MUKESH KUMAR
Azure Security Architect — Microsoft Purview & Copilot Governance Microsoft Sentinel
Defender XDR Zero Trust AI Security Entra ID Microsoft Priva DLP
+91-931******* *******@*****.*** New Delhi, India. LinkedIn: https://www.linkedin.com/in/mukesh-kumar-64161418 PROFESSIONAL SUMMARY
Microsoft Cybersecurity & Solutions Architect with 21+ years in IT and over 13 years specializing in enterprise cloud security. Expert in designing, securing, and transforming complex environments using Microsoft cloud security solutions including Azure policies, DLP, sensitivity labels, data classification, defense in depth and audit configurations. Skilled in implementing Generative AI/Copilot governance integrated with Microsoft Sentinel and Defender XDR to enhance SOC visibility and resilience. Proficient in developing SOAR/Logic Apps playbooks, Sentinel analytics rules, and supporting incident triage with seamless go-live hyper care. Experienced in aligning enterprise security architecture with GDPR, SOC 2, and HIPAA compliance through Microsoft Purview controls. Recognized for delivering secure, compliant, and scalable cloud solutions that empower organizations to innovate confidently.
Microsoft Zero Trust Network Access (ZTNA)
Hands-on architected and implemented Microsoft Zero Trust Network Access (ZTNA) solutions, leveraging Microsoft Entra Private Access, Conditional Access, and Defender for Endpoint to replace legacy VPNs with identity-based, risk-adaptive access controls. ensured secure, least-privilege access across hybrid environments, integrated device compliance checks, and aligned implementations with NIST Zero Trust Architecture and regulatory frameworks such as ISO 27001, GDPR, and HIPAA.
Unified IAM governance
Enforced strict least-privilege policies across hundreds of Azure subscriptions. Deployed Entra ID Privileged Identity Management to enable Just-In- Time elevated access. Enforced strict RBAC constraints to isolate namespace resource access. Integrated legacy servers safely into cloud environments. Deployed Azure Key Vault for password rotation. Enforced key vault access policies using the Azure RBAC model to isolate secret rotation service permissions.
Microsoft Purview & Data Governance
Hands-on architecture, build, and live-tenant testing of Purview DLP policies, sensitivity labels, and data classification (SIT/EDM/classifier) across Exchange/SharePoint/OneDrive/Teams for critical applications, validating effectiveness through simulation, tuning, enforcement and reducing policy false positives
Cloud-Native Application Protection Platform (MDC) Designed to secure Azure environments with unified visibility and risk prioritization. Leveraged Microsoft defender for cloud agentless scanning to identify misconfigurations, vulnerabilities, and secrets across workloads, containers, and Kubernetes clusters. Integrated MDC with Devsecops pipelines, enabling early detection of risks in IaC templates and container images. and enforced least-privilege access policies by correlating MDC findings with IAM roles and permissions. Reduced exploitable cloud risks by 40%, Improved compliance audit success rate by 25%. Copilot & AI Governance
Standardized AI security guardrails and enabled Microsoft Defender for AI Services (prompt shield, jailbreak detection, data-poisoning alerts) across Azure OpenAI and Copilot-adjacent workloads, Integrated Microsoft Purview DSPM for AI into the control plane to gain complete tracking visibility over user prompts and responses. Enforced automated Data Loss Prevention policies directly preventing the oversharing of PII and sensitive data inside LLM prompts.
Data Lifecycle Management
Designed and enforced data retention labels across Microsoft 365 workloads, reducing compliance risks by automating document lifecycle. Configured retention schedules for emails, SharePoint, and OneDrive content, ensuring secure archiving and timely disposal of obsolete data. Reduced storage costs and Improved compliance audit success rate.
SIEM/SOAR Integration
Integrated Microsoft Purview, Entra ID, and M365 audit logs into Microsoft Sentinel; built KQL detections, analytics rules, and Logic Apps/SOAR playbooks aligned to MITRE ATT&CK for AI and Copilot-related activity, improving alert and Mean Time to Respond (MTTR). Defender XDR & Endpoint Coverage
Configured Defender XDR signals and Microsoft Defender for Endpoint (MDE) coverage supporting AI/Copilot usage monitoring, feeding unified detections into Sentinel for SOC-wide visibility.
