Point your AI agent at freehire and let it find you a job.

Get the CLI →

StarZen

NewBe an early applicant

DevOps & Cloud Security Engineer

Posted 1 view
Discussion

Summary

Owns StarZen's entire Azure/Microsoft stack end-to-end: cloud architecture, AKS containers, relational/NoSQL databases, Elasticsearch, the Microsoft Fabric data platform, Dynamics 365/ERP integrations, plus security (Key Vault, WAF, vulnerability management), 24x7 monitoring, backups and DR. Core tools: Azure, Terraform/Bicep, Docker/Kubernetes, SQL, Python.

DevOps & Cloud Security Engineer

Experience: 3–5 years | Location: Gurugram | Type: Full-time

Role

Own our entire Azure and Microsoft stack end-to-end — infrastructure, containers, data platform, security and monitoring. You will design the architecture, keep it documented and current, and make sure nothing breaks silently.

Responsibilities

  • Architecture & Design — Design the complete cloud architecture (network, compute, data, security layers), maintain up-to-date diagrams and documentation, and evolve the design as the stack grows.
  • Azure Infrastructure — Manage VMs, VNets, NSGs, App Gateway, Front Door, Entra ID/RBAC and cost optimisation. Infrastructure as Code via Terraform/Bicep.
  • Containers — Run and upgrade AKS / Container Apps and ACR; build hardened, minimal Docker images with CVE scanning in the pipeline.
  • Databases — Administer relational databases (Azure SQL / SQL Server, PostgreSQL / MySQL): schema and index management, query performance tuning, high availability, replication, automated backups and tested point-in-time restores. Also manage MongoDB (replica sets, sharding, backups, restore testing).
  • Search & Log Store — Manage Elasticsearch / OpenSearch clusters: index lifecycle and retention policies, shard and node sizing, snapshots, query performance, cluster health monitoring and secure access. Maintain the ELK/EFK stack used for centralised logging where applicable.
  • Data Platform — Own Microsoft Fabric and OneLake: workspace setup, capacity management, access control, pipelines and data governance.
  • Business Application Integrations — Manage Dynamics 365 and ERP environments and their APIs — authentication, integration pipelines, data sync, error handling, rate limits, monitoring and environment refreshes.
  • Secrets Management — Own Azure Key Vault. Enforce a scheduled secret, key and certificate rotation policy; zero hardcoded credentials anywhere.
  • 24×7 Monitoring & Alerting — Set up full-stack observability (Azure Monitor, Log Analytics, App Insights, Grafana). Define SLIs/SLOs and configure alerts so that any anomaly triggers a notification immediately, routed to the right on-call channel with minimal noise.
  • Log Retention & Governance — Define and maintain retention policies per log type (application, security, audit, infra) with correct archival tiers and compliance alignment.
  • Security & Vulnerability Management — Continuous scanning across servers, containers and dependencies; triage and remediate CVEs within SLA. Operate Defender for Cloud / Sentinel.
  • DDoS, WAF & Anti-Crawler — Configure Azure DDoS Protection and WAF; implement rate limiting, geo/IP filtering, bot management, robots.txt policy and anti-scraping controls.
  • Patch Management — Keep all servers and container images current — OS, kernel, runtimes and libraries — on a documented cadence, with emergency patching for critical CVEs.
  • Automation & Cron Inventory — Maintain CI/CD pipelines (Azure DevOps / GitHub Actions) and a documented register of every cron and scheduled job: what it does, why it exists, schedule, owner and failure alerting.
  • Backup & DR — Own backup strategy across all workloads with regular tested restores and a drilled DR plan (defined RTO/RPO).
  • Documentation — Keep runbooks, SOPs, change logs and asset inventory accurate and current. Undocumented infrastructure is treated as incomplete work.


Must-Have Skills

  • Azure (3+ yrs) · Microsoft Fabric & OneLake · Dynamics 365 APIs · ERP APIs and integrations · Relational databases (Azure SQL / SQL Server, PostgreSQL or MySQL) incl. query tuning and HA · Elasticsearch / OpenSearch cluster administration · MongoDB · Effective use of AI assistants (Claude / ChatGPT) for scripting, IaC generation, log analysis, debugging and documentation · Linux administration incl. kernel patching · Docker & Kubernetes/AKS · Terraform or Bicep · Networking, DNS, TLS, Nginx · WAF / DDoS / bot protection · Vulnerability management · Azure Key Vault · REST / OData API integration and troubleshooting · Bash / PowerShell / Python · CI/CD pipelines · Monitoring and alerting stacks


Note on AI tools: We expect you to actively use Claude/ChatGPT to work faster — but with judgement. You must be able to review, test and take full ownership of anything AI-generated before it touches our infrastructure.


Good to Have

Basic working knowledge of AWS (EC2, S3, IAM) and GCP · Microsoft Sentinel / SIEM · Cloudflare · Power Platform / Dataverse · Azure Data Factory or Synapse · ISO 27001 / SOC 2 exposure

Certifications (Preferred)

AZ-104, AZ-400, AZ-500, CKA/CKS


What We Look For

Ownership mindset, disciplined documentation habits, security-first thinking, and calm handling of production incidents. Willingness to be on-call.

Skills

See also

DevOps jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available