DevOps & Cloud Security Engineer

StarZen

Haryana

On-site

INR 2,500,000 - 4,000,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

StarZen invites a DevOps & Cloud Security Engineer to Gurugram, India, owning the Azure and Microsoft stack end‑to‑end—from infrastructure and containers to data platforms, security and monitoring.

The role emphasizes architecture design, current documentation, and IaC with Terraform/Bicep, AKS and cloud security practices, including Defender for Cloud and compliance considerations.

Qualifications

  • 3+ years Azure experience with Fabric & OneLake.
  • Experience with Dynamics 365 APIs and ERP integrations.
  • Relational databases with tuning and HA (Azure SQL/SQL Server, PostgreSQL, MySQL).
  • Elasticsearch/OpenSearch cluster administration and OpenSearch tooling.
  • MongoDB replication/sharding and backups.
  • Ability to use AI assistants for scripting, log analysis and automation.
  • Linux administration including kernel patching.
  • Docker & Kubernetes (AKS) in production environments.
  • Terraform or Bicep IaC for provisioning.
  • Networking, DNS, TLS, Nginx, WAF/DDoS protections.
  • Vulnerability management and remediation workflows.
  • Azure Key Vault with rotation policies.

Responsibilities

  • Architect cloud design and maintain up-to-date diagrams and docs.
  • Maintain Azure infrastructure (VMs, VNets, NSGs, App Gateway, Front Door, Entra ID/RBAC) and IaC.
  • Upgrade AKS/Container Apps, manage ACR, and secure image pipelines with CVE scans.
  • Administer relational DBs (Azure SQL/SQL Server, PostgreSQL/MySQL) incl. HA and backups; MongoDB replica sets.
  • Manage Elasticsearch/OpenSearch clusters, retention, shards, and monitoring.
  • Own Data Platform activities with Microsoft Fabric and OneLake; governance and access control.
  • Handle Dynamics 365/ERP APIs, data synchronization, and environment refreshes.
  • Enforce scheduled secret rotation with Azure Key Vault; prevent hardcoded creds.
  • Configure 24x7 monitoring: Azure Monitor, Log Analytics, App Insights, Grafana; set SLIs/SLOs.
  • Implement DDoS/WAF controls; bot protection and geo/IP filtering; maintain alerting pipelines.
  • Document runbooks, SOPs, and asset inventories; ensure production ops readiness.

Skills

Azure
Microsoft Fabric/OneLake
Dynamics 365 APIs
ERP APIs
Relational databases
Elasticsearch/OpenSearch
MongoDB
AI assistants (Claude/ChatGPT)
Linux admin
Docker/Kubernetes (AKS)
Terraform/Bicep
Networking/DNS/TLS
WAF/DDoS bot protection
Vulnerability management
Azure Key Vault
REST/OData integration
scripting (Bash/PowerShell/Python)
CI/CD pipelines
Monitoring/alerting

Tools

Terraform
Bicep
Azure DevOps
GitHub Actions
Docker

Job description

DevOps & Cloud Security Engineer

Experience: 3–5 years | Location: Gurugram | Type: Full-time

Role

Own our entire Azure and Microsoft stack end-to-end — infrastructure, containers, data platform, security and monitoring. You will design the architecture, keep it documented and current, and make sure nothing breaks silently.

