Multi-Cloud Administrator
Client & Project
EssilorLuxottica SA, France
Duration & Role
1 year 2 months - Current, Multi-Cloud Administrator
Environment
Microsoft Azure, Amazon Web Services and Google Cloud Platform
Project Description
EssilorLuxottica SA is an Italian-French vertically integrated multinational corporation based in Paris. The Company designs, produces and markets ophthalmic lenses, optical equipment, prescription glasses and sunglasses. The company has a portfolio of proprietary and licensed brands including Ray-Ban, Oakley, Michael Kors, Varilux, Crizal, Transitions and LensCrafters. EssilorLuxottica is currently a global leader in the design, production and sale of ophthalmic lenses and frames.
Project Activities
- Setup HUB-Spoke Topology for on Microsoft Azure to integrate multiple project related environments.
- Secured network traffic to prevent communication between Azure Resource Groups through the HUB Firewall Policy.
- Configured multiple High Availability site-to-site BGP IPsec tunnels including Phase 1 and Phase 2 specifications between Azure, AWS and GCP for secured encrypted network traffic communication between VPC's.
- Setup Azure Spoke Resource group Virtual Machines with external IP traffic routing through HUB Firewall Resource group.
- Delegated Access Control(IAM) for individual users to specified resource groups on Azure.
- Configured NAT Masking for inbound traffic through IPsec tunnels to prevent overlapping CIDR conflicts on Azure Virtual Network Gateway.
- Configured Azure Point-to-site sessions to enable VPN Profiles to connect with the integrated Virtual Networks and associated resources.
- Manage AWS IAM Users custom policies and enabled MFA Authentication for all logged in users and 60 days password reset policy.
- Configured AWS Lambda Functions to automate the daily email notifications advising the team members about the users with MFA disabled and user’s access limited to force the users to enable MFA.
- Configured Azure automated Start-Stop schedule using Azure Logic Apps.
- Coordinated with all Organization GitHub users to update their user profile details.
- Project Infrastructure Security Report 95% - Single handedly architect the project environment to migrate resources from AWS and third-party Hosting vendor to Azure. Information Security team scan for Vulnerability and gave the environment score as A+ at 95%.
- Cloudwatch monitoring for AWS EC2. Custom Dashboards for Azure resource monitoring and Kubernetes Dashboard of AWS EKS.
- Coordinated with required Team Leads to upgrade existing Kubernetes Infrastructure to the latest versions for EKS, AKS and GKE and performed the necessary pre-deployment and post deployments validations.
- Setup Azure Load Balancer with multiple backend pools to relay network traffic back to IIS VM with multiple private IP's configured on the VM NIC.
- Setup Azure Front Door and Azure Load Balancer for Production Tableau VM on Azure.
- Migrate AWS EC2 instances to Azure through Azure Migrate Service.
- Migrate Route 53 Domains to GoDaddy.
- Manage Azure Portal User creation and role assignment for various resource groups and Subscription level permissions. Also created VM users and attached required permissions through the Azure Portal via command line.
- Setup automated EC2 snapshots on AWS using AWS Lifecycle Manager and automated VM snapshots for Azure using Recovery Services Vault.
- Setup SFTP for Azure Storage accounts to backup and restore VM files between Virtual Machines on multiple resource groups.
- Provide monthly reports to include daily outlined tasks and related ticket or change order ID's.
- Provide 24/7 support for all critical issues.