Owns ZS’s Azure enterprise architecture, governance, security, networking, infrastructure-as-code, CI/CD, identity, monitoring, and platform operations. Supports AKS, AI workloads, Microsoft 365, Power Platform, Azure DevOps, and ServiceNow integrations. The role provides technical guidance, investigates incidents, manages vendors, reviews solution architectures, automates operations, and serves as an L3 escalation point for Azure and Microsoft 365 issues.
ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you'll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS.
What you'll do: Enterprise Systems Lead in the Enterprise will..
What you'll bring:
How you'll grow:
Perks & Benefits:
At ZS, your growth matters. We offer a comprehensive total rewards package that supports your health and well-being, financial future, time away, and professional development. With robust skills-building programs, multiple career progression paths, internal mobility, and a deeply collaborative culture, you'll have the opportunity to do meaningful work, expand your capabilities, and thrive as part of a global community. For details on total rewards in India , visit ZS India office locations | Where we work | ZS .
Hybrid working model:
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems-the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you're eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com
What you'll do: Enterprise Systems Lead in the Enterprise will..
- Own the architecture of the ZS Azure estate end to end: tenant and management group hierarchy, subscription topology, landing zones, hub-and-spoke networking, VNet integration, private endpoints and Private DNS, firewalls and load balancing, resource group standards and environment separation for internal and client-facing workloads.
- Define and enforce governance through Azure Policy, RBAC, tagging standards (client, project, cost center, environment), quota management and Azure Cost Management, so that cost allocation and chargeback across roughly 30 client tenants and growing is accurate and scalable.
- Provide architecture and hands-on guidance for the Azure services ZS runs on: App Service, Azure Functions, Azure Kubernetes Service, Azure Container Apps, API Management, Azure Virtual Desktop, Storage, Key Vault and related services; advise data science and delivery teams on scalable, billable and secure designs such as per-client subscriptions for multi-tenant GenAI workloads.
- Own Azure security posture with the SOC and Information Protection teams: Defender for Cloud recommendations, Key Vault secrets and certificate lifecycle, network exposure decisions (for example refusing public-facing VMs and offering compliant alternatives) and project-code mapping of resource groups with Finance.
- Design and govern the enterprise API layer on Azure API Management: authentication and authorisation, network placement, policies, throttling and backend integrations to internal and client-facing services.
- Deliver Azure infrastructure as code (Bicep or Terraform) through Azure DevOps: Repos, YAML Pipelines, service connections, environments with approvals, and Boards for work tracking. Move remaining portal-built resources into version-controlled, repeatable deployments.
- Design and run the CI/CD pattern for platform and application infrastructure, including environment promotion (dev, sub-production, production), secrets handling through Key Vault, policy-as-code checks and drift detection.
- Administer and govern the Azure DevOps organisation used by Enterprise Systems, including repositories, pipelines, service connections, permissions, security and integrations, and support tooling migrations that touch it, such as the Azure DevOps Boards to Jira migration.
- Automate repetitive operations (certificate renewals, access provisioning, tagging remediation, cost reports) with pipelines, Azure Automation or PowerShell and Azure CLI, and measure the reduction in manual effort and tickets.
- Support containerised application platforms and deployments on AKS and Azure Container Apps, including container registries, image and secret handling, ingress and private networking, and the CI/CD pipelines that ship to them.
- Own Azure Monitor and Log Analytics alerting, including the Purview Information Protection (label downgrade) alert rules and Action Groups that create ServiceNow incidents for the SOC, and keep that pipeline reliable end to end.
- Investigate gaps and failures using KQL, ingestion-latency analysis and event reconciliation; produce clear root-cause write-ups with findings, recommended changes and next steps for security and IT stakeholders.
- Manage platform certificates and secrets (Azure Key Vault, RD Web and Azure Virtual Desktop SSL renewals), Function App networking and private connectivity so that internal applications remain reachable and secure.
- Drive down recurring ticket volume from system-health issues by working with Cloud Operations and vendors on permanent fixes rather than repeated workarounds.
- Provide the Azure foundation for ZS AI programs: Azure AI Foundry and Azure OpenAI resources, Azure AI Search indexes, Function Apps, API Management, private networking and Key Vault configuration that Copilot agents and internal knowledge agents depend on.
- Support Microsoft 365 Copilot and Copilot Studio agent enablement from the platform side: Entra security groups that govern agent access, publishing Foundry agents to Teams, SharePoint and Microsoft Graph integrations for enterprise search and knowledge solutions, and the identity and network prerequisites raised by implementation partners.
- Maintain working, hands-on familiarity with Power Platform (Power Apps, Power Automate, Dataverse), Power BI and Microsoft Fabric, including secure connectivity from those services to enterprise systems and the managed production environment behind the ZS Technical Assistance Center AI Agent, working with the IT Manager for Enterprise Systems who leads that area day to day.
- Give practical guidance to project teams on hosting AI tools within ZS Azure infrastructure, including approved use of enterprise LLM providers, and route requests through the AI Assist Intake Form where appropriate.
- Design and support identity and application security on Microsoft Entra ID: app registrations and enterprise applications, OAuth 2.0 and OpenID Connect, Microsoft Graph permissions, managed identities, RBAC and Privileged Identity Management, applying least privilege throughout.
