Talent Apply
Log in
All jobs
Z

Enterprise Systems Lead

ZS
Pune, India
On-site

About this role

Job title: Enterprise Systems Lead

ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS.

What you'll do: Enterprise Systems Lead in the Enterprise will..

  • Own the architecture of the ZS Azure estate end to end: tenant and management group hierarchy, subscription topology, landing zones, hub-and-spoke networking, VNet integration, private endpoints and Private DNS, firewalls and load balancing, resource group standards and environment separation for internal and client-facing workloads.
  • Define and enforce governance through Azure Policy, RBAC, tagging standards (client, project, cost center, environment), quota management and Azure Cost Management, so that cost allocation and chargeback across roughly 30 client tenants and growing is accurate and scalable.
  • Provide architecture and hands-on guidance for the Azure services ZS runs on: App Service, Azure Functions, Azure Kubernetes Service, Azure Container Apps, API Management, Azure Virtual Desktop, Storage, Key Vault and related services; advise data science and delivery teams on scalable, billable and secure designs such as per-client subscriptions for multi-tenant GenAI workloads.
  • Own Azure security posture with the SOC and Information Protection teams: Defender for Cloud recommendations, Key Vault secrets and certificate lifecycle, network exposure decisions (for example refusing public-facing VMs and offering compliant alternatives) and project-code mapping of resource groups with Finance.
  • Design and govern the enterprise API layer on Azure API Management: authentication and authorisation, network placement, policies, throttling and backend integrations to internal and client-facing services.
  • Deliver Azure infrastructure as code (Bicep or Terraform) through Azure DevOps: Repos, YAML Pipelines, service connections, environments with approvals, and Boards for work tracking. Move remaining portal-built resources into version-controlled, repeatable deployments.
  • Design and run the CI/CD pattern for platform and application infrastructure, including environment promotion (dev, sub-production, production), secrets handling through Key Vault, policy-as-code checks and drift detection.
  • Administer and govern the Azure DevOps organisation used by Enterprise Systems, including repositories, pipelines, service connections, permissions, security and integrations, and support tooling migrations that touch it, such as the Azure DevOps Boards to Jira migration.
  • Automate repetitive operations (certificate renewals, access provisioning, tagging remediation, cost reports) with pipelines, Azure Automation or PowerShell and Azure CLI, and measure the reduction in manual effort and tickets.
  • Support containerised application platforms and deployments on AKS and Azure Container Apps, including container registries, image and secret handling, ingress and private networking, and the CI/CD pipelines that ship to them.
  • Own Azure Monitor and Log Analytics alerting, including the Purview Information Protection (label downgrade) alert rules and Action Groups that create ServiceNow incidents for the SOC, and keep that pipeline reliable end to end.
  • Investigate gaps and failures using KQL, ingestion-latency analysis and event reconciliation; produce clear root-cause write-ups with findings, recommended changes and next steps for security and IT stakeholders.
  • Manage platform certificates and secrets (Azure Key Vault, RD Web and Azure Virtual Desktop SSL renewals), Function App networking and private connectivity so that internal applications remain reachable and secure.
  • Drive down recurring ticket volume from system-health issues by working with Cloud Operations and vendors on permanent fixes rather than repeated workarounds.
  • Provide the Azure foundation for ZS AI programs: Azure AI Foundry and Azure OpenAI resources, Azure AI Search indexes, Function Apps, API Management, private networking and Key Vault configuration that Copilot agents and internal knowledge agents depend on.
  • Support Microsoft 365 Copilot and Copilot Studio agent enablement from the platform side: Entra security groups that govern agent access, publishing Foundry agents to Teams, SharePoint and Microsoft Graph integrations for enterprise search and knowledge solutions, and the identity and network prerequisites raised by implementation partners.
  • Maintain working, hands-on familiarity with Power Platform (Power Apps, Power Automate, Dataverse), Power BI and Microsoft Fabric, including secure connectivity from those services to enterprise systems and the managed production environment behind the ZS Technical Assistance Center AI Agent, working with the IT Manager for Enterprise Systems who leads that area day to day.
  • Give practical guidance to project teams on hosting AI tools within ZS Azure infrastructure, including approved use of enterprise LLM providers, and route requests through the AI Assist Intake Form where appropriate.
  • Design and support identity and application security on Microsoft Entra ID: app registrations and enterprise applications, OAuth 2.0 and OpenID Connect, Microsoft Graph permissions, managed identities, RBAC and Privileged Identity Management, applying least privilege throughout.
  • Act as the decision point for access requests that carry risk, such as external client or contractor access to Azure and Microsoft 365 resources, steer teams toward compliant alternatives (contractor onboarding, sub-production access through virtual desktops) instead of exceptions, and partner with the Information Protection, SOC and Cloud Operations teams on private networking, secrets management, auditing, monitoring and control improvements.
  • Manage the working relationship with Microsoft and implementation partners: prepare and run vendor working sessions, raise and track Microsoft support cases, and escalate through partner leadership when delivery slips.
  • Translate technical detail into clear written updates for IT leadership, business sponsors and delivery teams, and keep status threads accurate and current.
  • Review solution architectures for client-project and internal workloads landing on ZS Azure and recommend approaches based on security, scalability, maintainability, performance, operational requirements and cost; coordinate dependencies with Cloud Operations, networking, database and security owners.
  • Act as the L3 escalation point for the ZS Technical Assistance Center and Cloud Operations on Azure, identity and Microsoft 365 platform issues, including out-of-hours coverage for critical incidents as agreed with the team.

What you’ll bring:

  • Bachelor's degree in Computer Science, Information Technology, Engineering or a related field, or equivalent practical experience.
  • 8 or more years in cloud or infrastructure engineering, including at least 4 years designing, building and running production Microsoft Azure environments. This is an Azure-first role: deep, current, hands-on Azure expertise is a must.
  • Full-stack Azure cloud depth: management groups, subscriptions and landing zones, Azure Policy, RBAC and Privileged Identity Management, tagging and Cost Management; networking (VNets, VNet integration, private endpoints, Private DNS, firewalls, load balancing); compute and application platforms (VMs, App Service, Azure Functions, AKS, Azure Container Apps, container registries, API Management, Azure Virtual Desktop); Storage, Key Vault, Azure Monitor and Log Analytics with strong KQL.
  • Infrastructure as code and DevOps capability is a must: Bicep or Terraform (ARM acceptable), Git, and Azure DevOps in depth, including Repos, YAML Pipelines, service connections, environments and approvals, and Boards. Proven track record of delivering Azure infrastructure through CI/CD rather than portal changes.
  • Strong Microsoft Entra ID and application security knowledge: app registrations and enterprise applications, O

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →