Back to search
Providence India Linkedin · Posted yesterday

Principal Cybersecurity Engineer

India

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

As a Cybersecurity Principal Engineer, you will

  • Design, implement, and own the Azure Landing Zone security architecture, including:
  • Azure Policies and Policy Initiatives
  • Guardrails, RBAC models, management groups, and subscription architecture
  • Lead implementation and day‑to‑day management of enterprise security platforms, including:
  • CrowdStrike (endpoint protection, detection, and response)
  • Proofpoint (email security, phishing protection, and threat intelligence)
  • Rapid7 (vulnerability management, exposure analytics, and threat detection)
  • Checkmarx (SAST, DAST, SCA, code security governance)
  • Wiz (CNAPP / CSPM / workload and cloud risk visibility)
  • Implement and operationalize Azure Policy for:
  • Resource tagging, region restrictions, SKU allowlists
  • Encryption, data residency, and compliance guardrails
  • Deploy, tune, and manage:
  • Microsoft Defender for Cloud (CSPM/CWPP)
  • Defender for Identity
  • Container and AKS security controls
  • Stand up and evolve Microsoft Sentinel (SIEM/SOAR):
  • Data connectors, analytics rules, UEBA
  • Threat enrichment and automated response playbooks
  • Implement Policy‑as‑Code and Security Baselines‑as‑Code using GitOps practices.
  • Maintain enterprise risk register, report security KPIs to leadership, and partner with risk, compliance, and audit teams.
  • Run purple‑team style control validation, lead incident response runbooks, and drive post‑incident improvements.
  • Establish and govern network security architectures:
  • Hub‑spoke / vWAN
  • Private Endpoints, Azure Firewall, WAF, DDoS

What would your day look like?

  • Partner with Engineering, Network, and Platform teams to design and operate a secure, compliant Azure platform and Snowflake tenant.
  • Analyze and audit platform and application codebases using Checkmarx and related tooling to identify vulnerabilities and compliance gaps.
  • Act as a security authority on the Architecture Review Board, shaping approved application and cloud design patterns.
  • Collaborate with vendors and partners on security assessments and remediation strategies (CrowdStrike, Proofpoint, Rapid7, Wiz).
  • Continuously monitor threats and alerts; define SOPs and train L1/L2 teams for effective triage and escalation.
  • Drive sprint delivery for security initiatives with high quality and on‑time execution.

Who are we looking for?

  • 10+ years of cybersecurity experience with 5+ years focused on Azure cloud security architecture.
  • Deep expertise in:

Azure RBAC, Microsoft Entra ID, Conditional Access

PIM / PIM for Groups, Identity Governance

Strong Hands‑on Experience With

CrowdStrike, Proofpoint, Rapid7, Checkmarx, Wiz

Defender for Cloud, Microsoft Sentinel, Azure Firewall, WAF

  • Proven experience delivering Azure Landing Zones aligned to Microsoft Cloud Adoption Framework and Well‑Architected principles.
  • Strong identity federation knowledge (SAML, OAuth2/OIDC), SCIM provisioning, and B2B integrations.
  • Automation‑first mindset with PowerShell, Python, Terraform, Bicep, Git, YAML, and CI/CD workflows.

Required Skills

  • Expert‑level Microsoft Entra ID, Conditional Access, PIM, RBAC, and identity governance
  • Enterprise‑scale Azure network security and private connectivity design
  • Deep experience implementing CNAPP, EDR, email security, vuln management, and code security platforms
  • Strong DevSecOps background including SAST/DAST, IaC scanning, and API security
  • Mature incident response, observability, and alert tuning experience
  • Familiarity with AI/LLM security patterns (Azure OpenAI, RAG architectures)
  • Strong experience with Azure network security, including VNet architecture, private endpoints, DDoS, WAF, and Azure Firewall
  • Hands-on experience implementing Defender for Cloud, Sentinel SIEM/SOAR, and cloud threat-detection pipelines
  • Demonstrated ability to design Azure Policy, policy-as-code, and compliance automation for SOC2/ISO/HIPAA
  • Deep understanding of Key Vault, CMK encryption, data protection, and secure data pipelines
  • Proven background in DevSecOps, secure CI/CD, IaC (Terraform/Bicep), SAST/DAST, and API security
  • Strong capability in observability, logging, alert tuning, and incident response automation
  • Experience building secure Azure Landing Zones and enterprise cloud architecture.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search