{"id":1222678,"url":"https://alion.io/job/sun-pharma-manager-cloud-operations-lead","title":"Manager - Cloud Operations Lead","company":{"id":1808960,"name":"Sun Pharma","domain":"sunpharma.com","url":"https://alion.io/company/sun-pharma","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Mumbai, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":17500,"max_usd":51000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":12},"experience_years_min":6,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon CloudWatch","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure AKS","optional":false},{"name":"Azure DevOps","optional":false},{"name":"Bicep","optional":false},{"name":"CI/CD","optional":false},{"name":"CloudFormation","optional":false},{"name":"Configuration Management","optional":false},{"name":"DNS","optional":false},{"name":"FinOps","optional":false},{"name":"GDPR","optional":false},{"name":"GitHub","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab","optional":false},{"name":"GitLab CI","optional":false},{"name":"Grafana","optional":false},{"name":"HIPAA","optional":false},{"name":"ITIL","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"Platform Engineering","optional":false},{"name":"PowerShell","optional":false},{"name":"Prometheus","optional":false},{"name":"Python","optional":false},{"name":"SBOM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Terraform","optional":false},{"name":"VPN","optional":false}],"status":"live","first_seen_at":"2026-09-12T02:00:00Z","employer_posted_date":"2026-09-12","last_verified_at":"2026-09-30T19:56:44Z","board_verified":true,"closed_at":null,"days_open":19,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":19},"description":"Job Summary\n\nAt Sun Pharma, we commit to helping you “Create your own sunshine ”- by fostering an environment where you grow at every step, take charge of your journey and thrive in a supportive community.\nAre You Ready to Create Your Own Sunshine?\nAs you enter the Sun Pharma world, you’ll find yourself becoming ‘Better every day’ through continuous progress. Exhibit self-drive as you ‘Take charge’ and lead with confidence. Additionally, demonstrate a collaborative spirit, knowing that we ‘Thrive together’ and support each other’s journeys.”\nJob Summary:\nWe are looking for a hands-on Cloud Operations Lead to run the day-to-day operations of our AWS-primary cloud estate (with a fast-growing Azure footprint) and to own and drive DevSecOps across the organisation. Reporting to the Cloud Architect within the Cloud CoE, the role spans three areas: cloud operations (about half the role), cloud-security remediation (about a quarter), and DevSecOps ownership, adoption and governance (about a quarter). In practice that means running the reliability and cost-efficiency of the cloud estate, closing security findings and hardening the environment, and owning the DevSecOps toolchain while driving its adoption and governance across delivery teams. It is a deeply technical, execution-focused role for an engineer equally comfortable in infrastructure-as-code, pipeline security, incident response, and directing a managed-services partner pool.\nOn the operations side, you will operate and continuously improve the landing zones, networking, and platform services designed by the Cloud Architect - primarily on AWS, and increasingly on Azure as that estate grows. You will run monitoring and observability, drive incident, problem, and change management to resolution, and enforce operational guardrails, patching, and backup/DR routines across environments. You will act as the operational owner of the NTT DATA cloud and DevSecOps managed-services pool, holding the partner to SLAs and quality standards.\nOn the security and DevSecOps side, you will remediate cloud-security findings and harden the estate, and own the DevSecOps toolchain and practice end-to-end - building and maintaining secure CI/CD pipelines, integrating SAST, DAST, SCA, secrets-scanning, and image/container security into the delivery flow, and shifting security left. You will define secure-pipeline standards, onboard and enable delivery teams, and actively drive DevSecOps adoption and maturity across the organisation, in line with CISO requirements. Across both halves of the role you will maintain infrastructure-as-code, automate operational toil, support cloud cost/FinOps optimisation, and work within the architecture standards and guardrails set by the Cloud Architect and the Enterprise Architecture Review Board (EARB), escalating design changes rather than making them unilaterally.\n\nAreas Of Responsibility\n\nArea of Responsibility\n\nResponsibilities\n\nCloud Operations & Reliability (~50%)\n\nOperate and maintain the AWS-primary cloud estate (and growing Azure footprint) for reliability and availability against agreed SLOs.\n\nOwn monitoring, alerting, and observability across infrastructure and platform services.