Responsibilities
  • Architecture & Design — Design the complete cloud architecture (network, compute, data, security layers), maintain up-to-date diagrams and documentation, and evolve the design as the stack grows.
  • Azure Infrastructure — Manage VMs, VNets, NSGs, App Gateway, Front Door, Entra ID/RBAC and cost optimisation. Infrastructure as Code via Terraform/Bicep.
  • Containers — Run and upgrade AKS / Container Apps and ACR; build hardened, minimal Docker images with CVE scanning in the pipeline.
  • Databases — Administer relational databases (Azure SQL / SQL Server, PostgreSQL / MySQL): schema and index management, query performance tuning, high availability, replication, automated backups and tested point‑in‑time restores. Also manage MongoDB (replica sets, sharding, backups, restore testing).
  • Search & Log Store — Manage Elasticsearch / OpenSearch clusters: index lifecycle and retention policies, shard and node sizing, snapshots, query performance, cluster health monitoring and secure access. Maintain the ELK/EFK stack used for centralised logging where applicable.
  • Data Platform — Own Microsoft Fabric and OneLake: workspace setup, capacity management, access control, pipelines and data governance.
  • Business Application Integrations — Manage Dynamics 365 and ERP environments and their APIs — authentication, integration pipelines, data sync, error handling, rate limits, monitoring and environment refreshes.
  • Secrets Management — Own Azure Key Vault. Enforce a scheduled secret, key and certificate rotation policy; zero hardcoded credentials anywhere.
  • 24×7 Monitoring & Alerting — Set up full‑stack observability (Azure Monitor, Log Analytics, App Insights, Grafana). Define SLIs/SLOs and configure alerts so that any anomaly triggers a notification immediately, routed to the right on‑call channel with minimal noise.
  • Log Retention & Governance — Define and maintain retention policies per log type (application, security, audit, infra) with correct archival tiers and compliance alignment.
  • Security & Vulnerability Management — Continuous scanning across servers, containers and dependencies; triage and remediate CVEs within SLA. Operate Defender for Cloud / Sentinel.
  • DDoS, WAF & Anti‑Crawler — Configure Azure DDoS Protection and WAF; implement rate limiting, geo/IP filtering, bot management, robots.txt policy and anti‑scraping controls.
  • Patch Management — Keep all servers and container images current — OS, kernel, runtimes and libraries — on a documented cadence, with emergency patching for critical CVEs.
  • Automation & Cron Inventory — Maintain CI/CD pipelines (Azure DevOps / GitHub Actions) and a documented register of every cron and scheduled job: what it does, why it exists, schedule, owner and failure alerting.
  • Backup & DR — Own backup strategy across all workloads with regular tested restores and a drilled DR plan (defined RTO/RPO).
  • Documentation — Keep runbooks, SOPs, change logs and asset inventory accurate and current. Undocumented infrastructure is treated as incomplete work.
Must‑Have Skills
  • Azure (3+ yrs) · Microsoft Fabric & OneLake · Dynamics 365 APIs · ERP APIs and integrations · Relational databases (Azure SQL / SQL Server, PostgreSQL or MySQL) incl. query tuning and HA · Elasticsearch / OpenSearch cluster administration · MongoDB · Effective use of AI assistants (Claude / ChatGPT) for scripting, IaC generation, log analysis, debugging and documentation · Linux administration incl. kernel patching · Docker & Kubernetes/AKS · Terraform or Bicep · Networking, DNS, TLS, Nginx · WAF / DDoS / bot protection · Vulnerability management · Azure Key Vault · REST / OData API integration and troubleshooting · Bash / PowerShell / Python · CI/CD pipelines · Monitoring and alerting stacks

Note on AI tools: We expect you to actively use Claude/ChatGPT to work faster — but with judgement. You must be able to review, test and take full ownership of anything AI‑generated before it touches our infrastructure.

Good to Have

Basic working knowledge of AWS (EC2, S3, IAM) and GCP · Microsoft Sentinel / SIEM · Cloudflare · Power Platform / Dataverse · Azure Data Factory or Synapse · ISO 27001 / SOC 2 exposure

Certifications (Preferred)

AZ-104, AZ-400, AZ-500, CKA/CKS

What We Look For

Ownership mindset, disciplined documentation habits, security‑first thinking, and calm handling of production incidents. Willingness to be on‑call.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevOps & Cloud Security Engineer
DevOps & Cloud Security Engineer

StarZen • Gurugram District

On-site
INR 1,500,000 - 2,800,000
DevOps Consultant
DevOps Consultant

StarZen • Gurugram District

On-site
INR 1,800,000 - 3,000,000
Senior Devops And Cloud Infrastructure Engineer
Senior Devops And Cloud Infrastructure Engineer

Bigsun Technologies • Navi Mumbai

On-site
INR 3,000,000 - 6,000,000
Lead Cloud Engineer
Lead Cloud Engineer

Anblicks • Hyderabad

On-site
INR 7,462,000 - 9,329,000
Azure DevOps (22nd Aug Face-To-Face Interview at Bangalore/Chennai)
Azure DevOps (22nd Aug Face-To-Face Interview at Bangalore/Chennai)

EY • Chennai District, Bengaluru

Hybrid
INR 1,500,000 - 2,500,000
Senior CloudOps DevOps Consultant
Senior CloudOps DevOps Consultant

EY • Bengaluru

On-site
INR 1,800,000 - 3,000,000
DevOps Engineer
DevOps Engineer

Comviva • Maharashtra

On-site
INR 1,500,000 - 2,400,000
Senior Azure Cloud DevSecOps Engineer
Senior Azure Cloud DevSecOps Engineer

NewVision Software • Pune District

Hybrid
INR 2,600,000 - 5,200,000
Devops Engineer
Devops Engineer

Zybisys • Bengaluru

On-site
INR 1,500,000 - 2,300,000
DevOps with Multi cloud - AWS and Azure - Bangalore
DevOps with Multi cloud - AWS and Azure - Bangalore

Happiest Minds Technologies • Bengaluru

On-site
INR 1,800,000 - 2,800,000