Results-oriented Senior Cloud Specialist with over 10 years of experience in Azure architecture and cloud migration. Led cost optimization and infrastructure as code initiatives, enhancing operational efficiency and security across enterprise environments. Designed resilient solutions and fostered collaboration to drive impactful cloud initiatives.
Overview
1
1
Certification
12
12
years of professional experience
Work History
Senior Cloud specialist
LTI Mindtree
Pune
08.2022 - Current
Designed and implemented enterprise-scale cloud solutions on Microsoft Azure aligned with business, security, and compliance requirements.
Led end-to-end cloud transformation initiatives, including assessment, planning, migration, modernization, and post-migration optimization.
Architected highly available, scalable, and resilient solutions using Azure Virtual Machines, App Services, Azure Kubernetes Service (AKS), Azure Functions, and Azure SQL Database.
Developed Azure Landing Zone architecture incorporating governance, networking, identity, security, and cost management best practices.
Designed hub-and-spoke network topology using Azure Virtual Network, Azure Firewall, VPN Gateway, ExpressRoute, NSGs, and Azure Bastion.
Implemented Zero Trust security architecture using Microsoft Entra ID (Azure AD), Managed Identities, Azure Key Vault, Microsoft Defender for Cloud, and Azure Policy.
Defined disaster recovery and business continuity strategies leveraging Azure Site Recovery, Azure Backup, Availability Zones, and Geo-Redundant Storage.
Automated infrastructure deployment using Terraform, Bicep, ARM templates, Azure DevOps, and GitHub Actions.
Established monitoring and observability using Azure Monitor, Log Analytics, Application Insights, and Microsoft Sentinel.
Optimized Azure spending through Azure Cost Management, Reserved Instances, Auto Scaling, and resource right-sizing.
Conducted infrastructure and application discovery using Azure Migrate, Dependency Visualization, and Azure Advisor.
Performed application portfolio assessment to determine rehost, refactor, replatform, retire, retain, or replace strategies.
Evaluated application dependencies, licensing, security, networking, and performance requirements.
Estimated migration costs, cloud readiness, and ROI using Azure Total Cost of Ownership (TCO) Calculator.
Created migration roadmap, wave planning, and cutover strategy for business-critical workloads.
Designed target Azure architecture including subscriptions, management groups, networking, identity, and governance.
Defined migration runbooks, rollback plans, risk mitigation strategies, and success criteria.
Infrastructure Migration
Led migration of Windows and Linux virtual machines using Azure Migrate and Azure Site Recovery.
Migrated VMware and Hyper-V workloads to Azure with minimal downtime.
Configured ExpressRoute, Site-to-Site VPN, Azure DNS, and hybrid connectivity.
Implemented Azure Backup and disaster recovery solutions before production cutover.
Database Migration
Migrated SQL Server databases using Azure Database Migration Service (DMS).
Migrated Oracle, MySQL, and PostgreSQL workloads to Azure managed database services.
Optimized database performance through indexing, scaling, and monitoring.
Identity & Security
Integrated on-premises Active Directory with Microsoft Entra ID using Azure AD Connect, Cloud Sync.
Extended Current Domain Controller and created new AD sites in Azure.
Implemented Role-Based Access Control (RBAC), Privileged Identity Management (PIM), Conditional Access, and Multi-Factor Authentication.
Secured secrets and certificates using Azure Key Vault.
DevOps & Automation
Built CI/CD pipelines using Azure DevOps and GitHub Actions.
Automated infrastructure provisioning with Terraform and Bicep.
Implemented Infrastructure as Code (IaC) for repeatable deployments across environments.
Azure Networking
Designed enterprise-scale Azure networking architecture using Azure Virtual WAN (vWAN) for centralized connectivity across regions, branches, and hybrid environments.
Architected hub-and-spoke and Virtual WAN network topologies based on business, security, and scalability requirements.
Designed IP addressing strategy, subnet segmentation, and network isolation for multi-subscription Azure environments.
Implemented hybrid connectivity using ExpressRoute, Site-to-Site VPN, Point-to-Site VPN, and Azure VPN Gateway.
Designed secure interconnectivity between on-premises datacenters, Azure, and third-party cloud environments.
Configured Azure Virtual Network peering, Global VNet Peering, and Virtual WAN hubs for low-latency communication.
Implemented Azure Firewall, Network Security Groups (NSGs), Application Security Groups (ASGs), and Azure DDoS Protection for layered network security.
Designed private connectivity using Private Endpoints, Private Link, and Service Endpoints to eliminate public exposure of PaaS services.
Architected secure internet ingress and egress using Azure Application Gateway (WAF), Azure Front Door, Azure Load Balancer, and Azure Traffic Manager.
Configured Azure DNS, Private DNS Zones, and custom DNS integration for hybrid name resolution, Azure DNS Private resolver.
Designed network routing using User Defined Routes (UDRs), BGP, route tables, and Virtual WAN routing policies.
