SharePoint Security Architect at EVOCS India · Jaipur · 5 - 10 years · ₹15L - ₹30L / yr · Profitable · Posted 7 Jan 2026

SharePoint Security Architect
EVOCS is seeking a SharePoint Security Architect to lead a engagement focused on discovery and future state recommendations for a large enterprise SharePoint Online environment.
This role is heavily assessment-driven: you will map the tenant, identify architectural and security gaps, and produce deliverables including a Gap Register, Data Exposure Catalog, Architecture Map, and a Future State Recommendations Report. You will be hands-on with discovery, confident in stakeholder engagement, and able to translate complex findings into clear, actionable reports.
Responsibilities
Discovery and Analysis
- Inventory and map the entire SharePoint Online estate (sites, hubs, Teams-backed sites, channel sites, OneDrive interactions).
- Extract and analyze site and library permissions, identify inheritance breaks, and highlight excessive role assignments.
- Enumerate all external sharing links, classify by type (Anyone, Org-wide, Specific People), and review expiry posture.
- Catalog guest accounts and sponsorship status; identify stale or unmanaged guests.
- Review tenant and site-level settings affecting external collaboration.
- Assess adoption of sensitivity labels, DLP coverage, retention/records configuration, and conflicts.
- Evaluate monitoring and logging posture, Unified Audit Log retention, and SIEM routing.
- Inventory third-party applications, OAuth consents, and risky Power Automate flows.
Gap Register and Reporting
- Produce a Gap Register: clear gap statements with evidence, risk scoring (severity/likelihood), business impact, and suggested owners.
- Build a Data Exposure Catalog for sensitive libraries and their exposure posture.
- Deliver an Architecture Map showing current hubs, sites, and high-risk clusters.
- Develop an Executive Heat Map of the top 10 risks.
Future State Recommendations
- Define a target SharePoint security and governance model:
- Site provisioning, ownership, and lifecycle controls.
- External collaboration model (guest lifecycle, expirations, access reviews).
- Baseline tenant and site settings for sharing, links, and unmanaged device sessions.
- Content protection model (sensitivity labels, auto-labeling, DLP tiers, retention standards).
- Monitoring and alerting strategy with dashboards and escalation paths.
- Outline a phased roadmap with quick wins, 90-day baselines, and a 6-month uplift.
Communication and Stakeholder Engagement
- Lead technical workshops with admins, security engineering, and business data owners.
- Translate technical findings into business-focused risks and recommendations.
- Produce polished deliverables: Discovery Workbook, Gap Register, Recommendations Report, and executive presentation decks.
Required Skills and Experience
- 7+ years of experience with Microsoft 365 and SharePoint Online in large, enterprise environments.
- Proven track record leading at least two tenant-wide SharePoint security or architecture assessments.
- Strong understanding of Microsoft Entra ID (Azure AD) identity and access controls: Conditional Access, PIM, access reviews, cross-tenant access.
- Hands-on expertise with Microsoft Purview: sensitivity labels, DLP, retention, records management.
- Knowledge of Microsoft Defender for Cloud Apps and Defender for Office 365.
- Strong familiarity with Unified Audit Log, KQL queries, and SIEM integrations.
- Experience auditing app consents and Power Automate flows for data leakage risk.
- Proficiency with PnP.PowerShell, Microsoft Graph, and PowerShell scripting.
- Exceptional ability to produce clean, evidence-driven documentation and reports.
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Microsoft Certified: Security Engineer Associate (AZ-500)
- CISSP or CCSP (optional, for broader security framing)
Core Attributes
- Analytical, detail-oriented, and evidence-driven.
- Skilled at stakeholder communication and risk storytelling.
- Strong documentation and executive presentation skills.
- Comfortable with ambiguity; able to structure unorganized environments.

About EVOCS India
About
Company social profiles
Similar jobs (10)
Location : Kochi
Candidated must be in Kerala and should be willing to relocate.
Notice Period : up to 30 days
Job Summary
We are seeking a motivated and detail-oriented Junior Azure Cloud Engineer with 2–3 years of experience in Microsoft cloud technologies. The ideal candidate will have hands-on experience in Microsoft Azure infrastructure services and Microsoft 365 administration. This role involves supporting cloud environments, managing identity and security, and assisting in cloud-based deployments and operations.
Key Responsibilities
- Manage and support Azure Entra ID (Azure Active Directory) including user management, group policies, conditional access, and identity governance.
- Configure and maintain Azure networking components such as Virtual Networks (VNet), Subnets, NSGs, VPN, and Load Balancers.
- Deploy and manage Azure Compute services including Virtual Machines, App Services, and related infrastructure.
- Administer Azure Storage services (Blob, File Shares, Backup, etc.).
