appropriate privileged access controls. Implement platform governance using management groups, subscriptions, landing zone controls, Azure Policy and initiatives, Defender for Cloud, secure score and regulatory compliance capabilities. Engineer network security controls including virtual networks, network security groups, Azure Firewall, web application firewall, Private Link and private endpoints … including information protection, sensitivity labels, data classification, data loss prevention, retention and records controls. Investigate and resolve cloud security issues, configuration drift, policy non-compliance and implementation defects, documenting root cause and corrective action. Automation and DevSecOps: Build and maintain secure, repeatable deployments using Bicep, Terraform, PowerShell, Azure ...