Job Description

 Roles & responsibilities
Role Purpose
Design, build, and govern secure, resilient, and scalable cloud/hybrid infrastructure on Microsoft Azure, integrating on‑prem and platform services. The role blends Infrastructure Architecture & Operations with Infrastructure Security & Compliance, ensuring Zero Trust, policy‑as‑code, and operational excellence across identity, network, compute, containers (AKS), storage, backup, observability, and disaster recovery
Key Responsibilities
A. Infrastructure Architecture & Operations 
Own the Azure landing zone (CAF‑aligned) and hub‑spoke network design (ExpressRoute/VPN, Private DNS, Private Endpoints).
Define standards for compute, storage, databases, and platform services (VM/VMSS, images, disks, files, backups, SQL/MI).
AKS Platform Ownership (Mandatory): 
Design AKS clusters (node pools, taints/tolerations, zoning, multi‑region DR), Azure CNI/Overlay networking, and ingress (NGINX/App Gateway).
Establish lifecycle practices for upgrades, autoscaling (HPA/VPA, Cluster Autoscaler), image management (ACR), and workload placement.
Integrate platform services (Key Vault, Managed Identities, Private Link) and ensure operational SLOs.
Lead modernization/migration for Windows/Linux workloads and data platforms; ensure resilience, cost efficiency, and operational readiness.
Establish BCDR strategy—RTO/RPO targets, automated recovery runbooks, DR rehearsals, and evidence packs.
Build observability: Azure Monitor, Log Analytics, Application Insights, synthetic checks, and incident runbooks.
Drive FinOps: tagging, showback/chargeback, rightsizing, reservations/savings plans, and lifecycle policies.
B. Infrastructure Security & Compliance 
Implement Zero Trust across identity, device, network, and data: RBAC, PIM, Conditional Access/MFA, workload identities.
Design network security: NSG/ASG, Azure Firewall/WAF, micro‑segmentation, DDoS Protection, egress control, DNS security.
AKS Security (Mandatory): 
Entra ID/RBAC integration, Pod Security Admission (PSA) baselines, Network Policies, secrets management and workload identity.
Container image scanning, supply‑chain security (Helm/OCI), baseline hardening, and Defender for Containers posture/threat protection.
Embed policy‑as‑code (Azure Policy/Blueprints) for guardrails, CIS/benchmarks, drift detection, and automated remediation.
Integrate Defender for Cloud and Microsoft Sentinel with tuned alerts, SOAR playbooks, and incident coordination.
Ensure compliance with enterprise policies and applicable standards (ISO 27001, SOC 2, GDPR/HIPAA where relevant).
C. Automation & DevOps (Shared)
Champion IaC using Terraform/Bicep—reusable modules, environment promotion, approvals in Azure DevOps/GitHub CI/CD.
Build image pipelines (Packer/Golden Images) and configuration baselines (DSC/Automanage).
Implement GitOps for AKS (Flux/Argo), pre‑deployment policy validation, and security scans.
D. Governance, Documentation & Stakeholder Management
Author reference architectures, standards, roadmaps, HLD/LLD/Technical Architecture Proposal, RACI, risk registers, and decision logs; enforce via design reviews.
Partner with platform engineering, security, app/dev, and risk/compliance to deliver secure‑by‑design outcomes and smooth operational handovers.
Mentor engineers/architects; lead threat modeling, resiliency reviews, incidents & escalations.
 


Job Details

Role Level: Executive-Level Work Type: Full-Time
Country: India City: Hyderabad ,Telangana
Company Website: https://social.kpmg/contactus Job Function: General Management
Company Industry/
Sector:
Business Consulting and Services

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


ad 1
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn