Azure Security Architect
Mumbai, IN
Atos is the Atos Group brand dedicated to AI-powered, secure, end-to-end digital services. Atos designs, develops, and operates critical digital environments that drive performance, resilience and sovereignty, helping public and private organizations worldwide retain control over their data and infrastructures, while meeting regulatory requirements.
With more than 54,000 employees serving over 4,500 clients across 54 countries, Atos helps modernize core IT systems, accelerate cloud and data transformation, strengthen cybersecurity, and deliver secure digital workplace environments to support its clients, its employees and society. Atos also provides consulting and advisory services through its Atos Amplify brand.
A trusted partner in operating complex and mission-critical environments, Atos supports organizations across highly regulated and sovereign contexts.
About Atos Group
Atos Group is a global leader in digital transformation with c. 56,000 employees and annual revenue of c. €7.2 billion (at the go-forward perimeter), operating in 54 countries under two brands - Atos for services and Eviden for products and systems. European number one in cybersecurity and a leader in cloud, Atos Group is committed to a secure and decarbonized future and provides tailored AI-powered, end-to-end solutions for all industries. Atos Group is listed on Euronext Paris.
Work Location- Mumbai/ Bangalore
Role Overview
We are looking for an experienced Azure Security Architect to design and architect secure, resilient and scalable Microsoft Azure environments. The role will focus on Microsoft Security, Azure security architecture, identity, cloud security, SIEM/SOAR, endpoint security, data security and AI security.
The candidate will work with enterprise customers to assess security requirements, define security architecture, develop HLD/LLD, recommend Microsoft security solutions and provide technical leadership through implementation and operational transition.
The role also requires extensive hands-on experience in applying AI and GenAI technologies to automate and optimize enterprise processes. This includes designing secure Azure AI workloads using Microsoft Foundry and Azure OpenAI, building RAG solutions and AI agents, integrating intelligent automation with enterprise systems, and establishing appropriate data protection, responsible AI and operational controls.
Key Responsibilities
Azure Security Architecture
- Design end-to-end security architecture for Microsoft Azure and hybrid cloud environments.
- Develop security HLD/LLD, architecture diagrams, security controls and technical design documentation.
- Conduct security assessments and identify architectural gaps, risks and improvement opportunities.
- Define defense-in-depth, Zero Trust and security-by-design architecture.
- Design security controls across identity, endpoint, network, application, data and cloud layers.
- Define security architecture standards, patterns and reference architectures.
- Provide technical leadership during implementation, migration and transformation programmes.
Microsoft Security Architecture
Strong experience architecting and integrating the Microsoft security ecosystem, including:
Microsoft Defender
- Microsoft Defender for Endpoint (MDE / EDR)
- Microsoft Defender for Servers
- Microsoft Defender for Identity
- Microsoft Defender for Office 365
- Microsoft Defender for Cloud Apps (MDCA / CASB)
- Microsoft Defender for Cloud
- Microsoft Defender Vulnerability Management
- Microsoft Defender XDR
- Microsoft Defender for Cloud CSPM / CNAPP capabilities
Microsoft Sentinel
- Microsoft Sentinel SIEM/SOAR architecture
- Data connectors and log ingestion architecture
- Analytics rules and detection engineering
- Automation rules and Logic Apps
- Playbooks and SOAR orchestration
- Incident management and investigation workflows
- UEBA and threat detection
- Threat intelligence integration
- Sentinel workspaces, data architecture and cost optimization
- Integration with Defender XDR and third-party security platforms
- Sentinel migration and modernization
Microsoft Entra Security
- Microsoft Entra ID architecture
- Conditional Access
- MFA
- Privileged Identity Management (PIM)
- Identity Governance
- RBAC and least-privilege access
- Application identities and service principals
- Managed identities
- Identity Protection
- Zero Trust identity architecture
Microsoft Purview
- Microsoft Purview Information Protection
- Data Classification and Sensitivity Labels
- Data Loss Prevention (DLP)
- Insider Risk Management
- Information Governance
- Data lifecycle and retention
- Data security and compliance architecture
- Integration of Purview with Microsoft 365 and security platforms
Cloud Security / CNAPP
- Architect Microsoft Defender for Cloud across Azure and hybrid/multi-cloud environments.
