Principal Cybersecurity Engineer

Location
Hyderabad
Workplace
On-site

About this role

As a Cybersecurity Principal Engineer, you will

  • Design, implement, and own the Azure Landing Zone security architecture, including:
  • Azure Policies and Policy Initiatives
  • Guardrails, RBAC models, management groups, and subscription architecture
  • Lead implementation and day‑to‑day management of enterprise security platforms, including:
  • CrowdStrike (endpoint protection, detection, and response)
  • Proofpoint (email security, phishing protection, and threat intelligence)
  • Rapid7 (vulnerability management, exposure analytics, and threat detection)
  • Checkmarx (SAST, DAST, SCA, code security governance)
  • Wiz (CNAPP / CSPM / workload and cloud risk visibility)
  • Implement and operationalize Azure Policy for:
  • Resource tagging, region restrictions, SKU allowlists
  • Encryption, data residency, and compliance guardrails
  • Deploy, tune, and manage:
  • Microsoft Defender for Cloud (CSPM/CWPP)
  • Defender for Identity
  • Container and AKS security controls
  • Stand up and evolve Microsoft Sentinel (SIEM/SOAR):
  • Data connectors, analytics rules, UEBA
  • Threat enrichment and automated response playbooks
  • Implement Policy‑as‑Code and Security Baselines‑as‑Code using GitOps practices.
  • Maintain enterprise risk register, report security KPIs to leadership, and partner with risk, compliance, and audit teams.
  • Run purple‑team style control validation, lead incident response runbooks, and drive post‑incident improvements.
  • Establish and govern network security architectures:
  • Hub‑spoke / vWAN
  • Private Endpoints, Azure Firewall, WAF, DDoS

 

What would your day look like?

  • Partner with Engineering, Network, and Platform teams to design and operate a secure, compliant Azure platform and Snowflake tenant.
  • Analyze and audit platform and application codebases using Checkmarx and related tooling to identify vulnerabilities and compliance gaps.
  • Act as a security authority on the Architecture Review Board, shaping approved application and cloud design patterns.
  • Collaborate with vendors and partners on security assessments and remediation strategies (CrowdStrike, Proofpoint, Rapid7, Wiz).
  • Continuously monitor threats and alerts; define SOPs and train L1/L2 teams for effective triage and escalation.
  • Drive sprint delivery for security initiatives with high quality and on‑time execution.

Who are we looking for?

  • 10+ years of cybersecurity experience with 5+ years focused on Azure cloud security architecture.
  • Deep expertise in:

Azure RBAC, Microsoft Entra ID, Conditional Access

PIM / PIM for Groups, Identity Governance

Strong hands‑on experience with:

CrowdStrike, Proofpoint, Rapid7, Checkmarx, Wiz

Defender for Cloud, Microsoft Sentinel, Azure Firewall, WAF

  • Proven experience delivering Azure Landing Zones aligned to Microsoft Cloud Adoption Framework and Well‑Architected principles.
  • Strong identity federation knowledge (SAML, OAuth2/OIDC), SCIM provisioning, and B2B integrations.
  • Automation‑first mindset with PowerShell, Python, Terraform, Bicep, Git, YAML, and CI/CD workflows.

Required Skills:

  • Expert‑level Microsoft Entra ID, Conditional Access, PIM, RBAC, and identity governance
  • Enterprise‑scale Azure network security and private connectivity design
  • Deep experience implementing CNAPP, EDR, email security, vuln management, and code security platforms
  • Strong DevSecOps background including SAST/DAST, IaC scanning, and API security
  • Mature incident response, observability, and alert tuning experience
  • Familiarity with AI/LLM security patterns (Azure OpenAI, RAG architectures)
  • Strong experience with Azure network security, including VNet architecture, private endpoints, DDoS, WAF, and Azure Firewall
  • Hands-on experience implementing Defender for Cloud, Sentinel SIEM/SOAR, and cloud threat-detection pipelines
  • Demonstrated ability to design Azure Policy, policy-as-code, and compliance automation for SOC2/ISO/HIPAA
  • Deep understanding of Key Vault, CMK encryption, data protection, and secure data pipelines
  • Proven background in DevSecOps, secure CI/CD, IaC (Terraform/Bicep), SAST/DAST, and API security
  • Strong capability in observability, logging, alert tuning, and incident response automation
  • Experience building secure Azure Landing Zones and enterprise cloud architecture.

 

 

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?