Valocity
Cloud Infrastructure & Technical Assurance Lead
Skills
Job description
About the Role
The Cloud Infrastructure & Technical Assurance Lead is a senior technical role within Valocity's global IT Operations function.
The role combines three areas that are normally treated separately:
Cloud infrastructure and security governance
Technical compliance, evidence and audit readiness
Customer-facing technical architecture and assurance
The successful candidate must be capable of working directly with Azure infrastructure while also representing Valocity confidently in technical discussions with banks, auditors, customer security teams and senior stakeholders.
This is not primarily a governance or documentation role. It requires someone who understands how the underlying technology actually works and can explain, troubleshoot and evidence it.
In one line
A senior Azure infrastructure professional who can operate the platform, prove that its controls work and confidently explains Valocity's technical architecture to banks, customers and auditors.
What makes this role different
Traditional infrastructure roles often focus primarily on operating technology
Traditional compliance roles often focus on controls, policies and evidence
This role needs to understand both, while also being capable of representing Valocity's architecture to sophisticated financial services customers
Major Responsibilities
- Azure infrastructure governance
Provide senior technical oversight of Valocity's Azure infrastructure and security posture.
Responsibilities include:
Review and maintain security and operational standards across Azure environments
Work closely with cloud and platform engineers to investigate and remediate infrastructure issues
Ensure infrastructure configuration remains aligned with Valocity's security, compliance and operational standards
Review infrastructure-as-code changes for operational, security and compliance implications.
Assist with complex infrastructure incidents and investigations
Key technology areas include:
AKS and container platforms
- Private cluster architecture
- Microsoft Entra ID integration
- Kubernetes RBAC
- Workload identity
- Network policies
- Ingress and application routing
- Container registry security
- Node pool hardening
- Cluster upgrade cadence
- Image scanning
- Defender for Containers
Azure networking
- Hub-and-spoke architecture
- VNets and subnets
- NSGs
- Private endpoints
- DNS
- Azure Firewall
- DDoS protection
- Routing and network segregation
Internet-facing services
- Azure Front Door
- Application Gateway
- Web Application Firewall policies
- TLS standards
- Certificate management
- Routing to AKS, App Services and other application components
Azure governance and security
- Defender for Cloud
- Azure Policy
- Management Groups
- Azure RBAC
- Privileged Identity Management
- Key Vault
- Diagnostic logging
- Azure Monitor
- Log Analytics
- Infrastructure security posture
- Customer technical architecture and assurance
Act as one of Valocity's senior technical representatives for customers in India.
Work directly with banks, financial institutions, customer technology teams and customer security teams to explain how Valocity's platform meets their technical requirements.
Responsibilities include:
Explain Valocity's Azure architecture and infrastructure to customer technology teams.
Represent Valocity in customer architecture, infrastructure, security and technical assurance discussions
Explain platform architecture including networking, identity, application security, APIs, data flow, encryption, monitoring and resilience
Support customer architecture and security reviews during onboarding and implementation
Respond to detailed technical questions from customer architecture, infrastructure, cloud, security and risk teams
Translate customer technical requirements into clear internal requirements
Work with Solution Architects, Engineering and IT Operations to assess requirements that require platform changes
Identify whether customer requirements can be met through existing controls, configuration changes or new engineering
Ensure technical commitments made to customers accurately reflect the capability of the Valocity platform
Escalate material architecture decisions to the appropriate Solution Architect, Head of IT Operations or CTO
Ensure customer-specific requirements remain aligned with Valocity's global architecture and operating model
- Compliance automation and Vanta
Own the operational administration, technical integrations and evidence quality of Valocity's compliance automation platform.
Valocity uses Vanta to support ISO/IEC 27001, SOC 2 and other security and assurance activities.
Responsibilities include:
Administer Vanta and its technical integrations
Ensure all relevant Azure environments and systems are correctly represented
Validate integrations rather than relying solely on a "connected" status
Reconcile assets and coverage against Azure source environments
Investigate failing or incomplete controls
Determine whether issues relate to configuration, evidence, integration, tooling or process
Assign remediation actions to appropriate owners
Track technical findings through to closure
Raise technical support issues with Vanta where appropriate
Maintain accurate evidence for technical controls
- Technical evidence and documentation
Maintain clear and traceable evidence showing how Valocity's infrastructure implements security and compliance requirements.