\n\nDrive incident, problem, and change management to timely resolution, including on-call/major-incident response.\n\nOperate landing zones, networking, and platform services within the guardrails set by the Cloud Architect.\n\nMaintain infrastructure-as-code (Terraform primary; CloudFormation / Bicep / ARM) to provision and change environments consistently.\n\nAutomation & Platform Engineering\n\nAutomate operational toil across provisioning, monitoring, and scaling.\n\nBuild and maintain CI/CD pipelines for infrastructure and platform deployments in collaboration with DevOps/DevSecOps.\n\nPerform operational debugging, root-cause analysis, and performance tuning; document runbooks and share operational knowledge.\n\nOperate backup, restore, and disaster-recovery routines; verify recoverability and data availability.\n\nImplement and maintain configuration management and environment consistency across dev, test, and production.\n\nMaintain platform health across integrated components and dependencies.\n\nTrack operational metrics and keep stakeholders informed of service health and incidents.\n\nCloud Security Remediation & Hardening (~25%)\n\nImplement and operate cloud security and DevSecOps controls in line with CISO requirements.\n\nOwn the cloud-security remediation backlog: triage findings from CSPM, Security Hub / Defender, and CISO reviews, and drive them to closure within SLA.\n\nApply patching, hardening, and encryption/key-management routines across the estate.\n\nRemediate vulnerabilities and misconfigurations across accounts/subscriptions; harden baselines and prevent regression.\n\nContinuously monitor cloud posture (CSPM) and report remediation status, risk burn-down, and exceptions to the CISO office.\n\nEnsure controls and remediation evidence are audit-ready (GxP, GDPR, HIPAA); support security reviews and audits.\n\nScalability and Performance\n\nOptimise platform performance, scaling, and resource utilisation against SLOs.\n\nPerform capacity planning and autoscaling configuration for cloud workloads.\n\nIdentify and resolve operational bottlenecks; right-size resources for cost and performance.\n\nDevSecOps Ownership, Adoption & Governance (~25%)\n\nOwn the DevSecOps toolchain end-to-end and integrate security scanning (SAST, DAST, SCA, secrets, IaC scanning) into CI/CD pipelines.\n\nEmbed image/container and Kubernetes security (registry scanning, admission controls, policy-as-code) into the delivery flow.\n\nDefine secure-pipeline standards and reusable templates; maintain release hygiene for continuous, safe delivery.\n\nDrive DevSecOps adoption across delivery teams: onboard projects, run enablement, and track maturity uptake.\n\nEstablish and report DevSecOps KPIs (pipeline coverage, scan pass rates, mean-time-to-remediate, adoption %).\n\nManage secrets, keys, and certificates and enforce supply-chain security (SBOM, dependency and artifact integrity).\n\nOwn DevSecOps governance: define policy, standards, and gates in coordination with the CISO and EARB, and enforce them across teams.\n\nContinuous Improvement & Vendor Oversight\n\nOwn the NTT DATA cloud managed-services pool: assign work, hold to SLAs, and review quality.\n\nTrack operational best practices and drive continuous improvement of run processes.\n\nPropose and implement automation and tooling improvements to reduce toil and cost.\n\nPilot operational tooling (monitoring, FinOps, automation) with the Cloud Architect’s endorsement.\n\nFeed operational insights back into architecture and standards via the Cloud Architect / EARB.\n\nStakeholder Collaboration, Communication and Reporting\n\nInterface with application, infrastructure, and business teams to understand operational needs.\n\nCoordinate with external partners, vendors, and technology providers on operational delivery.\n\nCoordinate cross-functional teams during incidents, changes, and releases.\n\nEnsure operations meet agreed service levels and business expectations.\n\nClearly communicate service health, incidents, and root causes to technical and non-technical stakeholders.\n\nProvide regular operational reporting (availability, incidents, cost) to the Cloud Architect and management.\n\nOperational Delivery & Run Management\n\nOwn operational delivery of the cloud run function, including SLAs and service reviews.\n\nEnsure operational commitments are met within agreed timelines and budget.\n\nManage the managed-services pool and schedules for operational execution.\n\nTravel Estimate\n\nJob Scope\n\nInternal Interactions (within the organization)\n\nFunction Heads, business vertical leads/end users , procurement , SUN Infrastructure Teams (Network, Server, Database, Security), vendor payment, commercial, SAP support & other as necessary\n\nExternal Interactions (outside the organization)\n\nOEM, SI’s others partners/vendors/service providers in the space as applicable\n\nGeographical Scope\n\nGlobal\n\nFinancial Accountability (cost/revenue with exclusive authority)\n\nCost Management:\nExecute cloud cost/FinOps optimisation: right-sizing, reserved-capacity actions, and waste elimination.