Cloud Engineer (SRE), Assistant Manager – Deloitte Support Services India Private Limited
Organisation Summary
At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.
Team Summary
The Hybrid Infrastructure Management Services function is accountable for Cloud Infrastructure provisioning, DevOps, system administration, Cloud Infrastructure administration, server builds, virtualized application support, user support, application support, patching, troubleshooting, break fix, automation FCR etc. This function is responsible for working with Internal/External clients across the firm and works closely with other ITS teams.
Location: Bangalore
Work shift Timings:
- Shifts (India time): 2:00 PM – 11:00 PM (IST)
- Working on USI holidays and oncall during weekends when there is a business requirement.
Specific Responsibilities
- Administer and harden Windows and Linux servers across on‑prem (e.g., VMware/vSphere/ESXi, Hyper‑V) and cloud (Azure, AWS, GCP).
- Operate core services: Active Directory/Entra ID, DNS/DHCP, PKI, NTP, NFS/SMB, IIS/Apache/Nginx, file/print, RDS/Terminal Services.
- Manage backup/restore and disaster recovery (on-prem and cloud-native), test failover, and validate RPO/RTO.
- Implement and maintain monitoring, logging, and alerting (e.g., Azure Monitor/Log Analytics, AWS CloudWatch/CloudTrail, GCP Cloud Monitoring/Logging, Prometheus/Grafana), define SLIs/SLOs, and reduce alert noise.
- Drive Infrastructure as Code (IaC): Terraform (preferred), plus Azure Bicep/ARM, AWS CloudFormation where needed.
- Build CI/CD pipelines for infrastructure (GitHub Actions, Azure DevOps, GitLab CI, Jenkins) with policy-as-code, pre-deploy validations, and automated testing.
- Create and maintain configuration management (Ansible preferred; Chef/Puppet acceptable) for idempotent server builds, patch baselines, middleware configs, and security controls.
- Develop reusable modules/roles and self-service workflows (ServiceNow/Jira integration) for standardized, compliant provisioning.
- Script with PowerShell and Python (Bash optional) to automate routine tasks, audits, and incident remediation.
- Implement and operate landing zones (hub/spoke, VPC/VNet design), networking (routing, firewalls, load balancers, VPN/ExpressRoute/Direct Connect), and hybrid connectivity.
- Manage cloud IAM (Azure Entra ID/AAD, AWS IAM, GCP IAM), Key Vault/KMS/Secrets Manager, and role-based access.
- Oversee cost optimization/FinOps basics: rightsizing, scheduling, reservations/savings plans, and tagging/chargeback.
- Enforce hardening baselines (CIS/NIST), vulnerability remediation, patch orchestration, and least privilege access.
- Integrate with EDR, vulnerability scanners, and SIEM, support audits, evidence collection, and remediation tracking.
- Embed guardrails in pipelines (OPA/Conftest, Sentinel, Policy as Code) to prevent misconfigurations.
- Lead/participate in post-incident reviews with actionable remediation and knowledge articles/runbooks.
- Identify toil; implement automation/standardization to reduce MTTR and increase deployment reliability.
- Partner with app teams and DBAs; support container platforms (Docker, Kubernetes/AKS/EKS/GKE) for infrastructure dependencies.
Qualifications
Required:
- Education (degree): Bachelor’s degree/College diploma in Computer Science or equivalent industry experience
- 7–10+ years in systems administration/engineering across on-prem data centers and at least one major cloud (Azure, AWS, or GCP). Comfortable in all three is a plus not required
- Strong automation mindset with demonstrated delivery using Terraform (or equivalent IaC), Ansible, PowerShell, and Python.
· Solid Windows and Linux admin, identity (AD/Entra), networking (TCP/IP, DNS, DHCP, load balancing, VPN), storage (SAN/NAS), and virtualization (VMware/Hyper‑V).
· Proven experience building CI/CD pipelines for infrastructure, Git workflows, and artifact/version management.
· Hands-on monitoring/observability and logging in at least one major cloud, plus metric design (SLIs/SLOs) and alert tuning.
· Security basics: least privilege, secrets management, encryption, patching/vuln remediation, and compliance awareness.
· Strong documentation, cross-team communication, and on-call maturity.
Preferred
- Kubernetes fundamentals (AKS/EKS/GKE), cluster operations, and GitOps (Argo CD/Flux).
- Experience with ServiceNow/Jira automation, CMDB hygiene, and ITIL practices (Incident/Problem/Change).
- Exposure to SRE practices (error budgets, reliability patterns) and FinOps reporting.
Preferred Certifications (not a pre-requisite for the role):
- ITIL Foundation
- Azure Administrator (AZ‑104)
- Solutions Architect (AZ‑305)
- AWS SysOps/Architect, GCP Associate/Professional, HashiCorp Terraform Associate