Sairin Ray Choudhury
Senior Cloud & DevSecOps Engineer DevOps Azure & GCP Certified
+91-725******* ******************@*****.*** LinkedIn: sairin-ray-choudhury Bengaluru, Karnataka, India PROFESSIONAL SUMMARY
Results-driven Senior Cloud & DevSecOps Engineer with 5 years of experience building, automating, and optimising enterprise-grade infrastructure across Azure and GCP ecosystems. Proven track record of reducing cloud infrastructure costs by 35%, cutting deployment cycle time by 60%, and improving system availability to 99.95% through CI/CD automation, Kubernetes container orchestration, and infrastructure-as-code practices. Hands-on experience in designing scalable, secure, and highly available systems across multi-cloud environments. Microsoft Certified: Azure Administrator Associate (AZ-104) and Google Cloud Certified Professional Cloud Developer. Actively seeking Cloud / DevOps Engineering roles with system-design scope. TECHNICAL SKILLS
Cloud Platforms Microsoft Azure (AZ-104), Google Cloud Platform (Professional Cloud Developer), Multi-Cloud Architecture
DevOps & CI/CD Azure DevOps Pipelines, ArgoCD, GitOps Containers & Orchestration Docker, Kubernetes (AKS, GKE), Helm, Docker Compose, Artifact Registry Infrastructure as Code and
Configuration Management
Terraform (IaC), OpenTofu, Ansible, Ansible Automation Platform/Ansible Tower AI/ML & Data Platforms Azure ML Workspace (Provisioning), Vertex AI, BigQuery, Foundry, RAG framework, LLMs Models, AI Agents, Tools
Cloud Storage & Data Azure Cosmos DB, Google Cloud Storage, Azure Storage Account, PostgreSQL, MySQL, Redis (Caching) Networking Azure Application Gateway, Google Cloud Load Balancing, VPC (Azure & GCP), API Gateway, Private Endpoints, Private DNS Zones
Security & DevSecOps IAM (Azure & GCP), RBAC, Azure Policy, Microsoft Defender for Cloud, Container Security Scanning
(Wiz, SonarQube), Kubernetes Security Posture Management (KSPM), Policy-as-Code (Kyverno), Secret Management (Azure Key Vault), SOC 2 readiness
Monitoring & Logs Azure Monitor, Google Cloud Monitoring, Grafana, Prometheus, Azure Log Analytics, Google Cloud Logging
Scripting & Dev Python, Bash/Shell, PowerShell, YAML System Design Microservices Architecture, Event-Driven Design, API Gateway, Load Balancing, Disaster Recovery, High Availability
CERTIFICATIONS
• Microsoft Certified: Azure Administrator Associate — AZ-104 Credential ID: F94BAD998E72A430
• Google Cloud Certified: Professional Cloud Developer Credential ID: d81884137f3b4d07bf04fe29b4191fb5 WORK EXPERIENCE
Senior Cloud & DevSecOps Engineer Confluentis Consulting LLP Bengaluru, India Jun 2024 – Present Platform & Networking
• Drove the technical implementation of migrating NGINX Ingress to NGINX Gateway Fabric using the Kubernetes Gateway API across DEV, QA, Staging and Production environments, implementing HTTPRoute, BackendTLSPolicy, SnippetsFilter, and NetworkPolicy with zero traffic disruption.
• Led Disaster Recovery (DR) readiness initiatives by implementing environment-specific deployment configurations, release automation, infrastructure replication strategies, and DR validation processes across platform services.
• Decreased deployment cycle time by 60% by optimizing Docker builds and CI/CD pipelines; implemented multi-stage containerization, leveraged Azure Artifact feeds for dependency caching, and decoupled heavy scientific workloads (GROMACS, LAMMPS) via dynamic volume mounting.
Security & Container Hardening
• Remediated root-access and privilege-escalation vulnerabilities across 80+ production microservices identified via Microsoft Defender for Cloud, then deployed Kubernetes policy-as-code frameworks using Kyverno to enforce security controls such as privilege escalation restrictions, pod validation policies, and exception management for future deployments.
• Established DevSecOps practices by integrating Wiz container security scanning into CI/CD pipelines, driving the end-to-end vulnerability management lifecycle — detection, triage, and remediation of critical/high CVEs across Node.js, Python, Golang, Guacamole, and workspace container images.
• Led container hardening initiative by using Docker Hardened Images (DHI), reducing container attack surface and strengthening software supply chain security.
• Eliminated NGINX server version disclosure vulnerability and implemented controlled error-page handling for gateway failures (502/503), improving security posture while preserving application-level error visibility. Observability, Logging & Cost Optimization
• Enhanced AKS observability and logging reliability by upgrading and maintaining Prometheus, Grafana, Logging Operator, Fluent Bit, and Fluentd while enabling cluster-wide telemetry and service monitoring.
