Azure Cloud Security
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, Azure
What you will do,
?????? Remediation & recurrence prevention (the core of this role)
Own the full lifecycle of security findings and recommendations whether they come from the security team, Microsoft Defender for Cloud, or other tooling through triage, remediation, verification, and closure.
Root cause recurring issues and implement systemic fixes (policy as code, automated guardrails, secure baselines) so the same findings donâ reappear quarter after quarter.
Track remediation SLAs and report on risk reduction and posture trends over time.
Identity & authenticationSecure and govern modern authentication flows across the estate: OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS.
Administer and harden Microsoft Entra (Azure Entra): app registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least privilege scoping.
Design, implement, and continuously tune Conditional Access policies.
Cloud security engineering & governanceBuild and enforce guardrails using Azure Policy and Terraform; maintain secure by default infrastructure as code baselines and detect/remediate configuration drift.
Operate Microsoft Defender for Cloud–drive secure score improvement, remediate recommendations, and manage cloud security posture (CSPM).
Contribute to security governance: standards, control definitions, exception handling, and audit evidence.
Admin portal & privileged access securitySecure all cloud and SaaS administrative portals–Azure and other admin consoles (e.g., Microsoft 365 admin, identity providers, and any additional cloud platforms in use).
Strengthen privileged access: MFA enforcement, Privileged Identity Management (PIM) / just in time elevation, role minimization, and break glass procedures.
AI securityApply security controls to AI workloads, services, and AI agents: agent and workload identities, tool and permission scoping, data exposure and prompt injection risk, and emerging AI security best practices.
What You Bring (Required)5+ years in cloud security or security engineering, with deep, hands on Azure experience.
Strong, hands on Microsoft Entra : app registrations, Enterprise Apps, permissions and consent, and Conditional Access.
Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS.
Proficiency with Terraform and Azure Policy for policy as code and automated guardrails.
Experience with Microsoft Defender for Cloud and cloud security posture management.
A demonstrable track record of root causing and permanently closing security findings–not just patching them.
Working understanding of AI, AI agents, and AI security considerations.
Nice to HaveExperience with CI/CD pipeline security, secrets management, and SIEM/SOAR.
Scripting/automation (Power Shell, Python).
Hands on experience securing LLM based or agentic systems in production.
Fulltime:
The pay range for this role is CAD $100,000 - CA $120,000 per annum including any bonuses or variable pay. Tech Mahindra also offers benefits like medical, vision, dental, life, disability insurance and paid time off (including holidays, parental leave, and sick leave, as required by law). The exact offer terms will depend on the skill level, educational qualifications, experience and location of the candidate.
“AI tools may assist in the recruitment process; however, all hiring decisions are made by the recruitment team based on a comprehensive evaluation of candidates.
#J-18808-LjbffrTo Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: