Manager - Cloud Operations Lead

SUN PHARMA · Mumbai Metropolitan Region

  • Experience6–10 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelsenior
  • Posted11 Sept 2026

About SUN PHARMA

SUN PHARMA is hiring in Mumbai Metropolitan Region in pharma biotech. This role looks for around 6+ years of experience.

Skills

  • AWS
  • Azure
  • Terraform
  • AWS CloudWatch
  • Grafana
  • Prometheus
  • Kubernetes
  • CI/CD
  • GitHub Actions
  • GitLab CI
  • Jenkins
  • AWS CodePipeline
  • PowerShell
  • Bash
  • Python
  • Cloud networking
  • DevSecOps
  • SAST
  • DAST
  • SCA
  • CSPM
  • AWS Cost Explorer
  • ITIL

The role

A cloud operations lead at a pharmaceutical company operates AWS and Azure environments, secures CI/CD pipelines through DevSecOps, and manages cloud security remediation. Terraform and Kubernetes support infrastructure automation and platform reliability across production services.

Full job description

Job Summary

At Sun Pharma, we commit to helping you “Create your own sunshine”— by fostering an environment where you grow at every step, take charge of your journey and thrive in a supportive community.

Are You Ready to Create Your Own Sunshine?

As you enter the Sun Pharma world, you’ll find yourself becoming ‘Better every day’ through continuous progress. Exhibit self-drive as you ‘Take charge’ and lead with confidence. Additionally, demonstrate a collaborative spirit, knowing that we ‘Thrive together’ and support each other’s journeys.”

Job Summary:

We are looking for a hands-on Cloud Operations Lead to run the day-to-day operations of our AWS-primary cloud estate (with a fast-growing Azure footprint) and to own and drive DevSecOps across the organisation. Reporting to the Cloud Architect within the Cloud CoE, the role spans three areas: cloud operations (about half the role), cloud-security remediation (about a quarter), and DevSecOps ownership, adoption and governance (about a quarter). In practice that means running the reliability and cost-efficiency of the cloud estate, closing security findings and hardening the environment, and owning the DevSecOps toolchain while driving its adoption and governance across delivery teams. It is a deeply technical, execution-focused role for an engineer equally comfortable in infrastructure-as-code, pipeline security, incident response, and directing a managed-services partner pool.

On the operations side, you will operate and continuously improve the landing zones, networking, and platform services designed by the Cloud Architect — primarily on AWS, and increasingly on Azure as that estate grows. You will run monitoring and observability, drive incident, problem, and change management to resolution, and enforce operational guardrails, patching, and backup/DR routines across environments. You will act as the operational owner of the NTT DATA cloud and DevSecOps managed-services pool, holding the partner to SLAs and quality standards.

On the security and DevSecOps side, you will remediate cloud-security findings and harden the estate, and own the DevSecOps toolchain and practice end-to-end — building and maintaining secure CI/CD pipelines, integrating SAST, DAST, SCA, secrets-scanning, and image/container security into the delivery flow, and shifting security left. You will define secure-pipeline standards, onboard and enable delivery teams, and actively drive DevSecOps adoption and maturity across the organisation, in line with CISO requirements. Across both halves of the role you will maintain infrastructure-as-code, automate operational toil, support cloud cost/FinOps optimisation, and work within the architecture standards and guardrails set by the Cloud Architect and the Enterprise Architecture Review Board (EARB), escalating design changes rather than making them unilaterally.

Areas Of Responsibility

Area of Responsibility

Responsibilities

Cloud Operations & Reliability (~50%)

Operate and maintain the AWS-primary cloud estate (and growing Azure footprint) for reliability and availability against agreed SLOs.

Own monitoring, alerting, and observability across infrastructure and platform services.

Drive incident, problem, and change management to timely resolution, including on-call/major-incident response.

Operate landing zones, networking, and platform services within the guardrails set by the Cloud Architect.

Maintain infrastructure-as-code (Terraform primary; CloudFormation / Bicep / ARM) to provision and change environments consistently.

Automation & Platform Engineering

Automate operational toil across provisioning, monitoring, and scaling.

Build and maintain CI/CD pipelines for infrastructure and platform deployments in collaboration with DevOps/DevSecOps.

