Strong grasp of security engineering (IAM design, secrets, key management, network security, container security, vulnerability mgmt) and policy-as-code. * Establish multi-cloud landing zones (AWS Organizations + Control Tower; Azure Management Groups + Landing Zones) with policy, identity, and network guardrails. * Build an internal platform (IDP) that abstracts complexity and provides self-service: project scaffolding, environment creation, CI/CD, observability, and secrets management. * Drive pipeline-native IaC (GitOps principles, PR-based workflows, security scans, unit/integration tests, drift detection, and change approvals). Security, Governance, and Compliance * Design identity-first architectures (Azure AD/Microsoft Entra ID,
mehr