|
1. Microsoft Defender for Cloud Implementation — Proven, hands-on expertise with Microsoft Defender for Cloud, including CSPM and Defender workload plans (CWPP), with demonstrated ability to design and deploy Defender capabilities at scale. 2. Azure Security Services & Configuration — Deep knowledge of Azure Policy (Audit/Deny/DeployIfNotOnce initiatives), Guest Configuration, Update Manager, Log Analytics, Key Vault, RBAC, and PIM/JIT access controls. 3. Automated Posture Management & Remediation — Experience implementing CNAPP/CSPM posture management with auto-remediation capabilities covering storage configurations, encryption, network controls, diagnostics, and resilience policies. 4. Defender Plan Coverage & Reporting — Ability to enable and manage Defender plans across multiple workload types (Servers, Storage, Key Vault, SQL, Resource Manager) with central coverage and cost reporting dashboards. 5. Vulnerability & Patch Management Integration — Experience surfacing missing OS/package patches and exploitable CVEs, prioritising exploitable vulnerabilities, and integrating with Azure Update Manager for critical patch baselines and scheduled deployments. 6. ServiceNow SecOps Integration — Demonstrated experience integrating Defender for Cloud findings with the ServiceNow SecOps module for feedback loops to infrastructure and application teams, with KPI/SLA dashboards. 7. Multi-Vendor Environment Coordination — Comfortable operating in a multi-vendor delivery environment, coordinating across internal and external stakeholders. |
|
1. CIEM Concepts (Cloud Infrastructure Entitlement Management) — Familiarity with CIEM in Azure, including privileged access governance, service principal oversight, standing privilege detection, and role-assignment alerting. 2. Identity & Privileged Access Posture — Experience detecting standing privileged RBAC and over-permissioned service principals, supporting shifts to just-in-time (JIT) and privileged identity management (PIM) with periodic access reviews. 3. Multi-Cloud Posture Awareness — Understanding of AWS/GCP equivalent posture management solutions (given wider CSPM/CNAPP scope beyond Azure), enabling alignment with the broader multi-cloud security strategy. 4. CTEM Lifecycle Alignment — Familiarity with Continuous Threat and Exposure Management (CTEM) phases (Scope, Discover, Prioritize, Validate, Mobilize) to ensure posture outputs feed the exposure-management lifecycle. 5. Diagnostic & Logging Architecture — Experience configuring diagnostic settings to central Log Analytics for Key Vault, Storage, App Service, Logic Apps, and Event Hub with drift alerting capabilities. 6. Network & Resilience Controls — Knowledge of network security controls, public network access restrictions, Azure Firewall configurations, and VM backup policy implementations within Defender for Cloud. 7. Scanning Frequency Automation — Experience supporting increased scanning frequency toward continuous as part of the broader automation goal across the cloud estate. |
Mandatory Skills: CNAPP Services .
Experience: 5-8 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.