JATIN SRIVASTAVA
Cloud Engineer Microsoft Azure Specialist
Active Directory & Microsoft Entra ID (Azure AD) Identity & Access Management Noida, Uttar Pradesh, India +91-638******* ****************@*****.*** linkedin.com/in/jatinsrivastava PROFESSIONAL SUMMARY
Microsoft Azure-certified Cloud Engineer (AZ-104, AZ-500, AZ-700, AZ-140) with 3+ years of enterprise experience designing, securing, and administering Active Directory and Microsoft Entra ID (Azure AD) environments. Specialized in identity and access management, including hybrid identity architecture, RBAC, Conditional Access, Privileged Identity Management, and Zero-Trust security enforcement. Skilled in end-to-end cloud migration using Azure Migrate and Azure Site Recovery, WAF hardening with OWASP Core Rule Set (CRS), and disk encryption using Customer-Managed Keys (CMK) and Platform-Managed Keys (PMK). Proficient in PowerShell, Azure CLI, and KQL for identity automation, access governance, and real-time monitoring via Azure Monitor and Log Analytics. Delivered 99.99% uptime SLA and 96-99% CSAT scores while enforcing enterprise identity compliance and security standards across IaaS, PaaS, and hybrid workloads. CORE SKILLS
Identity & Access Management: Microsoft Entra ID (Azure AD), Active Directory Domain Services (AD DS), Domain Controllers & OU Structure, Hybrid Identity (Azure AD Connect / Entra Connect Sync), Active Directory Federation Services (ADFS), RBAC & Conditional Access, Privileged Identity Management (PIM), Dynamic & Security Groups, App Registrations & Enterprise Applications, Multi-Factor Authentication (MFA), Single Sign-On (SSO), Self-Service Password Reset (SSPR), Group Policy Objects (GPO), Identity Governance & Access Reviews, Zero-Trust Architecture
Cloud & Networking: Azure Cloud Migration, Azure Site Recovery (ASR), Azure Application Gateway v2, Web Application Firewall
(WAF), Network Security Groups (NSG), Private Endpoints & DNS Zones, VMware vSphere, Disaster Recovery Planning Security & Compliance: Azure Key Vault (CMK/PMK), Disk Encryption, OWASP Core Rule Set (CRS), SSL/TLS Management, Regulatory Compliance Enforcement
Tools & Automation: PowerShell Scripting, Azure CLI / Bash, Azure Monitor / Log Analytics, KQL Dashboards, Azure Policy AI & Intelligent Automation: Claude AI, AI-Assisted Documentation & Runbook Generation, AI-Based Cost Optimization & Resource Management, Prompt Engineering, AI-Driven Platform Re-architecture, AI-Enhanced Monitoring & Reporting CERTIFICATIONS
• AZ-104: Microsoft Certified Azure Administrator Associate
• AZ-500: Microsoft Certified Azure Security Engineer Associate
• AZ-700: Microsoft Certified Azure Network Engineer Associate
• AZ-140: Microsoft Certified Azure Virtual Desktop Specialty WORK EXPERIENCE
Cloud Engineer Apr 2024 – Jan 2026
Noventiq India Pvt. Ltd. — Noida, Uttar Pradesh, India Project 1: Hybrid Identity & Active Directory to Microsoft Entra ID Migration
• Led full lifecycle cloud migration of OVH on-premises workloads to Microsoft Azure using Azure Migrate, including Active Directory identity assessment, dependency mapping, replication, and zero-downtime VM cutover.
• Configured hybrid identity synchronization between on-premises Active Directory and Microsoft Entra ID using Azure AD Connect, ensuring seamless user, group, and device authentication across environments.
• Managed Active Directory Organizational Units (OUs), security groups, and Group Policy Objects (GPOs), and mapped them to Entra ID dynamic groups and Enterprise Applications for consistent access control post-migration.
• Redesigned legacy virtual machines into Azure-native PaaS and IaaS solutions, improving scalability, identity governance, and security posture while achieving measurable cost optimization.
• Used Azure Dependency Visualization and Application Insights for comprehensive performance analysis, enabling a smooth and risk-free workload and identity transition.
• Collaborated with cross-functional stakeholders throughout all migration phases; delivered post-migration performance tuning and consistently met high-availability SLA targets. Tech Stack: Azure Migrate, Azure Site Recovery, Microsoft Entra ID, Active Directory, Azure VMs, App Services, Azure SQL, Blob Storage, Application Gateway, NSG, Azure Monitor, Log Analytics, Application Insights, PowerShell, Key Vault, RBAC Project 2: Identity-Driven Secure Resource Deployment with Disk Encryption (CMK & PMK)
• Deployed and configured Azure VMs, Managed Disks, Key Vaults, and NSGs in alignment with enterprise identity and security architecture and regulatory compliance standards.
• Implemented RBAC and Conditional Access policies through Microsoft Entra ID to restrict resource access based on least- privilege identity principles.
• Configured Privileged Identity Management (PIM) for just-in-time role elevation on sensitive resources, reducing standing administrative access across the environment.