Enterprise data privacy architecture
Utilizing Microsoft Priva, establishing automated policy baselines that mitigated cross-border data transfer risks and aligning Priva with Microsoft Purview Information Protection, Defender for Cloud, and enterprise SIEM/SOAR platforms and combining Priva Privacy Risk Management with Purview DLP to automatically detect, restrict, and encrypt exposed PII/PHI across SharePoint and OneDrive. Compliance & Regulatory Alignment
Translated GDPR, ISO27001, CIS, SOC 2, HIPAA, and DPDP requirements into technical Purview controls (audit, eDiscovery, Compliance Portal, retention/labeling), supporting audit readiness across regulated business units. Threat Modeling
Evaluated systems for data poisoning risks, securing data ingestion pipelines for fine-tuning and retrieval-augmented generation (RAG). Led comprehensive threat modeling assessments across enterprise architectures using STRIDE. Created reusable threat model templates for microservice architectures, reducing security assessment turnaround times. Analyzed complex data flows to enforce end-to-end encryption and secure transit mechanisms for sensitive data assets. Mitigated prompt injection vectors by implementing strict input sanitization boundaries, LLM firewall layers, and robust system prompt guardrails. Go-Live & Hypercare Support
Supported phased rollout of security monitoring programs by validating alert visibility, tuning detections, assisting incident triage during hyper care, and producing Security Monitoring & SIEM Integration documentation. TECHNICAL SKILLS
Microsoft Purview & Data Governance
Audit & Compliance Communication & Compliance Data Lifecycle Management DSPM Information protection Purview DLP Sensitivity Labels Data Classification (SIT, EDM) eDiscovery Information Barriers DLP Simulation Records Management I Prompt Monitoring IRM. Copilot & AI Governance
Copilot Governance Generative AI Governance Azure AI Foundry Defender for AI Services Prompt Shields Prompt Detection OWASP LLM Top 10 LLM Threat Modeling Copilot for Security. SIEM / SOAR / XDR
Microsoft Sentinel Threat Intelligence MITRE ATT&CK Data Connector SIEM Integration Defender XDR Defender for Endpoint (MDE) KQL Detections & Hunting ASIM Normalization MITRE ATT&CK Logic Apps Playbooks SOAR Incident Triage & Hypercare. Compliance & Regulatory Frameworks
ISO 27001 CIS NIST GDPR SOC 2 HIPAA DPDP Security Monitoring Documentation. Azure Identity & Security
Zero Trust Architecture M365 Entra ID Entra ID Backup Entra Id Connect Identity protection Conditional Access PIM Azure Governance
Compliance Account recovery Enterprise App IAM MFA SSO PAM RBACK Managed Identities ADFS Radius AAA Authentication Application Proxy Key Vault Managed HSM CSPM Endpoint Azure Monitor Log Analytics Defender for Cloud Defender for Identity Defender for Cloud Apps Defender for Office Security Assessment Endpoint Security EDR EPM UEBA MDM & MAM Autopilot Microsoft Priva IRM B2B B2C IDP Okta SAML Hybrid cloud Cross Tenant Synchronization Global secure access Custom domain Application Security Azure Light House MITRE Threat intelligence Threat modeling (DREAD, STRIDE, TRIKE,OCTIVE, PASTA) Attack Surface CrowdStrike
CyberArk Exposure Management SOC Optimization Defense in Depth. Additional Cloud Platform Experience
Landing Zone (CAF) Hub-and-Spoke Azure Firewall Premium Private Link DNS WAF DDoS Protection Terraform ARM PowerShell
ExpressRoute Zscaler (ZIA+ZPA) Okta AKS Security Fortinet firewall IDS/IPS Proxies NAC Site to site VPN Azure Front Door Application Gateway NSG Point to Site VPN Azure RBAC Immutable Backup ASR Veeam SAN NAS Azure Storage VNet Peering Private Endpoint AVD
Azure Policy Azure Beston Azure well architected framework CNAPP MDC Azure Policy Azure VM Azure VMSS High Availability App Service
Azure Kubernetes Service GitHub Azure Container Windows Update Management Vulnerability Management CVE Business continuity and disaster recovery Devsecops CyberArk PAM CrowdStrike RPO RTO MTD Azure SQL MySQL NoSQL Database backup and Patch Logic App SSL TLS Service Bus Azure Cashe Event Hub Function App AMA Power Automate Microsoft Copilot Studio Application Insight Azure ARC Azure lighthouse.
