Microsoft Defender for Cloud Specialist CNAPP/CSPM
Pune, Maharashtra, India · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
We are seeking an experienced Microsoft Defender for Cloud Specialist with expertise in CNAPP and CSPM to design, implement, and manage Defender solutions at scale within Azure environments. The role involves leveraging deep knowledge of Azure security services, automating posture management, integrating with vulnerability and patch management, and coordinating multi-vendor environments to ensure robust cloud security posture.
Key Responsibilities
- Design and deploy Microsoft Defender for Cloud including CSPM and CWPP workloads at scale.
- Manage Azure security services such as Policy initiatives (Audit/Deny/DeployIfNotExists), Guest Configuration, Update Manager, Log Analytics, Key Vault, RBAC, and Privileged Identity Management (PIM) with Just-In-Time access controls.
- Implement CNAPP/CSPM automated posture management and remediation for storage, encryption, network controls, diagnostics, and resilience policies.
- Enable and administrate Defender plans covering multiple workloads (Servers, Storage, Key Vault, SQL, Resource Manager) alongside centralized coverage and cost reporting dashboards.
- Integrate vulnerability and patch management processes by prioritizing missing OS/package patches and exploitable CVEs, working with Azure Update Manager for critical patch scheduling.
- Integrate Microsoft Defender findings with ServiceNow SecOps to create feedback loops, KPI, and SLA reporting dashboards for infrastructure and application teams.
- Coordinate activities in a complex multi-vendor delivery environment involving various internal and external stakeholders.
Profile Requirements
- Strong familiarity with Cloud Infrastructure Entitlement Management (CIEM) on Azure, including privileged access governance, service principal monitoring, and role assignment alerting.
- Capability to detect and manage standing privileged RBAC roles and over-permissioned service principals; support transitions to Just-In-Time (JIT) and Privileged Identity Management (PIM) with scheduled access reviews.
- Knowledge of multi-cloud posture management solutions covering AWS and GCP to align strategies beyond Azure.
- Understanding of Continuous Threat and Exposure Management (CTEM) lifecycle phases to feed exposure management outputs.
- Experience in setting up diagnostic and logging configurations centralized in Log Analytics for Azure services such as Key Vault, Storage, App Service, Logic Apps, and Event Hub with drift alerting.
- Expertise with network security controls including public network restrictions, Azure Firewall setups, and VM backup policies within Defender for Cloud.
- Support automation goals by increasing scanning frequency toward continuous monitoring across the cloud estate.
Mandatory Skills
Proven experience with CNAPP services is required.