Developing, implementing, and managing Azure Policies to enforce governance and compliance standards across the organization's Azure environments
Providing technical guidance and support to IOT team to ensure industrial regulation compliance during product development & maintenance.
Gathering user requirements and understanding use cases, design documents, and driving implementation in accordance with project and platform goals.
Monitoring and auditing Azure Policy compliance, investigating policy violations, and providing remediation guidance to ensure continuous adherence to security standards.
Supporting development teams and managing end-to-end execution of software development in the Azure DevSecOps.
Coordinating security tests of IOT products and identifying emerging threats and scanning the attack surface to ensure the secure implementation of the IOT products.
Vulnerability screening, assessment, classifying, prioritizing, and fixing the issues.
Troubleshooting and responding to security breaches.
Support of process improvements, standards, and guidelines through the creation of security documentation.
Requirements :
Have 4 years of experience in Cyber Security Engineering.
Be an expert with Microsoft Azure, including proficiency in Azure Policy, Azure Resource Manager, and Azure Governance.
Be very proficient with software Be able to design, test, and implement solutions through code and programming like Python or Java.
Be an expert with scripting and automation languages (e.g., Python, PowerShell, Azure CLI, JSON) to author and manage Azure Policies.
Have strong skills in identifying the pain areas of cloud security and automating cloud security workloads to improve Azure Governance.
Have a thorough understanding of CI / CD and DevSecOps to implement and manage Azure Policies and automations.
Creative, analytical, structured, and proactive approach.
Good understanding of Regulations ISO27001 NIST, RED, NIS2 IEC / ISA 62443
Helpful if the candidate has knowledge about CMMi or ASPICE for a good connection with the entire embedded development language.
Certified Cloud Security Professional (CCSP / CCSK), Or GIAC Cloud Security Essentials (GCLD), or CISSP - Certified Information Systems Security Professional.
Bachelor's degree from an accredited university or college with overall 7 years of experience.