Skip to main content
| HCL Global System logo

Azure Cloud Security Architect

| HCL Global System
2 days ago
Remote
Web Development
Azure Cloud Security Architect

Azure Cloud Security Architect
Infrastructure

Do you have the required skills?
have you preformed each description of services before?

Joint workshops with Cloud/Infra to define security guardrails feeding the landing zone design: identity model, network segmentation principles, logging/retention requirements, encryption standards, tagging and policy strategy.

Review Management Group hierarchy, subscription structure, custom RBAC role definitions, PIM eligible/active role design, and break-glass account setup proposed by Cloud/Infra for each tenant.
Validate hub-spoke topology, NSG/ASG rule sets, firewall placement, private endpoint usage, DDoS protection plan, and DNS architecture against security baseline.
Review and validate Azure Policy initiatives (deny public IP, enforce encryption at rest/in transit, allowed resource types/regions, mandatory tagging) assigned at each Management Group/subscription scope.
Validate the central Log Analytics workspace design, diagnostic settings scope (which resource types forward logs), retention periods, and confirm the workspace is correctly positioned for Sentinel onboarding.
Review Key Vault architecture (per-subscription vaults, RBAC vs. access policies, soft-delete/purge protection, private endpoint access) proposed for each landing zone.
Score each subscription tier (Prod/Non-Prod/Identity/Connectivity) against Azure Security Benchmark / CIS controls; issue formal security sign-off or a remediation list back to Cloud/Infra before tool deployment begins.