
Principal Cybersecurity Engineer
Providence1 month ago
Hyderābād, IndiaStaff+
Responsibilities
- Design, implement, and own Azure Landing Zone security architecture, including Azure Policies, RBAC, management groups, subscription architecture, and security guardrails.
- Lead day-to-day management of CrowdStrike, Proofpoint, Rapid7, Checkmarx, Wiz, Microsoft Defender for Cloud, Defender for Identity, and Microsoft Sentinel.
- Implement Azure Policy, policy-as-code, security baselines-as-code, GitOps practices, and compliance automation.
- Design and govern Azure network security architectures involving hub-spoke and vWAN networking, private endpoints, Azure Firewall, WAF, and DDoS protection.
- Stand up and evolve Sentinel SIEM/SOAR capabilities, including data connectors, analytics rules, UEBA, threat enrichment, and automated response playbooks.
- Maintain the enterprise risk register, report security KPIs, and partner with risk, compliance, audit, vendors, and engineering teams.
- Run purple-team control validation, lead incident response runbooks, monitor threats and alerts, and drive post-incident improvements.
- Analyze and audit platform and application codebases for vulnerabilities and compliance gaps using Checkmarx and related tools.
- Serve as a security authority on the Architecture Review Board and shape approved application and cloud design patterns.
- Define standard operating procedures, train L1/L2 teams, and drive timely delivery of security initiatives.
Requirements
- 10+ years of cybersecurity experience, including 5+ years focused on Azure cloud security architecture.
- Expertise in Azure RBAC, Microsoft Entra ID, Conditional Access, PIM, PIM for Groups, and identity governance.
- Hands-on experience with CrowdStrike, Proofpoint, Rapid7, Checkmarx, Wiz, Defender for Cloud, Microsoft Sentinel, Azure Firewall, and WAF.
- Experience delivering Azure Landing Zones aligned with the Microsoft Cloud Adoption Framework and Well-Architected principles.
- Strong knowledge of SAML, OAuth2/OIDC, SCIM provisioning, identity federation, and B2B integrations.
- Automation experience with PowerShell, Python, Terraform, Bicep, Git, YAML, and CI/CD workflows.
- Experience implementing CNAPP, EDR, email security, vulnerability management, code security, SAST/DAST, IaC scanning, and API security.
- Experience designing enterprise-scale Azure network security and private connectivity, including VNets, private endpoints, DDoS, WAF, and Azure Firewall.
- Hands-on experience with Defender for Cloud, Sentinel SIEM/SOAR, cloud threat-detection pipelines, observability, logging, alert tuning, and incident response automation.
- Experience designing Azure Policy, policy-as-code, and compliance automation for SOC2, ISO, and HIPAA.
- Deep understanding of Key Vault, CMK encryption, data protection, secure data pipelines, and DevSecOps.
- Familiarity with AI/LLM security patterns, Azure OpenAI, and RAG architectures.
- Experience building secure Azure Landing Zones and enterprise cloud architecture.
About Providence
Providence is a nonprofit Catholic health system that operates hospitals, clinics, and related care services for patients and communities across the western U.S. It runs 51 hospitals and 829 clinics and also offers a health plan in select markets. Headquartered in Renton, Washington, Providence provides acute, ambulatory, virtual, and home-based care along with pharmacy and behavioral health services, supported by centralized technology, cybersecurity, and shared services teams.