

Results-driven Cloud Network and Security Engineer with 8+ years of experience architecting, deploying, and securing scalable cloud infrastructures across AWS and Azure. Demonstrates deep expertise in cloud networking and security, leveraging a broad range of native services and tools across both platforms.
Proficient in designing secure, highly available, and automated cloud environments using Azure DevOps (Repository, Pipelines, Artifacts), Terraform, and PowerShell-based automation. Adept at building Infrastructure as Code (IAC) solutions that streamline deployments, enforce governance, and improve operational efficiency.
Collaborates effectively with cross-functional teams to optimize cloud network architectures and implement security best practices in multi-cloud environments. Brings a strong hybrid background, spanning cloud-based networking and traditional data center networks, enabling seamless support for both modern cloud-native workloads and legacy infrastructure.
Azure Network - Azure VNET Design & Peering, Azure Application Gateway, Azure DNS, Azure ExpressRoute, Azure Firewall, Azure Firewall Manager, Azure Front Door, Azure Load Balancer, Azure Network Watcher, Azure Private Link, Azure Traffic Manager, Azure Virtual Network, Azure Virtual WAN, Azure VPN Gateway
Azure Security - Microsoft Zero trust architecture, Microsoft Defender XDR (Identities, Endpoints, Apps, Email), Defender for cloud (VMs, Database, container, Microsoft Entra) Platform Protection - Microsoft Zero trust architecture, Microsoft Defender XDR (Identities, Endpoints, Apps, Email), Defender for cloud (VMs, Database, container, Microsoft Entra), Azure Arc Security Operations - Integration of Microsoft defender using sentinel, Data connectors & data types in MS Sentinel, Microsoft sentinel analytics rule(Scheduled, NRT, Fusion, ML behavior, Threat intelligence) Data and application security- Encryption of data at rest and in transit, Azure key Vault for secrets and SSL certificates, Data Loss Prevention purview, Document Protection purview, Intune Services
AWS Network - Virtual Private Cloud, Route 53, Network & Application load balancer, VPC Interface & Gateway Endpoints, Endpoint services, Transit Gateway, Direct connect Gateway,VPN gateway, Amazon CloudFront, Resource access manager, AWS organization
AWS Security - Amazon Guardduty, Amazon detective, Amazon Inspector, AWS Security hub, AWS WAF, AWS system Manager, cloudwatch, CloudTrail, AWS Eventbridge, AWS config, Amazon Macie, AWS shield, Cloud HSM, AWS KMS AWS logging, Monitoring & alert - Cloudwatch, CloudTrail, VPC flow log, Amazon Kinesis, Amazon OpenSearch, Amazon SNS, SES, Trusted advisor AWS identity & access management - Identity, Resource & service control policies, Permission Boundry, Cross account IAM policy evaluation logic, Active Directory, IAM identity center, AWS Cognito, Service & Pass Role AWS storage - Amazon S3 (Bucket Policies, Versioning, Batch operations, S3 object lock, inventory), AWS Glacier, AWS Backup, Amazon Elastic File System AWS automation & Governance - AWS CloudFormation, Lambda, Service Catalog, and Control Tower
Terraform HCL (Hashicorp configuration language)
Automated provisioning of network and security resources across Azure [ Terraform attributes, Variables, terraformtfvars, Data types, Meta Arguments in Terraform, Terraform Functions, logging & debugging in terraform, Terraform init, plan, apply, output]
Designated and implemented reusable Terraform modules to automate provisioning of cloud networking components- Azure Firewall, Network security group, Azure WAF custom rule, Private endpoint, Virtual machine, Virtual network, VNET Peering, Storage account
Azure DevOps-
Developed and maintained CI/CD pipelines in Azure DevOps to provision and update network infrastructure across multiple environments ( Dev, QA, Prod)Managed infrastructure as code using Azure DevOps repos with modular terraform configurations for scalable and reusable network provisioning
Implemented branching strategies and pull request workflows to ensure code quality and controlled infrastructure changes integrated Terraform linting, validation and plan stages into Azure DevOps pipelines to enforce best practices and prevent misconfigurations
Data Center Technology-
Cisco Nexus (9K,7K,5k,2K), Cisco 6500 WAN, Cisco ISE, F5 load balancers(GTM,LTM), Cisco Meraki,
Palo Alto Firewall, FortiGate Firewall
EXPRESSROUTE to Meraki SDWAN Migration, Virtual WAN HUB Migration, F5 GTM physical device to Virtual series (VMware),
AWS Certified Security – Specialty