Implemented Azure Bastion for secure administrative access without exposing management ports.
Integrated Microsoft Entra ID authentication with networking services where applicable.
Implemented network monitoring and diagnostics using Azure Network Watcher, Connection Monitor, NSG Flow Logs, Traffic Analytics, and Azure Monitor.
Optimized network performance, resiliency, and cost through regional architecture, redundant connectivity, and bandwidth planning.
Produced High-Level Design (HLD), Low-Level Design (LLD), IP plans, and network topology diagrams for enterprise Azure deployments.
Azure Landing Zone & Governance
Designed and implemented Azure Landing Zones aligned with the Microsoft Cloud Adoption Framework.
Established subscription hierarchy using Management Groups with enterprise governance and policy enforcement.
Designed shared services architecture including centralized networking, identity, monitoring, backup, and security.
Implemented Azure Policy, RBAC, resource tagging, budgets, and resource locks to enforce governance standards.
Configured Log Analytics workspaces, Azure Monitor, Microsoft Defender for Cloud, and Microsoft Sentinel for centralized monitoring and security.
Standardized infrastructure deployment using Terraform, Bicep, and Azure DevOps pipelines.
AI Landing Zone
Designed and deployed enterprise AI Landing Zone architecture aligned with Azure Cloud Adoption Framework and Azure AI best practices.
Established secure AI environments with dedicated subscriptions, resource groups, virtual networks, and governance controls.
Implemented network isolation for AI services using Private Endpoints, Private DNS Zones, and Azure Firewall.
Configured identity and access management using Microsoft Entra ID, Managed Identities, RBAC, and Azure Key Vault.
Implemented Azure Policy, resource tagging, budgets, and governance controls for AI workloads.
Automated AI Landing Zone provisioning using Terraform/Bicep and Azure DevOps CI/CD pipelines.
Integrated Azure Monitor, Log Analytics, and Microsoft Defender for Cloud for centralized monitoring and security compliance.
Designed scalable AI infrastructure supporting Azure AI Services, Azure Machine Learning, Azure OpenAI, and AI application workloads.
Designed AI Landing zone Integration with APIM Hub.
Consultant L1
T-systems
Pune
12.2019 - 08.2022
Azure Administration Azure Networking Administration Azure Migration Support Identity and Security Administration Backup and Disaster Recovery Monitoring & Operations Automation & DevOps Support
Administered Microsoft Azure infrastructure, ensuring high availability, security, and operational efficiency across production and non-production environments.
Provisioned and managed Azure Virtual Machines (Windows/Linux), Azure Storage Accounts, Azure App Services, and Azure SQL Databases.
Managed Azure subscriptions, resource groups, management groups, and resource organization following enterprise standards.
Configured and maintained Azure Virtual Networks (VNets), subnets, NSGs, Route Tables, Azure Firewall, and Azure Bastion.
Managed Microsoft Entra-ID users, groups, RBAC, Managed Identities, Conditional Access, and Multi-Factor Authentication (MFA).
Implemented Azure Backup, Azure Site Recovery (ASR), and disaster recovery solutions for business-critical workloads.
Configured Azure Monitor, Log Analytics, Application Insights, and alerts for proactive monitoring and incident management.
Performed patch management, OS upgrades, capacity planning, and performance optimization for Azure resources.
Managed Azure Cost Management, budgets, resource tagging, and rightsizing initiatives to optimize cloud expenditure.
Automated routine administrative tasks using Azure PowerShell, Azure CLI, and Azure Automation Runbooks.
Configured and administered Azure Virtual Networks (VNets), subnets, and IP addressing for enterprise workloads.
Managed Azure Virtual WAN (vWAN) hubs, VNet connections, and branch connectivity.
Configured VNet Peering and Global VNet Peering to enable secure communication between Azure environments.
Administered Site-to-Site VPN, Point-to-Site VPN, and ExpressRoute connectivity between Azure and on-premises environments.
Configured Azure Firewall rules, NSGs, ASGs, and User Defined Routes (UDRs) to secure network traffic.
Managed Azure Load Balancer, Application Gateway (WAF), Azure Front Door, and Traffic Manager.
Configured Private Endpoints, Private Link, Service Endpoints, and Private DNS Zones for secure PaaS connectivity.
Monitored network health and performance using Azure Network Watcher, Connection Monitor, NSG Flow Logs, and Traffic Analytics.
Troubleshot network connectivity, routing, DNS, VPN, and ExpressRoute issues.
Supported end-to-end migration of on-premises workloads to Microsoft Azure using Azure Migrate and Azure Site Recovery.
Performed server discovery, dependency mapping, and migration readiness assessments.
Provisioned target Azure infrastructure including VNets, storage accounts, virtual machines, and recovery services vaults.
Executed migration waves, monitored replication, and coordinated production cutovers.
Validated migrated workloads and resolved post-migration infrastructure issues.
Assisted with rollback planning, migration testing, and business continuity activities.
