments, Exchange Online integration, transport/connectors,certificates and mail flow troubleshooting.
- Hands-on experience with vulnerability management tooling such as Tenable.io, Tenable.sc or Tenable One, includingremediation planning and reporting.
- Experience with Microsoft Defender for Cloud, Azure Policy, secure score/recommendations, workload protectionand cloud security posture management.
- Advanced PowerShell scripting capability for infrastructure automation, reporting, remediation and operationalchecks.
- Experience with Terraform and/or Bicep for Infrastructure-as-Code, ideally delivered through Azure DevOps/Gitbasedworkflows.
- Experience with enterprise backup and resilience tooling, including Veeam Data Cloud and Azure Site Recovery.
- Good understanding of networking technologies including ExpressRoute, VPN, vWAN, DNS, firewall dependencies,load balancing, Cisco/Meraki concepts and hybrid connectivity patterns.
- Experience working within ITIL-aligned incident, problem, change and service transition processes.
Desirable
- Experience supporting monitoring and observability platforms such as Azure Monitor, Log Analytics, SolarWinds,ManageEngine or similar tooling.
- Experience with VMware, Hyper-V, Windows Failover Clustering, SQL clustering or enterprise storage platforms.
- Experience supporting Cyber Essentials Plus, audit evidence gathering, vulnerability exceptions and securityremediation reporting.
- Experience with Microsoft Sentinel, Defender for Endpoint, Defender for Servers or related Microsoft security tooling.
- Experience working in a global delivery or oshore/onshore operating model.
Skills/Attributes
- Clear, structured communicator able to explain technical risks, dependencies and remediation options to bothtechnical and non-technical stakeholders.
- Strong ownership mindset with the ability to drive assigned tasks through to completion while respecting approvedstandards, escalation routes and change governance.
- Calm and methodical under pressure, particularly during critical incidents, service restoration and out-of-hourssupport situations.
- Excellent documentation discipline, with the ability to produce accurate runbooks, support guides, diagrams, changerecords and operational evidence.
- Proactive approach to service improvement, automation and risk reduction, with the judgement to raiserecommendations through the correct channels before implementation.
- Comfortable working in a distributed onshore/oshore model across time zones, collaborating with UK platformleadership, MGCC engineers, Security, Networks, Modern Workplace, Service Management and vendors.
- Strong analytical troubleshooting skills across infrastructure, identity, security, network and application dependencylayers.
Preferred Qualifications
- Microsoft Certified: Azure Administrator Associate (AZ-104).
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305).
- Microsoft Certified: Azure Security Engineer Associate (AZ-500).
- Microsoft Certified: Identity and Access Administrator Associate (SC-300).
- Microsoft Certified: Security Operations Analyst Associate (SC-200) or Security, Compliance and Identity Fundamentals (SC-900).
- Microsoft Certified: DevOps Engineer Expert (AZ-400) or equivalent Azure DevOps/IaC experience.
- Terraform Associate or equivalent practical Terraform experience.
- ITIL Foundation or equivalent practical experience in an ITIL-aligned service environment.
- HPE, VMware, Veeam, Tenable or relevant vendor certifications would be advantageous.
Please note that this job profile is not an exhaustive list of duties but merely an outline of the key components of the role.
You may be required by your line manager to take on additional responsibilities when requested.