Cloud Strategy & Operations Head
Location: Bangalore
Experience
Required: 12 –
16 Years
Employment
Type: Full-Time
____
About Zybisys
Zybisys is a technology company that helps banks, financial
institutions, and FinTech businesses build and run secure, reliable, and
high-performance technology platforms. We work closely with some of India's
leading stock brokers to manage their cloud infrastructure, cybersecurity,
platform operations, and observability. With deep expertise in the Capital
Markets domain, we focus on simplifying complex technology, improving
operational resilience, and helping our customers innovate with confidence.
Job Description
The Cloud Strategy & Operations Head is a senior hands-on
technical leadership role within the Zybisys Managed Cloud Services practice.
The role owns the architecture, build, automation, and ongoing operations of a
complex multi-region Azure cloud environment integrated with an on-premises
datacenter in a hybrid model — serving both business-critical application
workloads and enterprise employee services.
This is not a purely governance or managerial position. The
ideal candidate is an experienced cloud architect and MSSP practitioner who
leads from the front — capable of designing infrastructure, building automation
pipelines, deploying and managing enterprise platforms, defining observability
strategy, and governing managed services delivery — while engaging directly
with the client as Zybisys's primary technical owner.
Key Responsibilities
Platform Architecture
& Build
· Architect and lead the build of
multi-region Azure cloud infrastructure integrated with on-premises datacenter
environments in a hybrid topology.
· Design end-to-end
infrastructure: compute, storage, networking, identity (Azure AD, ADFS, hybrid
directory), and connectivity layers for both business and employee workloads.
· Define platform standards,
configuration baselines, and architecture blueprints; own Azure build planning
and environment design from inception through steady-state operations.
· Plan and oversee Azure landing
zone design, subscription governance, management groups, and policy frameworks
aligned with enterprise requirements.
· Lead capacity planning,
infrastructure right-sizing, and ongoing resource optimisation across cloud and
on-premises layers.
Networking, Security
& Traffic Management
· Design and manage hub-and-spoke
or Virtual WAN network topologies spanning multi-region Azure and hybrid
datacenter connectivity (ExpressRoute, Site-to-Site VPN).
· Deploy and manage Azure-native
and marketplace-based firewall solutions, Web Application Firewalls (WAF),
Application Gateways, Azure Load Balancers, and Azure Front Door for traffic
management and application delivery.
· Implement and govern Azure API
Gateway and API Management for application exposure and traffic control.
· Deploy and manage Zscaler
Internet Access (ZIA) for clean, filtered internet egress and Zscaler Private
Access (ZPA) for secure internal application connectivity.
· Configure and manage Palo Alto
NGFW, Trend Micro EDR, and CyberArk PAM — implementing security baselines and
change configurations per client infosec policy directives.
Observability, Monitoring
& APM
· Design and implement a
comprehensive observability strategy covering infrastructure, application,
network, and security telemetry layers across all managed environments.
· Deploy and manage Prometheus and
Grafana stacks for real-time metrics collection, dashboard visualization, and
alerting across cloud and hybrid environments.
· Implement sFlow and NetFlow
monitoring for network traffic analysis, bandwidth utilization, and anomaly
detection across datacenter and Azure network paths.
· Evaluate, recommend, and deploy
Application Performance Monitoring (APM) solutions; integrate APM data into the
unified observability framework for application-layer visibility.
· Configure Azure Monitor, Log
Analytics, and custom KQL alert rules; establish noise-reduced alerting,
correlation rules, and escalation matrices.
· Define and maintain runbooks,
SOPs, and incident playbooks for all priority categories; own SLA adherence and
drive RCA discipline for major incidents.
Automation, DevOps &
CI/CD Readiness
· Champion an automation-first
operations culture — auto-remediation workflows, self-healing runbooks,
scheduled maintenance automation, and event-driven provisioning.
· Implement IaC practices using
Terraform, Ansible, ARM templates, or Bicep for all infrastructure provisioning
and configuration management workflows.
· Lead CI/CD readiness assessments
and pipeline design for managed cloud environments; collaborate with DevOps
teams on deployment automation, release governance, and environment promotion.
· Build and maintain operational
automation scripts (PowerShell, Python, Bash) that reduce manual toil, improve
MTTR, and increase consistency across operations.
Cloud Cost Optimisation
· Own cloud cost governance across
all managed Azure subscriptions — define tagging policies, cost allocation
frameworks, and budget alert structures.
· Continuously analyse Azure spend
using Cost Management + Billing; identify rightsizing opportunities, reserved
instance recommendations, and idle resource elimination.
· Produce regular cost
optimisation reports and present savings roadmaps to stakeholders; track and
report realized savings against targets.
· Implement FinOps practices
aligned with team maturity — chargeback models, showback dashboards, and
workload-level cost accountability.
MSSP Service Delivery
& Governance
· Own end-to-end managed services
delivery including incident, change, problem, and service request management
via ITSM platforms.
