DevOps Engineer
- 🇮🇳 India
- On-site
- 23 hours ago
- Azure Cloud
- CI/CD
- Azure
- Azure DevOps
- GitHub Actions
- IaC
- Terraform
- Bicep
- Secrets Management
- SAST
- DNS
- WAF
- RBAC
- Conditional Access
- Azure Monitor
- FinOps
- Change Management
- YAML
- Devops
- Key Vault
- Defender
- AKS
- SQL
- PowerShell
- Bash
- JSON
- REST API
- Git
- Disaster Recovery
- HIPAA
- SOC2
- ISO 27001
- NIST
- CIS Controls
- Kubernetes
- Docker
- Helm
- GitOps
Position Summary:
Â
The Azure Cloud and CI/CD Subject Matter Expert owns the architecture, engineering, automation, security, governance, cost optimization, and operational maturity of Microsoft Azure environments and software delivery platforms. This hands-on role establishes cloud and Dev SecOps standards, builds reusable infrastructure and deployment patterns, and partners with application, security, finance, product, and operations teams to deliver secure, resilient, observable, and cost-effective services.
Â
CRITICAL PRIORITY - AZURE COST SAVINGS: Continuously identify, quantify, prioritize, and deliver measurable Azure savings while protecting availability, security, performance, and business requirements.
Â
Key Responsibilities
• Serve as the technical authority for Azure architecture, platform engineering, networking, identity, security, governance, resiliency, and operations.
• Design and implement landing zones, management-group and subscription structures, resource organization, naming, tagging, policy, and role-based access-control standards.
• Build and maintain CI/CD pipelines using Azure DevOps and/or GitHub Actions for application, database, container, and infrastructure deployments.
• Develop reusable Infrastructure as Code using Terraform and/or Bicep/ARM, with version control, peer review, automated validation, testing, and controlled promotion between environments.
• Implement secure pipeline practices including workload identity or service connections, secrets management, artifact integrity, dependency scanning, SAST, container scanning, approvals, and separation of duties.
• Architect Azure networking, including VNets, subnets, NSGs, routing, private endpoints, Private DNS, VPN/ExpressRoute, Application Gateway, WAF, Load Balancer, and Azure Firewall patterns.
• Design identity and privileged-access solutions using Microsoft Entra ID, managed identities, RBAC, Conditional Access, MFA, PIM, and least-privilege principles.
• Establish monitoring and observability through Azure Monitor, Log Analytics, Application Insights, alerts, dashboards, diagnostic settings, and actionable operational runbooks.
• Own Azure cost optimization and FinOps execution: establish budgets and alerts; analyze Cost Management, Advisor, utilization, and billing data; eliminate waste; right-size resources; schedule non-production workloads; optimize storage; and evaluate Reservations, Savings Plans, licensing, and architectural alternatives.
• Create a prioritized savings backlog with documented baselines, forecasts, owners, target dates, realized savings, avoided costs, and validation that changes do not introduce unacceptable operational or security risk.
• Lead technical reviews, troubleshoot complex deployment and cloud-platform issues, perform root-cause analysis, and drive durable corrective actions.
• Create architecture diagrams, pipeline standards, implementation guides, operational procedures, and evidence supporting security, compliance, and change management.
• Mentor engineers and collaborate with development, database, networking, security, quality, product, and vendor teams.
Â
Required Qualifications
• Extensive hands-on experience architecting, implementing, securing, and operating enterprise Microsoft Azure environments.
• Expertise with Azure DevOps Pipelines and/or GitHub Actions, including YAML pipelines, templates, reusable workflows, environments, approvals, artifacts, variables, and release controls. Azure Cloud & CI/CD SME
• Confidential recruiting document JOB REQUISITION | CLOUD ENGINEERING & DEVOPS
• Strong Infrastructure as Code experience with Terraform and/or Bicep/ARM, including modules, remote state, dependency management, validation, and environment promotion.
• Deep knowledge of Azure networking, Microsoft Entra ID, RBAC, managed identities, Key Vault, Azure Policy, Defender for Cloud, and Azure Monitor.
• Experience with Azure compute and platform services such as Virtual Machines, App Service, Functions, AKS, Container Registry, Storage, SQL, and managed databases.
• Strong scripting and automation skills using PowerShell and Azure CLI; working knowledge of Bash, JSON, YAML, and REST APIs.
• Experience integrating security and quality controls into Git-based pipelines, including pull requests, code review, secret scanning, SAST, dependency/container scanning, policy gates, approvals, artifact versioning, rollback, and auditable deployment records.
• Ability to diagnose cross-platform problems and design for high availability, backup, disaster recovery, business continuity, scalability, performance, and cost optimization. • Demonstrated experience delivering measurable Azure savings using Cost Management, Azure Advisor, budgets, tagging, right-sizing, Reservations, Savings Plans, Hybrid Benefit, storage lifecycle controls, and workload scheduling.
• Excellent documentation, stakeholder communication, technical leadership, and mentoring skills.
Â
Preferred Qualifications
• Seven or more years in infrastructure, cloud, platform engineering, or DevOps, including at least four years of substantial Azure experience.
• Microsoft Azure and/or HashiCorp Terraform certification, supported by advanced production experience.
• Experience in regulated healthcare or another environment handling PHI, PII, or sensitive data, with knowledge of HIPAA, SOC 2, ISO 27001, NIST, or CIS controls.
• Experience with Kubernetes/AKS, Docker, Helm, GitOps, service mesh, or container-platform security.
• Experience creating cloud-cost dashboards, forecasts, showback/chargeback reporting, unit-cost metrics, and executive savings reports.
• Experience supporting tenant or subscription migrations, Azure Enterprise Agreement/billing structures, and multi-subscription governance.
Â
Â
DevOps Engineer · Natus Sensory