\nMonitor daily cloud expenditure and enforce tagging, budgets, and lifecycle policies on storage and compute.\nProvide regular cost analysis and anomaly alerts to identify savings, escalating structural decisions to the Cloud Architect.\nBudgeting and Forecasting:\nAssist in preparing and tracking the cloud services run budget.\nForecast run-rate cloud costs and flag variances early.\nEnsure operational cloud spend stays aligned to approved budgets.\nVendor and Contract Management:\nManage day-to-day relationship and tickets with cloud service providers.\nSupport commercial reviews with usage data; recommend cost actions (final negotiation owned by the Cloud Architect / management).\nTrack consumption against contractual commitments and flag over/under-utilisation.\n\nJob Requirements\n\nEducational Qualification\n\nSpecific Certification\n\nMandatory Certifications (at least 01 in each group)\nCloud Certification (one or more of the following):\nAWS Certified SysOps Administrator - Associate\nAWS Certified Solutions Architect - Associate (Azure Administrator AZ-104 a plus, given the growing Azure estate)\nCertified Kubernetes Administrator (CKA)\n\nSecurity Certification (one or more of the following):\nAWS Certified Security - Specialty (or CCSP)\nDevSecOps / pipeline security credential - e.g. GitLab Security Specialist, GitHub Advanced Security, or Certified DevSecOps Professional (CDP)\n\nDevOps Certification (one or more of the following):\nAWS Certified DevOps Engineer - Professional\nHashiCorp Certified: Terraform Associate\nMicrosoft Certified: DevOps Engineer Expert (AZ-400) - value-add for Azure\n\nOptional Certifications (any one of more of below will be a value add))\nITIL 4 Foundation (service operations)\nFinOps Certified Practitioner\n\nExperience\n\n6-10 years in cloud operations / cloud engineering, running production cloud environments (AWS primary; Azure growing). Blend of experience across the three areas of this role: cloud operations (~50% - monitoring, incident/change, IaC, vendor oversight), cloud-security remediation (~25% - CSPM/vulnerability closure, hardening, CISO-aligned), and DevSecOps (~25% - CI/CD security, toolchain ownership, adoption and governance).\n\n Skill (Functional & Behavioural): Functional Skills\n\nCloud Operations: Hands-on expertise operating AWS (primary) and Azure (growing) - landing zones, networking, compute, storage, and platform services in production.\nInfrastructure as Code (IaC): Strong hands-on skills with Terraform (primary) and CloudFormation (Bicep / ARM a plus) to provision and change infrastructure.\nMonitoring & Observability: Proficiency with AWS CloudWatch (Azure Monitor / Log Analytics a plus), Grafana/Prometheus or equivalent; alerting and SLO management.\nIncident, Problem & Change Management: Practical ITIL-aligned operations, including on-call and major-incident handling and RCA.\nDevOps & Automation: CI/CD pipelines (Azure DevOps / GitHub Actions / GitLab CI), scripting (PowerShell / Bash / Python) to automate operational tasks.\nContainers & Networking: Working knowledge of Kubernetes/AKS and cloud networking (VNet/VPC, subnets, VPN, load balancing, DNS, firewalls).\nDevSecOps (~25%): Owning CI/CD pipelines (GitLab CI / GitHub Actions / Jenkins / AWS CodePipeline) with integrated SAST, DAST, SCA, secrets and IaC scanning; container/K8s security; secure-pipeline standards; and driving org-wide adoption. Plus cloud security operations - patching, hardening, key management, and CSPM remediation under CISO guidance.\nCost / FinOps & Vendor Oversight: AWS Cost Explorer / Budgets (Azure Cost Management a plus), tagging/lifecycle governance; directing a managed-services (e.g., NTT DATA) pool to SLAs.\n\nBehavioural Skills\nAnalytical Thinking: Strong problem-solving skills with the abili...","description_format":"text","description_chars":13771,"description_truncated":true,"requirements":{"experience_years_min":6,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Prescription Drugs","Generic Drugs","OTC & Consumer Health Products","APIs & Drug Manufacturing"],"lifecycle":[{"event":"open","at":"2026-09-25T12:42:34Z"}],"liveness":{"score":74,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.825,"p_room":0.9,"age_days":18,"expected_fill_days":31,"reasons":["conf:5","velocity","win:mid","comp:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/sun-pharma-manager-cloud-operations-lead","json_url":"https://alion.io/job/sun-pharma-manager-cloud-operations-lead.json","meta":{"generated_at":"2026-10-01T02:00:15Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1599,"day_limit":5000,"remaining_today":3401,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}