- Act as the decision point for access requests that carry risk, such as external client or contractor access to Azure and Microsoft 365 resources, steer teams toward compliant alternatives (contractor onboarding, sub-production access through virtual desktops) instead of exceptions, and partner with the Information Protection, SOC and Cloud Operations teams on private networking, secrets management, auditing, monitoring and control improvements.
- Manage the working relationship with Microsoft and implementation partners: prepare and run vendor working sessions, raise and track Microsoft support cases, and escalate through partner leadership when delivery slips.
- Translate technical detail into clear written updates for IT leadership, business sponsors and delivery teams, and keep status threads accurate and current.
- Review solution architectures for client-project and internal workloads landing on ZS Azure and recommend approaches based on security, scalability, maintainability, performance, operational requirements and cost; coordinate dependencies with Cloud Operations, networking, database and security owners.
- Act as the L3 escalation point for the ZS Technical Assistance Center and Cloud Operations on Azure, identity and Microsoft 365 platform issues, including out-of-hours coverage for critical incidents as agreed with the team.
What you'll bring:
- Bachelor's degree in Computer Science, Information Technology, Engineering or a related field, or equivalent practical experience.
- 8 or more years in cloud or infrastructure engineering, including at least 4 years designing, building and running production Microsoft Azure environments. This is an Azure-first role: deep, current, hands-on Azure expertise is a must.
- Full-stack Azure cloud depth: management groups, subscriptions and landing zones, Azure Policy, RBAC and Privileged Identity Management, tagging and Cost Management; networking (VNets, VNet integration, private endpoints, Private DNS, firewalls, load balancing); compute and application platforms (VMs, App Service, Azure Functions, AKS, Azure Container Apps, container registries, API Management, Azure Virtual Desktop); Storage, Key Vault, Azure Monitor and Log Analytics with strong KQL.
- Infrastructure as code and DevOps capability is a must: Bicep or Terraform (ARM acceptable), Git, and Azure DevOps in depth, including Repos, YAML Pipelines, service connections, environments and approvals, and Boards. Proven track record of delivering Azure infrastructure through CI/CD rather than portal changes.
- Strong Microsoft Entra ID and application security knowledge: app registrations and enterprise applications, OAuth 2.0 and OpenID Connect, Microsoft Graph and REST APIs, managed identities, service principals, security groups, conditional access concepts and guest or external identity handling; working knowledge of Microsoft 365, SharePoint and Purview Information Protection sensitivity labels.
- Experience integrating Azure Monitor alerting with ServiceNow incident creation and working within ServiceNow ITSM processes (incident, change, request).
- Hands-on familiarity with Power Platform (Power Apps, Power Automate, Dataverse), Power BI and Microsoft Fabric, and with Microsoft Copilot and agent platforms (Copilot Studio or Agent Builder, Azure AI Foundry, Azure OpenAI, Azure AI Search) as they run on Azure. Working knowledge with real hands-on exposure is expected; this is not the primary specialism.
- Strong troubleshooting across multiple technology domains (application, infrastructure, networking, identity, database) with the ability to run root-cause investigations and write them up clearly, manage Microsoft and partner vendors against commitments, and advise senior stakeholders in excellent written and spoken English, pushing back constructively on risky requests.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
How you'll grow:
- Cross-functional skills development & custom learning pathways
- Milestone training programs aligned to career progression opportunities
- Internal mobility paths that empower growth via s-curves, individual contribution and role expansions
Perks & Benefits:
At ZS, your growth matters. We offer a comprehensive total rewards package that supports your health and well-being, financial future, time away, and professional development. With robust skills-building programs, multiple career progression paths, internal mobility, and a deeply collaborative culture, you'll have the opportunity to do meaningful work, expand your capabilities, and thrive as part of a global community. For details on total rewards in India , visit ZS India office locations | Where we work | ZS .
Hybrid working model:
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems-the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you're eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com
Similar Jobs at ZS
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Manages software asset and license lifecycles, including software requests, evaluations, onboarding, provisioning, renewals, reclamation, audits, compliance reporting, and cost optimization. Partners with Procurement, Security, Legal, Infrastructure, and vendors to assess risks, licensing, privacy, contracts, and deployment readiness. Maintains SAM/ITAM records, supports users with software-related issues, recommends alternatives, and improves governance and automation processes.
Top Skills:
It Asset Management SystemsMicrosoft 365ExcelSaas LicensingServicenow Sam Pro
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Support global performance review cycles by executing performance enablement processes, leading workstreams, analyzing performance data, tracking KPIs, and producing leadership insights. Maintain HR performance systems, collaborate with HR business partners and leaders, support performance improvement plans, guide stakeholders on best practices, and help develop transparent communications. The role also contributes to process enhancements and continuous improvement across a global, cross-functional organization.
Top Skills:
HrisExcelPower BISap Successfactors
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Design and implement production-grade AI and machine learning solutions, including scalable GenAI applications, RAG pipelines, ML platforms, data pipelines, and distributed cloud systems. Collaborate with architects and client-facing teams, write tested and maintainable code, conduct technical research and proofs of concept, participate in Agile delivery, troubleshoot production issues, review code, estimate work, and mentor engineers.
Top Skills:
Amazon SagemakerApache KafkaSparkAWSAws KinesisAzureCi/CdDistributed ComputingGitGoogle Cloud PlatformHadoopHiveJavaKubeflowLangchainLlamaindexMlflowMonitoring ToolsPysparkPythonRabbitMQRagScalaVersion Control
What you need to know about the Kolkata Tech Scene
When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