- Monitor and maintain Microsoft 365 environments including Exchange Online, Teams, and SharePoint Online.
- Administer SharePoint Online sites, permissions, and configurations.
- Manage and monitor security policies using Microsoft 365 Security Center.
- Support cloud governance, compliance, and security best practices.
- Troubleshoot cloud infrastructure and M365-related issues.
- Collaborate with internal teams to support cloud migration and deployment activities.
- Document configurations, processes, and standard operating procedures.
Required Skills & Qualifications
- 2–3 years of hands-on experience in Microsoft Azure cloud services.
- Strong experience with Azure Entra ID, Azure Networking, Azure Storage, and Azure Compute services.
- Experience in Microsoft 365 Administration.
- Hands-on experience in SharePoint Online administration.
- Experience working with Microsoft 365 Security Center.
- Good understanding of cloud security, identity management, and governance.
- Strong troubleshooting and problem-solving skills.
- Good communication and documentation skills.
Nice to Have (Added Advantage)
- Experience with Azure DevOps (CI/CD pipelines, Repos, Boards, etc.).
- Basic scripting knowledge (PowerShell, Azure CLI).
- Azure or Microsoft 365 certifications.

- SharePoint 2019 solutions – Knowledge
- Out Systems applications
- .NET applications -Mandatory
- SQL Server databases
- Windows Server and IIS deployments- Mandatory
- Application troubleshooting and production support -Mandatory
- Security vulnerability remediation
- SonarQube code quality analysis -Mandatory
- Release deployment validation and technical troubleshooting -Mandato
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Sharepoint Developer with SPFx @ PAN, India
SPFx
Location: Pan India
Exp: 5+
Shift Timings: 11:30AM to 8:00pm
Requested 2 developers should be skilled in,
- SPFx, Azure Functions, Power Automate, SharePoint List.
- E2E software development lifecycle Agile delivery model in multiple sprints.
- Good communication skill to interact daily with customer during implementation phases and follow all formal communication methodologies.
Strong knowledge with min 3 to 4 years in SPFx (Webparts and Extensions development experience)
Position: Technical Lead – Forcepoint (Data & Cloud Security)
Company: Inflow Technologies
Location: Bangalore
Work Mode: Work From Office | 5 days/week
Experience Required: Minimum 6 years
Interview Process: 2 rounds (Virtual + Final Face-to-Face)
About Inflow Technologies
Founded in 2005, Inflow is a value-added IT infrastructure distributor covering Networking, Cybersecurity, UC&C, AIDC, Surveillance, Server, Storage & Software across India/South Asia. HQ'd in Bangalore with 20+ locations, backed by a 120+ certified technical team, and ~USD 700M+ annual run-rate revenue.
Position Overview
Acting as the Forcepoint subject matter expert, this role owns end-to-end design, deployment, and troubleshooting of enterprise data and cloud security architectures — spanning DLP, SWG, CASB, and SSE/ZTNA. The role sits at the intersection of solution architecture and hands-on L3 execution: defining security policies, configuring network proxies, and resolving complex support escalations in a client-facing, consultative capacity.
Core Products
- Forcepoint DLP (Endpoint, Network, Web, Email)
- Forcepoint Web Security
- Forcepoint Email Security
- Forcepoint CASB
- Forcepoint Suite / Forcepoint One
- Forcepoint Cloud Security / SSE (incl. ZTNA)
- Forcepoint DSPM
Key Responsibilities
1. Solution Design & Architecture
- Design enterprise architectures: DLP (Endpoint + Network + Discovery), Web Security (Proxy/Hybrid/Cloud), CASB & SaaS protection, Forcepoint Suite/One
- Install & configure Management Server, Policy Engine, Detection Servers, Protectors (Email/Web/Network), Endpoint agents (Windows/Mac)
- Implement EDM/IDM/OCR and data classification policies
2. Web Security (SWG)
- Deploy on-prem (V-series appliances) and cloud SWG/hybrid mode
- Configure transparent/explicit proxy, SSL inspection, URL filtering
3. Email Security
- Configure SMTP routing, DLP email policies, encryption & compliance rules
4. Advanced Policy Configuration
- Design/tune DLP policies (structured + unstructured data), web filtering (user/group/app-based), cloud app governance rules
5. L3 Troubleshooting & RCA (Critical)
- Handle: DLP not detecting over HTTPS, endpoint agent communication failures, web proxy latency/SSL failures, policy not applying to users, email DLP bypass
- Approach: log analysis (Policy Engine, endpoint, web), packet capture/traffic analysis, root cause identification & permanent fix
Qualifications & Certifications (Preferred)
- Bachelor's degree (IT/CS or related)
- Forcepoint Certified Administrator (FCA)
- Forcepoint DLP Specialist
- CCNA / Security+ (nice-to-have)
Job Title: Technical Consultant – Netskope & SSE (L3 Engineer)
Company: Inflow Technologies
Location: Bangalore (Work From Office, 5 days/week)
About Inflow Technologies:
Inflow Technologies, founded in 2005 and headquartered in Bangalore, is a leading value-added IT infrastructure distributor across Networking, Cybersecurity, Unified Communications, AIDC, Surveillance, Server, Storage, and Software. With 20+ locations across India/South Asia and a 120+ member certified technical team, Inflow supports channel partners through the full solution sales cycle. Annual run-rate revenue: USD 700+ Million.
