Cloud Security Architect

  • Intern
  • Legal Entity: Bosch Service Solutions Inc.

Company Description

At Bosch, we shape the future by inventing high-quality technologies and services that spark enthusiasm and enrich people’s lives. Our promise to our associates is rock-solid: we grow together, we enjoy our work, and we inspire each other. Join in and feel the difference.

Established in 1985 as a monitoring center and provider of communication services, Bosch Service Solutions Inc. today ranks among the leading international providers of Business Process Outsourcing services. Employing more than 4,000 associates in Europe, Asia and South America, Bosch Service Solutions Inc. provides and optimizes business processes for our customers.

Job Description

Role Overview

The Cloud Security Architect will lead and elevate our cloud security posture across the BU, with a strong emphasis on Microsoft Azure. The ideal candidate is deeply experienced in cloud security principles, tooling, and governance, while also bringing a solid understanding of cloud architecture and development best practices to ensure secure-by-design cloud solutions. This role is crucial in aligning cloud security strategy with business requirements, guiding secure cloud adoption, and collaborating with product teams, cloud engineers, and external consultants.

Key Responsibilities

  • Leads the design, implementation, and governance of Azure cloud security controls, aligned with industry standards (e.g., CIS, NIST, ISO 27001)
  • Continuously strengthen Azure security posture using tools such as Defender for Cloud, Sentinel, Azure Policy, RBAC, and PIM
  • Develops and maintains cloud security policies, standards, and secure configuration baselines.
  • Coordinates the identification, prioritization, and remediation of cloud vulnerabilities and misconfigurations.
  • Supports security assessments, threat modeling, and risk analysis for cloud based solutions.
  • Provides guidance during cloud security incidents and contribute to incident response processes and root cause analysis.
  • Collaborates with cloud architects and development teams to ensure secure-by design patterns and reference architectures.
  • Provides architectural security input on Azure services, identity models, network design, and application deployment patterns.
  • Supports the creation of reusable secure infrastructure templates (e.g., Pulumi, Terraform) and DevSecOps automation.
  • Translates technical security risks into clear business impacts for stakeholders.
  • Willingness to grow into taking care of overarching Security Management topics. Support audits, compliance initiatives, and risk assessments. Serve as a key liaison between engineering teams, security consultants, and business stakeholders.

Qualifications

Must-Have

  • Proven hands-on experience with Azure cloud security engineering and architecture.
  • Strong understanding of cloud security frameworks, controls, and regulatory requirements.
  • Experience with Azure security tooling (Defender for Cloud, Sentinel, Azure Policy, RBAC, PIM, logging/monitoring).
  • Familiarity with application and API security principles (e.g., OWASP Top 10).
  • Experience working with cross-functional teams and external security vendors.

Nice to Have

  • Background in cloud architecture, platform engineering, or solution architecture (Azure preferred).
  • Experience with infrastructure-as-code (Terraform, Bicep) and CI/CD security integration.
  • Knowledge of DevSecOps practices and cloud-native security toolchains.
  • Cloud incident response experience in hybrid or cloud-native environments.

Education

  • Bachelor’s degree in Computer Science, Information Technology, Engineering, or a related field.

Certifications (Preferred, Not Required)

  • AZ-500 — Microsoft Azure Security Engineer Associate
  • SC-100 — Microsoft Cybersecurity Architect Expert
  • AZ-305 — Azure Solutions Architect Expert
  • CISSP, CCSP, or similar cloud/security certifications

Additional Information

Kindly attach your resume in your application. Only shortlisted candidates will be contacted via email.

Privacy NoticeImprint