- Design CSPM, CWPP and CNAPP security capabilities.
- Define cloud security posture management and security governance.
- Design workload protection for Azure VMs, containers, AKS and cloud services.
- Implement cloud security recommendations and risk remediation strategies.
- Design secure Azure landing zones and cloud security guardrails.
- Integrate cloud security findings with SIEM/SOC operations.
Network Security
- Design secure Azure network architectures using:
- Azure Firewall
- Web Application Firewall
- Application Gateway
- Azure Front Door
- Network Security Groups
- Private Endpoints / Private Link
- VPN Gateway
- ExpressRoute
- Azure DDoS Protection
- Azure Virtual WAN
- Design network segmentation and Zero Trust architectures.
- Define secure connectivity between on-premises, Azure and other cloud platforms.
- Design secure architectures for internet-facing and internal workloads.
Endpoint & Device Security
- Architect Microsoft Defender for Endpoint deployments at enterprise scale.
- Define endpoint security baselines and security controls.
- Design EDR/XDR capabilities and integration with SOC operations.
- Architect attack surface reduction, vulnerability management and endpoint protection.
- Integrate endpoint telemetry with Microsoft Sentinel and Defender XDR.
- Define security architecture for Windows, Linux, servers, VDI/AVD and other supported platforms.
AI-Driven Process Automation
- Identify, assess and prioritize business processes suitable for AI-led automation based on value, feasibility, risk and expected return on investment.
- Design end-to-end intelligent automation solutions using Microsoft Foundry, Azure OpenAI, Foundry Agent Service, Azure AI services and Azure Machine Learning.
- Build and orchestrate AI agents and agent-driven workflows that can reason, retrieve enterprise knowledge, invoke approved tools and complete governed business actions.
- Integrate AI capabilities with Azure Logic Apps, Azure Functions, API Management, Event Grid, Service Bus and enterprise APIs to automate cross-system workflows.
- Use Microsoft Copilot Studio, Power Automate, Power Apps and AI Builder where low-code automation is appropriate, while defining enterprise architecture, security and governance guardrails.
- Design document and content automation using Azure Document Intelligence, Content Understanding, language, vision and speech services to classify, extract, summarize and route information.
- Develop RAG and knowledge-grounded automation using Azure AI Search, vector stores and approved enterprise data sources.
- Apply prompt engineering, structured output, function and tool calling, human-in-the-loop controls, exception handling and fallback patterns to improve automation reliability.
- Define monitoring and evaluation for AI automations, including accuracy, groundedness, latency, throughput, cost, security events, business outcomes and operational handover.
- Create reusable automation patterns, reference architectures and accelerators that support secure adoption across multiple business functions.
AI & GenAI Security
- Design security architecture for Azure AI, Microsoft Foundry and Azure OpenAI workloads.
- Secure AI applications, models, APIs, agents and supporting infrastructure.
- Design security controls for RAG architectures, vector stores and enterprise data.
- Protect sensitive organizational data used by AI applications.
- Define identity, RBAC, network isolation and private connectivity for AI workloads.
- Assess AI-specific threats including prompt injection, data leakage, excessive permissions and insecure AI agents.
- Define AI security monitoring and integration with Microsoft Defender and Sentinel.
- Apply responsible AI, privacy and governance principles.
- Design controls for secure adoption of enterprise GenAI and Copilot solutions.
Security Operations Integration
- Design integration between Microsoft security platforms and SOC operations.
- Define security event flows from Defender, Entra, Purview, Azure and third-party platforms into Sentinel.
- Define alert prioritization, incident enrichment and automated response.
- Architect SIEM/SOAR onboarding and operational workflows.
- Define use-case architecture, detection strategy and security monitoring requirements.
- Support SOC transformation, SIEM migration and security platform optimization.
Security Governance & Compliance
- Define security governance and control frameworks for Azure.