• Contributed to cost optimization by automating ACR/Artifact Registry image lifecycle cleanup and Log Analytics ingestion filtering, and rightsizing Kubernetes workloads using an in-house prediction tool collectively reducing cloud spend by 35%
• Diagnosed and resolved an HTCondor cost-attribution defect caused by worker pod reuse across users, implementing single-user pod allocation and graceful queuing to ensure accurate workload chargeback and billing visibility.
• Prevented an estimated $50K–$70K (per industry pricing) in annual licensing costs by leading migration of 20+ Bitnami NGINX-based container images to official NGINX images ahead of Bitnami Secure Images subscription enforcement. Developer Platform Engineering
• Designed and delivered self-service developer workspaces (VS Code, PyCharm, Jupyter, RStudio, Generic Compute) on Kubernetes, improving developer productivity and reducing environment provisioning effort.
• Planned and executed platform upgrades across Helm, Prometheus, Logging Operator, HTCondor, Guacamole, and developer workspace environments, improving platform stability, security, and supportability.
• Automated Azure and GCP infrastructure provisioning using Terraform and environment configuration using Ansible, ensuring repeatable and consistent deployments across Dev, QA, Staging, Production, and Disaster Recovery environments. AI / MLOps
• Implemented MLOps and MS Foundry by automating machine learning model training, validation, and deployment using Azure Machine Learning Pipelines on Kubernetes compute, enabling scalable and reproducible AI workflows.
• Designed and supported RAG-based AI workflows covering document ingestion, chunking, embedding generation, vector retrieval, and LLM inference, integrating the solution with Azure networking, Kubernetes, identity, secure data access, and observability for enterprise workloads.
• Designed and supported Microsoft Discovery / Azure AI Foundry-based enterprise AI infrastructure, including Foundry Projects, with secure control/data-plane separation, VNets, Network Security Perimeters (NSPs), Private Endpoints, and integration with Azure services such as AKS, Container Apps, Storage, and Search.
DevOps Engineer Quess Corporation Ltd. Bengaluru, India Aug 2023 – May 2024
• Provisioned and managed Azure cloud resources including App Services, Function Apps, Storage Accounts, Load Balancers, VNets, NSGs, Private Endpoints, and Private DNS Zones across Development, QA, UAT, and Production environments.
• Developed and maintained Kubernetes workloads on AKS, including Deployments, Services, ConfigMaps, and ingress configurations for containerized applications.
• Contributed to the team's 99.95% availability objectives for production services by implementing Horizontal Pod Autoscalers (HPA), PodDisruptionBudgets (PDBs), liveness/readiness probes, automated rollback mechanisms in Azure DevOps CI/CD pipelines, and disaster recovery configurations including geo-redundant storage and database failover setups.
• Developed and maintained Ansible playbooks and YAML-based automation through Ansible Tower/Ansible Automation Platform for infrastructure configuration and deployment activities across Linux environments.
• Managed secret lifecycle using Azure Key Vault — provisioning vaults, configuring access policies, and integrating Key Vault references into Azure DevOps pipelines via variable groups — alongside Kubernetes-native Secrets management for in-cluster credential consumption.
• Administered Azure RBAC by assigning role-based access (Contributor, Reader, and custom roles etc.) to users aligned to job function, and supported Service Principal configuration including API permissions and redirect URI setup for application authentication flows. Senior Analyst Ernst & Young LLP (EY) Bengaluru, India Sept 2022 – Jul 2023
• Provisioned core Azure resources (AKS clusters, Cosmos DB, Storage Accounts) under guidance of senior consultants and monitored configured resource alerts — triaging issues directly or escalating to Microsoft support for major failures.
• Worked hands-on with Kubernetes on AKS, deploying and managing core workload types (Deployments, StatefulSets, DaemonSets, Services, Ingress).
• Supported Ansible-based automation using YAML playbooks for Linux configuration and routine infrastructure administration, gaining hands-on experience with Ansible Tower and automated job execution.
• Supported Azure DevOps pipeline builds and release stages, gaining working knowledge of CI/CD pipeline structure and deployment workflows.
Programmer Analyst Trainee Cognizant Bengaluru, India March 2022 – Aug 2022
• Gained hands-on exposure to cloud-based application environments, supporting application deployment, configuration, and troubleshooting activities.
• Worked with Linux, basic scripting, application monitoring, and deployment workflows, building foundational experience in cloud and DevOps practices.
EDUCATION
Bachelor of Engineering — Computer Science
Sir M. Visvesvaraya Institute of Technology, Bengaluru, Karnataka