· Govern SLA adherence across all
priority tiers; lead post-incident reviews, chronic issue elimination, and
continuous improvement programs.
· Serve as Zybisys's primary
technical owner and escalation authority in the client relationship — covering
both technical and executive-level stakeholder engagement.
· Publish monthly service review
reports, SLA dashboards, capacity reports, and quarterly business reviews;
drive CAB participation and change governance.
Team Leadership &
Development
· Lead, mentor, and
performance-manage the managed cloud operations team across L1, L2, specialist,
and DevOps engineering functions.
· Design 24x7 shift structures,
escalation paths, and on-call frameworks ensuring operational coverage and
resilience.
· Conduct skills gap assessments,
define technical training roadmaps, and build team capability aligned to
platform evolution.
· Foster a team culture of
ownership, documentation discipline, and continuous improvement.
Required Skills & Experience
Cloud Architecture &
Hybrid Infrastructure
· 12 – 16 years of overall
IT/infrastructure experience; minimum 6 years in cloud infrastructure or
managed cloud roles.
· Proven experience architecting
and operating multi-region Microsoft Azure environments including landing zone
design, subscription governance, and hybrid connectivity (ExpressRoute,
Site-to-Site VPN, Azure Arc).
· Strong hybrid infrastructure
experience — integrating on-premises datacenter environments with Azure through
consistent networking, identity, and management planes.
· Deep expertise in Windows Server
and Linux (RHEL/Ubuntu) administration, VM lifecycle management, storage
(SAN/NAS/Azure-native), and OS-level troubleshooting.
· Enterprise identity and
directory services: Azure AD, ADFS, hybrid identity, Conditional Access,
Privileged Identity Management, and M365 platform administration.
· Strong networking fundamentals:
BGP, OSPF, VLANs, VXLAN, DNS, DHCP, NTP, IPSec VPN, SD-WAN, and network
segmentation design.
Networking, Security
Platforms & Traffic Management
· Hands-on experience deploying
and managing Azure-native and marketplace-based firewalls, Azure WAF,
Application Gateway, Azure Load Balancer, Azure Front Door, and Traffic
Manager.
· Azure API Management and API
Gateway configuration — API policies, routing, throttling, security, and
developer portal management.
· Zscaler ZIA and ZPA deployment,
policy configuration, and operational management for secure internet access and
private application connectivity.
· Palo Alto NGFW (Panorama
preferred), Trend Micro Apex One / XDR, and CyberArk PAM administration —
policy implementation, change management, and compliance tracking under client
security directives.
Observability &
Monitoring
· Prometheus and Grafana
deployment and operations — metric scraping, custom dashboards, alerting rules,
and integration with cloud and on-premises targets.
· sFlow and NetFlow collection,
analysis, and visualization for network traffic monitoring and anomaly
detection.
· APM platform experience
(Dynatrace, AppDynamics, New Relic, Azure Application Insights, or equivalent)
— deployment, agent rollout, baseline tuning, and dashboard design.
· Azure Monitor, Log Analytics,
KQL query development, and unified alerting for hybrid environments.
· Experience designing
observability strategies from scratch — defining what to monitor, how to alert,
and how to present operational health to stakeholders.
Automation, DevOps &
IaC
· Strong scripting and automation
skills: PowerShell, Python, Bash; IaC with Terraform and / or Ansible across
cloud and hybrid environments.
· CI/CD pipeline design and
readiness assessment: Azure DevOps, Git-based workflows, deployment automation,
environment promotion strategies.
· Demonstrated track record of
building auto-remediation workflows and runbook automation that measurably
reduced MTTR or eliminated manual toil.
Cloud Cost Optimisation
· Azure Cost Management + Billing,
reserved instance analysis, rightsizing recommendations, and cost allocation
tagging.
· FinOps practices: chargeback /
showback models, budget governance, anomaly alerting, and savings tracking.
· Experience delivering cost
reduction programs with measurable outcomes in managed cloud or MSSP
environments.
MSSP & Service
Delivery
· Minimum 4 years in an MSSP or
multi-client managed services environment with full operational ownership (not
just support coordination).
· Proven SLA governance in 24x7
operations — escalation management, war-room coordination, and executive
communication during major incidents.
· ITSM platform experience: Zoho
Desk, ServiceNow, Freshservice, or equivalent — process ownership, not just
usage.
Certification (Preferred)
Domain
| Certification
|
Microsoft
Azure
| AZ-104 (Administrator) | AZ-305 (Solution Architect) | AZ-500 (Security)
|
Networking
/ Security
| Palo Alto PCNSE | Zscaler ZCCA / ZCCP | CyberArk Defender
|
Automation
/ DevOps
| HashiCorp Terraform
Associate | AZ-400 (Azure DevOps Engineer)
|
Observability
| Grafana Certified
Associate | Dynatrace or AppDynamics certification
|
Service
Management
| ITIL v4 Foundation or above
|
This document is confidential and prepared for internal
recruitment purposes only. | Zybisys Consulting Services LLP | www.zybisys.com