Position Overview:
We're looking for an experienced Technical Consultant (L3 Engineer) specializing in Netskope and Security Service Edge (SSE) technologies. You'll own end-to-end architecture, design, deployment, and optimization of cloud security solutions — acting as a trusted advisor who translates business requirements into secure, scalable technical architectures, and resolves advanced issues through root cause analysis.
Key Responsibilities:
Implementation & Deployment
- Deploy Netskope CASB (API + Proxy), SWG, DLP (Email/Web/Network), ZTNA (Private Access), NPA, and Prime Advantage package
- Configure traffic steering (Client, GRE, IPsec), policy rules (DLP, URL filtering, access control), and dashboard fine-tuning
- Perform agent rollout across Windows, Mac, and Mobile
Architecture & Design
- Design a secure access architecture for remote users, branch offices, and cloud workloads
- Integrate with identity providers (Azure AD, Okta) and existing security stack (Firewall, Proxy, SIEM)
- Integrate Netskope with SIEM (Splunk, QRadar), EDR tools, and email security
- Configure SSO/SAML authentication
Required Qualifications:
- Bachelor's degree in IT/CS or related field
- 6–8 years of experience (L3 level)
- Preferred certifications: Netskope Certified Cloud Security Architect (NCSA), NSK 100/200/300, CCNA/Security+ (good to have)
Interview Process: 2 rounds (Virtual) + Final round (Face-to-Face)
Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience).
3+ years of hands-on experience with Microsoft Azure, including IaaS, PaaS, networking, identity (Entra ID), and governance services.
2+ years of experience with DevOps tooling and practices, including CI/CD pipelines (Azure DevOps or GitHub Actions), Infrastructure as Code (Terraform, Bicep, or ARM), and version control (Git).
2+ years' experience in infrastructure design, platform engineering, or architecture.
Strong proficiency with automation and scripting — PowerShell, Azure CLI, Python, or Bash.
Solid understanding of containerisation (Docker) and familiarity with orchestration platforms (Azure Kubernetes Service).
Deep understanding of cloud architecture, deployment patterns, and management best practices, including the Azure Well-Architected Framework.
Experience defining standards, governance frameworks, and reference architectures for cloud platform consumption.
Strong knowledge of networking concepts, storage configurations, virtualisation technologies, and disaster recovery/backup design for hybrid environments.
Experience with Azure DevOps (Repos, Pipelines, Boards, Artifacts) or equivalent platforms.
Familiarity with identity and access management (IAM), including Entra ID, RBAC, PIM.
Strong understanding of security, compliance requirements, and IT governance frameworks (ITIL, COBIT, or similar).
Preferred
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
Job Description:
Job title : Cloud Architect
Experience: 10+ years
Location: Chennai / Pune / Hyderabad / Bangalore
Shift: UK Shift
Work Mode: Onsite(WFO)
Notice Period: Immediate Joiner/ serving notice period only
Project Scope:
This engagement automates end-to-end infrastructure build provisioning across on-prem and Azure. The team will build a shared ServiceNow-led intake, approval, orchestration, and closed-loop status model, using Jenkins/Ansible for on-prem builds and Azure DevOps/Terraform for cloud builds. Automation includes standards, security/compliance controls, scan gates, CMDB/change updates, and handover.
Roles and Responsibilities:
Define Azure automation architecture, governance, and reusable cloud build patterns.
Own Azure architecture for automated build provisioning using the ServiceNow-led control plane.
Define approved build patterns, SKUs, landing-zone integration, Terraform standards, Azure DevOps architecture, and guardrails.
Translate security, compliance, resiliency, tagging, cost, and data-residency requirements into automated controls.
Design ServiceNow, rules engine, Azure DevOps, Terraform, Azure Policy, CMDB, and callback integrations.
Review solution designs and assure quality with cloud, security, finance, and platform teams.
Required Skills:
Azure landing zones, networking, RBAC, Key Vault, Azure Policy, Terraform, Azure DevOps, FinOps, ServiceNow APIs.
10+ years in infrastructure/cloud engineering; 5+ years designing Azure solutions.
Bachelor’s degree or equivalent experience; Azure Solutions Architect certification preferred.
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.










