Manager - Cloud Technologies S 4D
Ready to turn bold ideas into real-world impact?
At Genpact, we don’t just adapt to change, we lead it. AI and digital innovation are transforming the way businesses work, and we’re at the forefront of it. Genpact’s AI Gigafactory, our industry-first accelerator, exemplifies how we scale advanced technology solutions to help global enterprises work smarter, grow faster, and transform at scale. Whether tackling complex challenges through large-scale models or agentic AI, our breakthrough solutions tackle companies’ most complex challenges.
If you thrive in a fast-moving, innovation-driven environment, love building and deploying cutting-edge AI solutions, and want to push the boundaries of what’s possible, this is your moment.
Genpact (NYSE: G) is an agentic and advanced technology solutions company. We leverage process intelligence and artificial intelligence to deliver measurable outcomes. With a strong partner ecosystem and decades of client trust, we provide innovative solutions that transform how businesses run. Powered by a team with an active learning mindset and client centricity at its core, we deliver lasting value for the world’s leading enterprises.
Get to know us at genpact.com and on LinkedIn, YouTube, X, and Facebook.
Job Description
Key Responsibilities
Bring-Your-Own Storage (BYOS) Management
- Own the complete lifecycle and security posture of NH2030-supplied Azure Storage Accounts registered as Unity Catalog external locations in ADP Databricks
- Configure storage firewall rules, Private Endpoints, and IP allowlists for BYOS storage accounts
- Set up and manage geo-replication and failover decisions for BYOS storage
- Enable and configure Defender for Storage on all BYOS accounts
- Manage Customer-Managed Keys (CMK) for BYOS storage encryption
- Configure container-level ACLs, SAS token policies, and key rotation schedules
- Enable immutability (WORM) locks and resource locks on BYOS storage containers as required by data classification
- Enable and manage Malware Scanning on BYOS storage accounts
- Own BYOS storage cost management, capacity planning, Azure Monitor alerts, and operational runbooks
Key Vault & Secret Management
- Coordinate with AzTech for provisioning of ADP-managed Key Vaults (minimum 1 per OE per stage)
- Configure Databricks KV-backed secret scopes using the provisioned Key Vaults
- Store and manage initial secrets required for storage access, external service connections, and API keys
- Implement and enforce secret rotation policies; ensure no credentials are stored in notebooks or code
- Configure Key Vault access policies and RBAC for the NH2030 Service Principals and team members
- Manage BYOS-specific Key Vault for CMK: RSA 4096, automated rotation, purge protection
Service Principal (SP) Lifecycle – Entra ID
- Create Service Principals in Entra ID (via GIAM) for CI/CD pipelines, automated jobs, data ingestion, and integration services
- Coordinate GIAM group membership for SPs (currently limited by SCIM sync; follow Automatic Identity Management roadmap)
- Support IAM Specialist in registering SPs in the Databricks account and assigning to workspace groups
- Generate and securely store SP credentials in KV-backed secret scopes for CI/CD pipeline use
- Monitor SP access and rotate credentials on schedule; immediately revoke on programme offboarding
Private Endpoint & Network Connectivity
- Identify and document all private endpoint requirements for NH2030 workloads (BYOS storage, Key Vault, external services)
- Raise requests with ADP Platform Team (AzTech) for additional private endpoints beyond default transitional zone connectivity
- Prepare and submit FQDN whitelisting requests via ServiceNow for both classic compute (to FCP firewall) and serverless compute (to ADP network policies)
- Identify all egress FQDNs required by NH2030 workloads: external APIs, data sources, PyPI/Nexus, container registries
- Validate private connectivity is functioning correctly post-provisioning for all required endpoints
BYOS Backup & Disaster Recovery
- Enable soft delete and blob versioning on all BYOS storage accounts
- Provision and configure Azure Backup Vault for BYOS storage backup
- Define and implement retention policies per NH2030 data retention and regulatory requirements
- Document and test restore procedures for BYOS storage accounts
- Contribute to the NH2030 DR runbook for BYOS storage failover and recovery
Infrastructure Planning & Request Coordination
- Document Key Vault and storage account requirements upfront (number of vaults per stage, ADP-managed vs BYOS breakdown)
- Confirm environment naming and tagging conventions with ADP Platform Team prior to SNOW request submission
- Monitor SNOW tickets for AzTech provisioning completion (subscription, VNET, storage, workspace)
- Act as technical interface for infrastructure queries during ADP/SPM review of SNOW provisioning requests
ADP-Specific Activities (from Operational Responsibility Matrix)
Primary Activities
Supporting Activities
- BYOS storage security controls (Defender, CMK, ACLs, SAS, WORM) – P5-07
- BYOS storage network config (firewall, PEs, geo-replication) – P6-04
