Security & Compliance: Hands-on experience implementing and operating Microsoft Defender for Cloud, Microsoft Sentinel, Azure Key Vault, RBAC, Azure Policy, and Blueprints in an enterprise environment; must be able to diagnose a token acquisition failure across multiple services without guessing, with demonstrated fluency in OAuth 2.0 / OIDC flows, managed identities, service principals, and certificate lifecycle management; proven experience operating CSPM platforms and building infrastructure that satisfies auditors under financial regulatory frameworks (PCI-DSS, SOX, GLBA, FFIEC, SOC-2). Hybrid Networking: Deep, production-grade experience with Azure ExpressRoute, VPN Gateways, Azure DNS (including private DNS zones and conditional forwarding), Private Link and Private Endpoints, NAT Gateway, and integration with on-premises network infrastructure; must be able to trace a request from a containerized workload through segmented networks across multiple DNS resolution layers and explain exactly where it broke.