Configured backup and disaster recovery solutions for migrated workloads.
Managed Microsoft Entra ID users, groups, and enterprise applications.
Configured Role-Based Access Control (RBAC) and least-privilege access across Azure subscriptions.
Assisted in backup monitoring, recovery validation, and disaster recovery support using Veeam Backup & Replication.
Supported Microsoft 365 administration, including user provisioning, mailbox management, and license assignments.
Assisted in Azure administration by provisioning Azure Virtual Machines, Resource Groups, Storage Accounts, and Virtual Networks under senior administrator guidance.
Monitored Azure resources using Azure Monitor and supported routine cloud operational activities.
Resolved Windows Server, VMware, backup, VPN, printer, and application-related incidents within defined SLA targets.
Logged, tracked, and resolved incidents using ITSM tools while maintaining technical documentation and standard operating procedures (SOPs).
Collaborated with infrastructure, network, storage, and cloud teams to support enterprise IT operations and planned maintenance activities.
Technical Support Engineer
Dynacons System & Solution
Pune
03.2017 - 02.2018
Provided Level 1 technical support for desktops, laptops, printers, and peripheral devices in a Windows enterprise environment.
Diagnosed and resolved hardware, software, operating system, and application-related issues within defined SLAs.
Troubleshot LAN/WAN, Wi-Fi, VPN, DNS, DHCP, and TCP/IP connectivity issues.
Installed, configured, and maintained Windows 10/11 operating systems and enterprise applications.
Installed and configured desktop hardware, printers, scanners, monitors, and other IT peripherals.
Configured and supported Microsoft Office 365, Outlook, Teams, OneDrive, and SharePoint applications.
Managed Active Directory user accounts, password resets, account unlocks, and group membership changes.
Assisted in user onboarding and offboarding, including workstation setup, software installation, and account provisioning.
Configured email profiles, Outlook mailboxes, signatures, and mobile device synchronization.
Installed software updates, security patches, antivirus solutions, and operating system upgrades.
Performed desktop imaging, OS deployment, and workstation provisioning using enterprise deployment tools.
Configured network printers, printer queues, and resolved printing and scanning issues.
Provided remote technical support using Remote Desktop, AnyDesk, TeamViewer, and Microsoft Quick Assist.
Logged, tracked, and resolved incidents and service requests using ITSM tools such as ServiceNow
Maintained IT asset inventory, hardware lifecycle records, and software license compliance.
Escalated complex issues to Level 2/Level 3 support teams while ensuring timely communication with end users.
Documented troubleshooting procedures, knowledge base articles, and standard operating procedures (SOPs).
Delivered technical support with a focus on customer satisfaction and first-call resolution.
Service Engineer
Unicorn Info-Solution
Pune
02.2015 - 07.2016
Provided technical support and troubleshooting for Apple MacBook, iMac, and macOS environments.
Diagnosed and resolved hardware issues related to MacBook components including logic board, battery, display, keyboard, trackpad, storage, and memory.
Performed Mac hardware diagnostics using Apple Diagnostic tools to identify and troubleshoot device failures.
Troubleshot macOS issues related to system performance, application crashes, startup failures, and user profile problems.
Installed, configured, and upgraded macOS operating systems and supported macOS version upgrades.
Performed macOS installation, system recovery, disk formatting, and data migration activities.
Configured email accounts, VPN clients, Wi-Fi profiles, printers, and enterprise applications on Mac devices.
Assisted users with MacBook setup, software installation, and application configuration.
Supported Microsoft Office 365 applications on macOS, including Outlook, Teams, Word, Excel, and OneDrive.
Performed hardware replacement activities including battery replacement, SSD replacement, keyboard/display replacement, and component diagnostics.
Managed Mac user accounts, permissions, and system preferences.
Supported data backup, restoration, and migration using Time Machine and enterprise backup solutions.
Troubleshot network connectivity issues including Wi-Fi, VPN, DNS, and internet access on macOS devices.
Supported enterprise Mac deployments, including device enrollment and configuration using MDM solutions.
Assisted with Apple device management using tools such as Jamf Pro, Microsoft Intune, or other MDM platforms.
Maintained service records, repair documentation, and asset tracking for Apple devices.
Logged incidents and service requests using ITSM tools and ensured timely resolution within SLA.
Provided remote and onsite technical support for end users.
Provided remote and onsite technical support for end users.
Education
BSC-IT -
NKTT
MH
01-2015
HSC -
Desai Collage
MH
01-2011
SSC -
Modern High School
MH
01-2009
Skills
Azure solution design
Cloud workload migration
Infrastructure automation
Cloud Architecture
Cloud infrastructure
Cost optimization
Azure Network Design
Certification
Microsoft Certified: Azure Fundamentals (AZ-900)
Microsoft Certified: Azure Administrator Associate (AZ-104)
Microsoft Certified: Azure Solutions Architect Expert(AZ-305)
70-740 – Installation, Storage, and Compute with Windows Server 2016