- BYOS backup and retention configuration – P8-03
- Key Vault-backed secret scope configuration – P4-07
- Service Principal creation in Entra ID – P3-03
- FQDN whitelisting requests (Classic & Serverless) – P5-02
- Environment naming and tagging convention – P0-04
- Key Vault and storage requirements documentation – P0-05
- SNOW infrastructure provisioning monitoring – P2-01, P2-02, P2-03
- Private endpoint requests and validation – P2-01
- BYOS integration with Unity Catalog (external location) – P6-04
- DR runbook contribution for BYOS storage – P8-03, P8-04
Required Skills & Experience
Core Technical Skills
Supporting Skills
- 3+ years Azure cloud engineering in enterprise environments
- Azure Storage (ADLS Gen2): lifecycle, networking, firewall, geo-replication
- Azure Key Vault: RBAC, secret management, CMK, key rotation, purge protection
- Azure Private Endpoints, Private DNS Zones, VNet integration
- Entra ID (Azure AD): Service Principal creation, GIAM interaction, PIM
- Azure Defender for Storage and Malware Scanning configuration
- WORM/immutability policies and resource locks for compliance
- Databricks Access Connectors and Unity Catalog external locations
- Azure networking fundamentals: VNet, NSG, UDR, peering, DNS
- RBAC design on Azure resources (Storage Blob Data Reader/Contributor, Key Vault roles)
- ServiceNow for infrastructure request management
- Azure Monitor alerts and operational runbook development
- Terraform (advantageous – ADP team uses for infrastructure deployment)
- Azure Backup Vault and storage-level disaster recovery
- Understanding of Azure Firewall FQDN allowlisting processes
- Experience working in regulated financial services environments
Certifications
- AZ-104 Microsoft Azure Administrator (required)
- AZ-305 Microsoft Azure Solutions Architect Expert (desirable)
- SC-300 Microsoft Identity and Access Administrator (desirable)
- AZ-500 Microsoft Azure Security Technologies (desirable)
Key Interfaces
- ADP Platform Team (AzTech): SNOW requests, BYOS external location registration, Private Endpoint provisioning, FQDN firewall rules
- FCP (Allianz Networking): Private DNS zones, hub routing for BYOS in FCP-connected subscriptions
- GIAM Team: Service Principal creation in Entra ID, group membership coordination
- Lead Databricks Platform Engineer: Secret scope setup, BYOS integration in Unity Catalog, SP workspace assignment
- Security / DevSecOps Engineer: BYOS security controls alignment, CMK configuration, Defender for Storage
Qualifications
Bachelors - Cloud Computing, Bachelors - Computer Science, Bachelors - Information Technology, Bachelors - Network Engineering, Masters - Computer ScienceCertifications
AWS Certified Solutions Architect - Professional - Amazon Web Services (AWS)Amazon Web Services (AWS), Certified Information Security Manager (CISM) - ISACA – Information Systems Audit and Control AssociationISACA – Information Systems Audit and Control Association, Certified Information Systems Security Professional (CISSP) - Workforce Academy OnlineWorkforce Academy Online, Red Hat Certified Engineer (RHCE) - Red HatRed HatRequired Skills
Agile Methodology, Change Management, Client Relations, Cloud Computing, Collaboration Tools, Design Thinking, Executive Presence, Inclusion, Information Technology (IT) Infrastructure, IT Service Management (ITSM), Modernizing Operations, People Leadership, Personal Effectiveness, Risk Management, StorytellingLanguage
English (Required), English (Required)Language Proficiency -
Advanced - C1Additional Job Location -
Job Type
RegularMaster Skill List -
Cloud Technologies SRemote Type -
HybridWork Shift -
Flex Time (India)Why join Genpact?
• Lead AI-powered transformation – Drive innovation and solve real-world business challenges that matter
• Make an impact – Help global enterprises solve business challenges that matter
• Accelerate your career – Gain hands-on experience, mentorship, and world-class learning opportunities to stay ahead
• Work with the best – Join 140,000+ bold thinkers and problem-solvers who push boundaries every day
• Thrive in a values-driven culture – Our courage, curiosity, and incisiveness - built on a foundation of integrity and inclusion - allow your ideas to fuel progress
Come join the 140,000+ coders, tech shapers, and growth makers at Genpact and take your career in the only direction that matters: Up.
Let’s build tomorrow together.
Genpact is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, religion or belief, sex, age, national origin, citizenship status, marital status, military/veteran status, genetic information, sexual orientation, gender identity, physical or mental disability or any other characteristic protected by applicable laws. Genpact is committed to creating a dynamic work environment that values respect and integrity, customer focus, and innovation.
Furthermore, please do note that Genpact does not charge fees to process job applications and applicants are not required to pay to participate in our hiring process in any other way. Examples of such scams include purchasing a 'starter kit,' paying to apply, or purchasing equipment or training.