Cloud Architecture & Azure Platform
Architecture and operation of secure enterprise Azure environments, with particular depth in private connectivity and shared platform services.
- ExpressRoute
- VPN Gateway
- VNet peering
- Private Link
- Private Endpoints
Turning two decades of infrastructure expertise into AI-enabled operations — RAG, knowledge assistants, and intelligent troubleshooting at enterprise scale.
Cloud Infrastructure Leader | Azure & Network Architecture | Automation | AI-Enabled Operations

20+
Years Experience
50+
Technologies & Platforms
25+
Certifications & Courses
30+
Projects & Solutions
I am a cloud infrastructure and connectivity leader with more than 20 years of professional experience spanning enterprise networking, security, Microsoft Azure, automation and platform engineering. I work across architecture and operations, turning complex infrastructure requirements into secure, supportable systems and practical engineering decisions. My strongest foundations are cloud connectivity and network architecture, supported by hands-on experience in automation, DevOps and container platforms. I am now extending that experience into AI-enabled operations, applied machine learning and intelligent troubleshooting. I value clear architecture, operational evidence and solutions that work under real enterprise constraints.
My career began in enterprise networking and customer-facing technical operations before progressing through network engineering, architecture, cloud platforms, automation and technical leadership. Today, as Associate Director — Public Cloud Connectivity Engineering, I work at the intersection of cloud infrastructure, connectivity, security, platform engineering and operational enablement.
My strongest professional foundation is the architecture and operation of complex enterprise networks and Azure connectivity services. I approach cloud systems as connected platforms rather than isolated services. Applications depend on routing, DNS, identity, security controls, observability, deployment processes and reliable operations, so effective architecture requires both a strategic view and the willingness to investigate technical detail when something fails.
I have worked across architecture, engineering, operations and consulting roles in India, the United Kingdom and the Czech Republic. My experience includes enterprise routing and switching, hybrid cloud connectivity, private Azure networking, firewalls, load balancing, Kubernetes, infrastructure as code, CI/CD and operational automation. I use Python, PowerShell, Terraform and related engineering practices to reduce manual effort and make outcomes more repeatable.
My current development focus is the intersection of infrastructure and AI. I am exploring retrieval-augmented generation, model-connected tools, machine learning and structured operational data for troubleshooting, knowledge access and engineering workflows. I present this as an evolving area of applied work and learning, grounded in my established cloud and networking experience.
I value direct problem solving, careful technical reasoning and honest evidence. This portfolio documents selected work, technical writing and professional experience while respecting employer and client confidentiality.

Depth across cloud, network and AI-enabled operations — grouped by domain.
Number of domains at each strength level
Cloud Architecture & Azure Platform, Networking & Connectivity, Azure Platform & Private Networking, Enterprise Network, Security & Hybrid Infrastructure
Security & Identity, Automation & DevOps
Platforms & Containers
Data & Analytics
AI & Machine Learning
Architecture and operation of secure enterprise Azure environments, with particular depth in private connectivity and shared platform services.
Enterprise network architecture across data-centre, hybrid-cloud and cloud-native environments.
Security-conscious architecture across cloud connectivity, network controls and identity-aware platform integration.
Repeatable infrastructure delivery and operational automation using code, pipelines and configuration management.
Applied development in AI-enabled operations, RAG, model-connected tools and machine-learning foundations.
Operational-data analysis, telemetry querying and data-platform integration for infrastructure and AI use cases.
Container, Kubernetes and enterprise platform experience spanning architecture, migration and operations.
Azure private connectivity, application delivery and platform integration across Private Link/DNS, ExpressRoute/VPN, NVA, Application Gateway/Front Door/WAF, API Management, Key Vault, AKS and hub-and-spoke architecture.
Enterprise routing and switching; BGP, OSPF and route redistribution; Cisco Nexus and spine-leaf fabrics; firewall clustering and segmentation across Palo Alto, Check Point and Fortinet; F5/NetScaler, secure web proxies, wireless controllers/APs, VMware, IBM Cloud and hybrid connectivity.
Every platform and tool across the domains above, at a glance.
Novartis
December 2022 – Present · Prague, Czech Republic
Full-time employment
Leadership scope: Cross-functional technical and architecture leadership
Enterprise scale & impact
Key projects & deliverables
Key technologies
Novartis
January 2021 – December 2022 · Prague, Czech Republic
Full-time employment
Leadership scope: Subject-matter and cross-team technical leadership
Enterprise scale & impact
Key projects & deliverables
Key technologies
IBM
March 2015 – January 2021 · Brno, Czech Republic
Full-time employment
Leadership scope: Technical leadership across engineering teams and client engagements
Enterprise scale & impact
Key projects & deliverables
Key technologies
JNCT
May 2013 – December 2013 · India
Full-time academic role
Key domains
IBM and AT&T — client assignments
2008–2011 · Bangalore, India and Brno, Czech Republic
Contract client assignments through a staffing agency
Enterprise scale & impact
Key projects & deliverables
Key technologies
Datacraft; resident assignment at Aztecsoft
November 2006 – December 2007 · Pune, India
Full-time employment with Datacraft; approximately 80% resident assignment at Aztecsoft and 20% Datacraft field assignments
Enterprise scale & impact
Key projects & deliverables
Key technologies
ClientLogic
July 2005 – May 2006 · Newcastle upon Tyne, United Kingdom
Part-time student visa work — limited to 20 hours per week while studying in the UK
Key domains
Alongside my primary career, I have completed selected independent and contractual assignments. These are presented separately to distinguish them from my full-time employment history.
2023
Automated repository and CI/CD migration activities and developed supporting Python tooling for enterprise environments
Tietoevry · March 2022 – April 2023 · Ostrava, Czech Republic
Designed Azure and AKS infrastructure for application migration; created reusable Terraform, Bicep/ARM and CI/CD assets; supported platform services and migration from Docker Swarm to AKS
drivvn · August 2021 – December 2021 · Remote
Built Azure DevOps build and release pipelines, supported AKS deployments, and worked on ingress, egress, certificates, CDN and VPN integration
2021–2023
Delivered selected Azure connectivity, platform integration, automation and infrastructure-as-code assignments for enterprise clients
2016–2021
Delivered cloud, container, networking and automation work for international clients
2011–2015
Provided remote network, firewall, VPN, monitoring, documentation and technical-training services
University of Sunderland
2004–2006 · United Kingdom
Specialized research in enterprise networking architectures, wide-area connectivity, distributed Java programming, and discrete network simulations.
Core modules
University Institute of Technology (RGPV)
2000–2004 · India
Rigorous foundation in telecommunications systems, signal propagation, VLSI design, semiconductor physics, and core TCP/IP data network models.
Core modules
A cost-conscious pipeline for parsing, enriching, querying, and visualizing Azure VNet flow logs without relying on Traffic Analytics.
A research evaluation of Azure SRE, Observability, and Troubleshooting agents against controlled, reproducible network incidents.
A planned lab exploring a privately networked Azure Machine Learning workspace with controlled outbound connectivity for a real ML workload.
Research in Progress
3 min readAI Systems
A working survey of Azure's SRE, observability, and troubleshooting agents — what each one covers, where its scope ends, and where extension points exist.
Preview
3 min readAzure Networking
A technical walkthrough of parsing and querying Azure VNet flow logs directly, as a cost-conscious alternative to Traffic Analytics.
Research in Progress
3 min readMachine Learning
Tracing what a Jupyter notebook session in an Azure Machine Learning compute instance actually talks to on the network, and why that matters for private workspace design.