Perform operational debugging, root-cause analysis, and performance tuning; document runbooks and share operational knowledge.

Operate backup, restore, and disaster-recovery routines; verify recoverability and data availability.

Implement and maintain configuration management and environment consistency across dev, test, and production.

Maintain platform health across integrated components and dependencies.

Track operational metrics and keep stakeholders informed of service health and incidents.

Cloud Security Remediation & Hardening (~25%)

Implement and operate cloud security and DevSecOps controls in line with CISO requirements.

Own the cloud-security remediation backlog: triage findings from CSPM, Security Hub / Defender, and CISO reviews, and drive them to closure within SLA.

Apply patching, hardening, and encryption/key-management routines across the estate.

Remediate vulnerabilities and misconfigurations across accounts/subscriptions; harden baselines and prevent regression.

Continuously monitor cloud posture (CSPM) and report remediation status, risk burn-down, and exceptions to the CISO office.

Ensure controls and remediation evidence are audit-ready (GxP, GDPR, HIPAA); support security reviews and audits.

Scalability and Performance

Optimise platform performance, scaling, and resource utilisation against SLOs.

Perform capacity planning and autoscaling configuration for cloud workloads.

Identify and resolve operational bottlenecks; right-size resources for cost and performance.

DevSecOps Ownership, Adoption & Governance (~25%)

Own the DevSecOps toolchain end-to-end and integrate security scanning (SAST, DAST, SCA, secrets, IaC scanning) into CI/CD pipelines.

Embed image/container and Kubernetes security (registry scanning, admission controls, policy-as-code) into the delivery flow.

Define secure-pipeline standards and reusable templates; maintain release hygiene for continuous, safe delivery.

Drive DevSecOps adoption across delivery teams: onboard projects, run enablement, and track maturity uptake.

Establish and report DevSecOps KPIs (pipeline coverage, scan pass rates, mean-time-to-remediate, adoption %).

Manage secrets, keys, and certificates and enforce supply-chain security (SBOM, dependency and artifact integrity).

Own DevSecOps governance: define policy, standards, and gates in coordination with the CISO and EARB, and enforce them across teams.

Continuous Improvement & Vendor Oversight

Own the NTT DATA cloud managed-services pool: assign work, hold to SLAs, and review quality.

Track operational best practices and drive continuous improvement of run processes.

Propose and implement automation and tooling improvements to reduce toil and cost.

Pilot operational tooling (monitoring, FinOps, automation) with the Cloud Architect’s endorsement.

Feed operational insights back into architecture and standards via the Cloud Architect / EARB.

Stakeholder Collaboration, Communication and Reporting

Interface with application, infrastructure, and business teams to understand operational needs.

Coordinate with external partners, vendors, and technology providers on operational delivery.

Coordinate cross-functional teams during incidents, changes, and releases.

Ensure operations meet agreed service levels and business expectations.

Clearly communicate service health, incidents, and root causes to technical and non-technical stakeholders.

Provide regular operational reporting (availability, incidents, cost) to the Cloud Architect and management.

Operational Delivery & Run Management

Own operational delivery of the cloud run function, including SLAs and service reviews.

Ensure operational commitments are met within agreed timelines and budget.

Manage the managed-services pool and schedules for operational execution.

Travel Estimate

Job Scope

Internal Interactions (within the organization)

Function Heads, business vertical leads/end users , procurement , SUN Infrastructure Teams (Network, Server, Database, Security), vendor payment, commercial, SAP support & other as necessary

External Interactions (outside the organization)

OEM, SI’s others partners/vendors/service providers in the space as applicable

Geographical Scope

Global

Financial Accountability (cost/revenue with exclusive authority)

Cost Management: Execute cloud cost/FinOps optimisation: right-sizing, reserved-capacity actions, and waste elimination. Monitor daily cloud expenditure and enforce tagging, budgets, and lifecycle policies on storage and compute. Provide regular cost analysis and anomaly alerts to identify savings, escalating structural decisions to the Cloud Architect. Budgeting and Forecasting: Assist in preparing and tracking the cloud services run budget. Forecast run-rate cloud costs and flag variances early. Ensure operational cloud spend stays aligned to approved budgets. Vendor and Contract Management: Manage day-to-day relationship and tickets with cloud service providers. Support commercial reviews with usage data; recommend cost actions (final negotiation owned by the Cloud Architect / management).