• Implemented Customer-Managed Keys (CMK) for sensitive workloads and Platform-Managed Keys (PMK) for standard environments, achieving complete data-at-rest protection.
• Delivered a fully compliance-ready, scalable deployment within agreed SLA timelines, earning a 99% Client Satisfaction (CSAT) score.
• Conducted knowledge transfer sessions and authored detailed operational runbooks, significantly improving client team self- sufficiency and reducing external support dependency. Tech Stack: Azure VMs, Managed Disks, Key Vault, Disk Encryption Set, CMK, PMK, Microsoft Entra ID, RBAC, NSG, Azure Policy, PowerShell, Azure CLI
Project 3: Azure Application Gateway v2 + Web Application Firewall (WAF) with Zero-Trust Enforcement
• Designed and deployed Azure Application Gateway v2 with WAF — configured path-based routing rules, custom health probes, backend pools, and multi-site listeners for multiple enterprise applications.
• Enforced Zero-Trust access policies through Microsoft Entra ID Conditional Access, integrating identity verification with network-layer security controls.
• Configured WAF policies using OWASP Core Rule Set (CRS) 3.2 and custom rules to defend against SQL injection, XSS, and other OWASP Top 10 Layer 7 threats, reducing security incidents by 85%.
• Implemented SSL/TLS termination and end-to-end HTTPS encryption with trusted CA certificates, ensuring fully encrypted traffic across all services.
• Achieved 99.99% uptime SLA and 96% CSAT through zero-trust policy enforcement, proactive threat protection, and real-time diagnostics via Azure Monitor and Log Analytics Workspace. Tech Stack: Application Gateway v2, WAF, OWASP CRS 3.2, Custom WAF Rules, Microsoft Entra ID, Conditional Access, Azure Monitor, Log Analytics Workspace, Application Insights, SSL/TLS, PowerShell, Azure CLI, NSG, Key Vault Project 4: AI-Driven Documentation & Platform Cost Optimization
• Leveraged Claude AI to generate and standardize technical documentation, operational runbooks, and knowledge-transfer material across cloud migration and security projects, improving documentation accuracy and turnaround time.
• Used Claude AI to streamline PowerShell and KQL script documentation, reducing time spent on manual write-ups and improving consistency across the team's operational knowledge base.
• Designed and built an AI-based cost optimization and resource management tool to analyze Azure resource utilization patterns and surface right-sizing and cost-saving recommendations across IaaS and PaaS workloads.
• Rebuilt and re-architected the underlying resource-monitoring platform to integrate AI-driven insights with Azure Monitor and Log Analytics data, improving visibility into cost trends and underutilized resources. Tech Stack: Claude AI, Azure Monitor, Log Analytics, Azure Advisor, PowerShell, KQL, Azure Cost Management IT Support Engineer Sep 2022 – Mar 2024
V-Connect Systems and Services — Noida, Uttar Pradesh, India
• Administered on-premises Active Directory environments, including user/group account management, Organizational Unit (OU) structuring, Group Policy Objects (GPO), and access provisioning across multiple client accounts.
• Supported Azure AD/Entra ID user and device onboarding, password reset workflows, and basic identity troubleshooting for hybrid client environments.
• Designed, configured, and tested enterprise hardware, networking software, and OS environments across multiple client accounts, ensuring high availability and performance standards.
• Administered VMware vSphere — scaled VM resources (vCPU, RAM, Disk) and performed cross-host VM migrations to optimize workload distribution and performance.
• Monitored multi-client infrastructure using Nagios; configured threshold-based alerts and managed escalation workflows for critical incidents.
• Managed end-to-end Azure VM lifecycle including automated shutdown scheduling, backup policy configuration, and resource cost optimization using Azure Monitor and Advisor.
• Performed VM-level and granular file/folder backup and disaster recovery operations using Azure Site Recovery (ASR) and Veeam Backup & Replication.
• Conducted regular infrastructure, cost, and security assessments for enterprise clients; resolved network, OS, and identity- related incidents through log analysis and root cause investigation. KEY ACHIEVEMENTS
• Configured hybrid identity synchronization and Conditional Access policies across on-premises Active Directory and Microsoft Entra ID, strengthening identity security posture for enterprise clients.
• Solo-delivered complete Application Gateway v2 + WAF deployment integrated with Entra ID Conditional Access — from architecture design to live production enforcement, reducing L7 attacks by 85%.
• Independently managed full CMK + PMK disk encryption rollout for enterprise environments, achieving 100% compliance ahead of the project deadline.
• Architected and configured Private Endpoints and Private DNS Zones to securely expose Azure PaaS services over private networks, eliminating public endpoint exposure.
• Built PowerShell and KQL-based operational reporting dashboards, reducing manual reporting overhead by 60% and improving real-time infrastructure and identity visibility.
• Contributed to Azure VMware Solution (AVS) hybrid workload integration, covering IaaS/PaaS configuration, NSG rule design, routing setup, and identity management with Microsoft Entra ID. EDUCATION
Bachelor of Business Administration (B.B.A.) — CGPA 7.6/10 Shri Ramswroop Memorial University, Lucknow, Uttar Pradesh LANGUAGES
English — Professional Proficiency Hindi — Native