Responsibilities include:
Maintain technical control evidence maps
Link compliance controls to Azure configuration and evidence sources
Maintain evidence supporting ISO/IEC 27001 and SOC 2 controls
Maintain technical runbooks for key systems and integrations
Document technical architecture where required for assurance purposes
Ensure evidence can be reproduced rather than relying on one-off screenshots or manual explanations
Improve automation of evidence collection wherever practical
- Audit and customer assurance
Support Valocity's audit and customer assurance programme.
Responsibilities include:
Support ISO/IEC 27001 certification and surveillance audits
Support SOC 2 Type II assurance activities
Participate in bank and customer audits
Act as a technical point of contact for auditors and customer security teams
Walk auditors and customers through how technical controls operate within Azure
Respond to customer technical due diligence and security questionnaires
Provide accurate technical evidence to support responses
Work with internal owners to resolve audit findings
Track technical findings through root cause, ownership, remediation and closure
Support the use of Vanta Trust Center and questionnaire automation where appropriate
- Security, vulnerability and infrastructure risk
Support the management of technical infrastructure and security risk.
Responsibilities include:
Identify and document infrastructure and cloud security risks
Provide technical input into Valocity's information security risk register
Support risk treatment decisions with technical analysis
Track penetration testing and vulnerability findings
Coordinate remediation of infrastructure and AKS vulnerabilities
Review Defender for Cloud and other security findings
Monitor infrastructure security posture against agreed standards
Support secure configuration and hardening activities
Assist with root-cause analysis following security or infrastructure incidents
- Resilience, backup and disaster recovery
Support the technical resilience of Valocity's cloud platform.
Responsibilities include:
Review backup configuration and coverage
Coordinate disaster recovery exercises
Validate recovery procedures
Support testing of RTO and RPO commitments
Ensure recovery evidence is documented
Identify infrastructure dependencies that could affect resilience
Assist with improvements to platform availability and recoverability
Must Haves
Azure production experience
Strong hands-on experience operating production Microsoft Azure environments. Candidates should be comfortable working across:
- AKS
- Azure Firewall
- Azure Front Door
- Application Gateway and WAF
- VNets
- NSGs
- Private endpoints
- Azure DNS
- Azure Policy
- Defender for Cloud
- Entra ID
- Azure RBAC
- PIM
- Key Vault
- Azure Monitor
- Log Analytics
Kubernetes
Practical understanding of Kubernetes includes:
- RBAC
- Network policies
- Ingress
- Container registries
- Workload identity
- Cluster upgrades
- Container security
Infrastructure security and governance
Strong understanding of:
- Identity and access management
- Least privilege
- Privileged access
- Network segmentation
- Encryption
- Key management
- Logging and monitoring
- Infrastructure hardening
- Cloud security posture management
Customer-facing technical communication
Strong ability to communicate with:
- Bank technology teams
- Bank security teams
- Enterprise architects
- Cloud teams
- Auditors
- Risk teams
- Senior customer stakeholders
- Valocity senior leadership
Audit and assurance
Practical experience supporting one or more of:
- ISO/IEC 27001
- SOC 2
- Financial-services audits
- Customer security reviews
- Regulatory technology assurance
Candidates should understand:
- Technical versus procedural controls
- Automated versus manual evidence
- Control ownership
- Exceptions
- Remediation
- Evidence traceability
- Audit findings
APIs and automation
Comfortable working with:
- REST APIs
- JSON
- OAuth
- Service principals and managed identities
- Azure CLI
- PowerShell or Python
- API documentation
- Authentication troubleshooting
Experience, Education & Certifications
A BE, BTech or equivalent qualification in CS, IT
6-10 years of relevant experience across cloud infrastructure, infrastructure security, platform engineering or technical assurance
Strongly preferred
AZ-104 - Microsoft Azure Administrator
AZ-500 - Microsoft Azure Security Engineer