Track consumption against contractual commitments and flag over/under-utilisation.

Job Requirements

Educational Qualification

Specific Certification

Mandatory Certifications (at least 01 in each group)

Cloud Certification (one or more of the following): AWS Certified SysOps Administrator – Associate AWS Certified Solutions Architect – Associate (Azure Administrator AZ-104 a plus, given the growing Azure estate) Certified Kubernetes Administrator (CKA) Security Certification (one or more of the following):

AWS Certified Security – Specialty (or CCSP) DevSecOps / pipeline security credential — e.g. GitLab Security Specialist, GitHub Advanced Security, or Certified DevSecOps Professional (CDP) DevOps Certification (one or more of the following):

AWS Certified DevOps Engineer – Professional HashiCorp Certified: Terraform Associate Microsoft Certified: DevOps Engineer Expert (AZ-400) — value-add for Azure

Optional Certifications (any one of more of below will be a value add))

ITIL 4 Foundation (service operations) FinOps Certified Practitioner

Experience

6–10 years in cloud operations / cloud engineering, running production cloud environments (AWS primary; Azure growing). Blend of experience across the three areas of this role: cloud operations (~50% — monitoring, incident/change, IaC, vendor oversight), cloud-security remediation (~25% — CSPM/vulnerability closure, hardening, CISO-aligned), and DevSecOps (~25% — CI/CD security, toolchain ownership, adoption and governance).

Skill (Functional & Behavioural):

Functional Skills

Cloud Operations: Hands-on expertise operating AWS (primary) and Azure (growing) — landing zones, networking, compute, storage, and platform services in production. Infrastructure as Code (IaC): Strong hands-on skills with Terraform (primary) and CloudFormation (Bicep / ARM a plus) to provision and change infrastructure. Monitoring & Observability: Proficiency with AWS CloudWatch (Azure Monitor / Log Analytics a plus), Grafana/Prometheus or equivalent; alerting and SLO management. Incident, Problem & Change Management: Practical ITIL-aligned operations, including on-call and major-incident handling and RCA. DevOps & Automation: CI/CD pipelines (Azure DevOps / GitHub Actions / GitLab CI), scripting (PowerShell / Bash / Python) to automate operational tasks. Containers & Networking: Working knowledge of Kubernetes/AKS and cloud networking (VNet/VPC, subnets, VPN, load balancing, DNS, firewalls). DevSecOps (~25%): Owning CI/CD pipelines (GitLab CI / GitHub Actions / Jenkins / AWS CodePipeline) with integrated SAST, DAST, SCA, secrets and IaC scanning; container/K8s security; secure-pipeline standards; and driving org-wide adoption. Plus cloud security operations — patching, hardening, key management, and CSPM remediation under CISO guidance. Cost / FinOps & Vendor Oversight: AWS Cost Explorer / Budgets (Azure Cost Management a plus), tagging/lifecycle governance; directing a managed-services (e.g., NTT DATA) pool to SLAs. Behavioural Skills

Analytical Thinking: Strong problem-solving skills with the ability to analyse complex technical issues and make data-driven decisions. Communication: Excellent verbal and written communication skills to explain technical concepts to non-technical stakeholders. Collaboration and Teamwork: Proven ability to work effectively in cross-functional teams and collaborate with various stakeholders. Adaptability: Quick learner who can adapt to new technologies and methodologies, and adjust to changing project requirements. Ownership & Vendor Management: Strong operational ownership and the ability to direct and hold a managed-services partner to account (rather than line-managing a Sun team). Attention to Detail: High level of accuracy and commitment to maintaining high standards in technical implementations. Customer Focus: Understanding of business requirements and dedication to providing excellent support and service to internal and external customers.

Your Success Matters to Us

At Sun Pharma, your success and well-being are our top priorities! We provide robust benefits and opportunities to foster personal and professional growth. Join us at Sun Pharma, where every day is an opportunity to grow, collaborate, and make a lasting impact. Let’s create a brighter future together!

Disclaimer: The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees as assigned to this job. Nothing herein shall preclude the employer from changing these duties from time to time and assigning comparable duties or other duties commensurate with the experience and background of the incumbent(s).