- Map technical controls relevant security and compliance requirements.
- Define Azure Policy and security governance standards.
- Support security risk assessments and architecture reviews.
- Ensure security designs comply with organizational security policies and regulatory requirements.
- Develop security standards, reference architectures and reusable security patterns.
Required Technical Skills
- Strong experience in Azure Security Architecture.
- Strong understanding of Microsoft security ecosystem.
- Hands-on architecture experience with Microsoft Defender, Sentinel, Entra ID and Purview.
- Strong knowledge of Zero Trust architecture.
- Strong Azure networking and cloud security knowledge.
- Experience with SIEM/SOAR and SOC integration.
- Experience designing enterprise-scale security solutions.
- Strong understanding of identity and access management.
- Knowledge of cloud security, CSPM/CNAPP and workload protection.
- Experience with security architecture documentation, HLD/LLD and design governance.
- Strong stakeholder and customer-facing communication skills.
AI Automation Technical Skills
- Extensive hands-on experience delivering production-grade AI-powered process automation and measurable business outcomes.
- Strong architecture and development experience with Microsoft Foundry, Azure OpenAI, Foundry Agent Service and relevant Azure AI services.
- Experience developing AI agents, multi-agent workflows, tool integrations and knowledge-grounded solutions using RAG.
- Proficiency in Python or C#, REST APIs, JSON, event-driven integration and Azure SDK-based solution development.
- Experience integrating AI solutions with Azure Logic Apps, Azure Functions, API Management, Service Bus, Event Grid and enterprise applications.
- Practical knowledge of Copilot Studio, Power Automate, Power Apps and AI Builder for governed low-code automation.
- Strong knowledge of prompt engineering, structured outputs, function calling, model selection, evaluation, guardrails and human-in-the-loop design.
- Experience with Azure AI Search, vector databases, document processing, content extraction and enterprise knowledge integration.
- Understanding of LLMOps/MLOps, CI/CD, model and prompt versioning, observability, performance optimization and AI cost management.
- Ability to assess automation opportunities, redesign processes, define success metrics and translate business requirements into secure technical architectures.
AI Security Skills
- Generative AI and LLM security fundamentals.
- Azure AI / Microsoft Foundry security architecture.
- Azure OpenAI security.
- RAG security and data protection.
- AI agent security and identity.
- Prompt injection and AI application security.
- AI data governance and privacy.
- AI security monitoring and threat detection.
- Responsible AI and AI governance.
- Understanding of emerging AI Security / AI-SPM concepts is an advantage.
Certifications
Preferred certifications include:
- Microsoft Certified: Cybersecurity Architect Expert – SC-100
- Microsoft Certified: Azure Solutions Architect Expert – AZ-305
- Microsoft Certified: Azure Security Engineer Associate – AZ-500
- Microsoft Certified: Identity and Access Administrator – SC-300
- Microsoft Certified: Security Operations Analyst – SC-200
- Microsoft Certified: Information Protection and Compliance Administrator – SC-400
- Relevant AI certifications such as Azure AI / AI Engineer or AI Apps and Agents Developer certifications.
Experience
- 8+ years of experience in cybersecurity, cloud security or security architecture.
- 5+ years of experience designing Microsoft/Azure security solutions.
- Strong enterprise experience across Microsoft Security technologies.
- Experience leading security architecture for large-scale cloud transformation programmes.
- Experience working with SOC, infrastructure, application, identity and compliance teams.
- Experience in customer-facing architecture workshops and technical solution presentations.
- 3+ years of hands-on experience designing and implementing AI, GenAI or intelligent automation solutions, with evidence of successful production deployments.
- Experience with AI/GenAI security architecture is highly desirable.
- Demonstrated experience automating document-intensive, knowledge-intensive or decision-support processes and quantifying improvements in cycle time, quality, productivity or cost.
Here at Atos, diversity and inclusion are embedded in our DNA. Read more about our commitment to a fair work environment for all.
Atos is a recognized leader in its industry across Environment, Social and Governance (ESG) criteria. Find out more on our CSR commitment.
Choose your future. Choose Atos.