TCS – EY
September 2022 - present
Deployed API Management to expose microservices securely and consistently, including rate limiting and quotas. Designed and managed Azure Express Route connections for high-bandwidth network links, performing advanced configuration like BGP routing and peering. Configured Azure Firewall Premium tier with Threat Intelligence and TLS inspection, developing FQDN filtering and application rules. Utilized Network Watcher for proactive network troubleshooting and developed automated diagnostic scripts. Conducted advanced network protocol analysis using Wireshark. Utilized Azure Front Door for global load balancing and secure access, and Azure Load Balancer for traffic management to backend services. Employed Azure Key Vault for managing encryption keys and secrets. Led the migration of legacy applications to OpenShift, reducing infrastructure costs by 30%. Implemented automated testing and deployment processes, improving release cycles. Managed Terraform modules for reusable infrastructure components and utilized Git for version control. Enhanced API security with robust API key and Lambda authorizer-based authentication, improving user access management and streamlining the authentication process. Responsible for implementing, designing, and architecting system and application infrastructure. Configured customized applications in a virtual environment. Managed API Key Management, Lambda Authorizers, JWT Tokens, AWS API Gateway, Azure API Management, Google Cloud Endpoints, AWS Lambda, Azure Functions, Google Cloud Functions, AWS Cognito, OAuth 2.0, OpenID Connect, Access Control, Token Management, and Encryption. Designed, implemented, and maintained CI/CD pipelines using Azure DevOps. Managed Azure network infrastructure (VNETs, subnets, NSGs, route tables, ACLs) and Azure AD, DNS, and domain management. Managed access to Azure AD resources, assigning administrative roles, resetting passwords, and managing licenses. Assisted with Discovery, Scoping, and Planning of cloud adoption projects. Experienced with Azure Security Center, Azure Key Vault, Azure Policies, Azure Monitoring, Log Analytics, and Kusto queries. Integrated third-party apps with Azure Active Directory and configured Single Sign-On (SSO). Managed and provided access/permissions to users and applications in Azure. Configured App Security Groups (ASG) vs Network Security Groups (NSG). Connected on-prem networks to Azure virtual networks via site-to-site and point-to-site VPN. Created storage accounts and containers for blob, file, and table storage. Developed PowerShell scripts and automation tools for daily activities on Windows servers, applications, and SQL databases. Managed Active Directory administration using PowerShell, preparing automation scripts for daily AD tasks. Performed Azcopy activities and sync-up processes daily. Developed and maintained security policies for AWS environments, ensuring compliance with GDPR, HIPAA, or PCI DSS. Conducted regular security assessments and vulnerability scanning using AWS tools like Amazon Inspector. Used Lambda, CloudFormation, JSON, YAML, Shell scripts, PowerShell for microservices and containerization. Focused on cloud resource security best practices, CloudWatch, Config, CloudTrail, SNS, Log Aggregation concepts, and backup. Expert in Linux and Linux automation, with good knowledge of Windows Server operating systems and automation. Utilized Terraform, Ansible, Jenkins for infrastructure and deployment automation. Used Git and AWS CodeCommit for source control. Automated manual collection of AWS EC2 spot metrics. Handled Configuration Management, Cloud Infrastructure, and Automation with AWS, Maven, Jenkins, and Ansible.