WORK EXPERIENCE
Microsoft Security Partner Technical Specialist, Sep 2024 – Jun 2026. Microsoft Security Architecture
Microsoft on the Payroll of Inviso Consulting Private Limited. Focus: Microsoft Security and Governance Microsoft Modern work Copilot & GenAI Security Compliance IRM Privacy Risk Management.
• Evaluated customer Cloud Security Posture Management (CSPM) and Microsoft Purview Compliance Manager to align operations with various frameworks such as ISO 27001, NIST, GDPR, CIS and HIPPA.
• Designed robust, scalable cloud and hybrid security environments, leveraging the Microsoft Purview compliance suite, Microsoft Entra
(Identity and Access Management), and Microsoft Intune suite.
• Perform information protection migrations (file/disk encryption, DLP, discovery, classification h labelling, CASB) and conduct Information Protection assessments.
• Perform vulnerability assessments, SAST/DAST scanning, and secrets management across CI/CD pipelines (GitHub Actions).
• Designed hub-spoke/VWAN network security architecture across 100 VNets using Azure Firewall Premium, UDR-based forced tunneling, and NSG/ASG segmentation; reduced direct internet breakout risk and improved network control visibility.
• Enabled Microsoft Defender for AI (Defender for Cloud – AI Services plan) to provide real-time threat protection across Azure OpenAI and Copilot-adjacent workloads; configured prompt shield monitoring, jailbreak detection, and data-poisoning alerts, integrating findings into Microsoft Sentinel for unified SOC visibility and automated response.
• Implemented Defender for Cloud across hybrid infrastructure, elevating the overall corporate secure score.
• Deployed Microsoft Defender XDR (Extended Detection and Response) to unify endpoint, identity, and application alert pipelines.,
• Architected Microsoft 365 security controls across Exchange Online, SharePoint, OneDrive, Teams, Entra ID, Defender, and Purview — including DLP, sensitivity labels/information protection, audit, and oversharing controls — reducing data leakage and oversharing risk.
• Enforced tenant-wide MFA and Password less authentication, mitigating credential-stuffing and password attacks.
• Secured enterprise generative AI pipelines using Microsoft Security Copilot and AI Foundry, reducing data exposure risks.
• Rolled out Microsoft Defender for Endpoint across workstations, utilizing automated investigation and remediation (AIR) to isolate malware.
• Collaborate with DevSecOps and engineering teams to embed security into the SDLC (shift-left approach).
• Developed unified endpoint management policies in Intune to enforce strict compliance baselines and remote-wipe compromised devices.
• Architected Azure Firewall, Network Security Groups (NSGs), and DDoS Protection layers to safeguard mission-critical web apps.
• Formulated data classification labels using Microsoft Purview, mitigating sensitive data leaks (DLP) across Teams, SharePoint, and Exchange.
• Implemented Microsoft Sentinel SIEM to ingest data logs across multi-cloud environments, reducing threat detection.
• Architected an enterprise-wide Microsoft Zero Trust strategy across multi-cloud environments, establishing explicit verification, least- privilege access, and assumed-breach controls.
• Assess and mitigate risks specific to AI/LLM workloads: prompt injection, model exfiltration, and API abuse vectors.
• Defined Azure AI/GenAI and Copilot governance security architecture for enterprise workloads by enforcing identity boundaries, private- access, least privilege, Key Vault-backed secrets, and SOC integration; mitigated high-risk findings and standardized security controls.
• Developed secure external identity and access architectures using Microsoft Entra External ID for client-facing portals, supporting secure OAuth 2.0 and SAML protocols.
• Formulated advanced automated response workflows inside Sentinel using Azure Logic Apps, lowering the Mean Time to Remediate (MTTR) critical incidents.
• Directed the enterprise-wide architecture of Microsoft Defender for Endpoint and Microsoft Intune, enforcing continuous device compliance baselines globally.
• Integrated Zscaler ZIA/ZPA with Azure Landing Zone egress architecture, onboarding 10 applications and migrating 500 users from legacy VPN to app-level access, reducing lateral movement risk.
• Enforced governance controls across modern enterprise cloud environments supporting multi-tenant AI systems using Microsoft Purview.
• Formulated global Data Loss Prevention (DLP) and Microsoft Purview Information Protection classification schemas, reducing accidental sensitive data exposure.
• Orchestrated threat intelligence operations by combining Microsoft Sentinel playbook automation with Security Copilot assistance.
• Configured Syslog, Log analytics, CEF, and cloud-to-cloud data connectors to ingest logs from critical network assets. Azure Architect, Nov 2023 - Jun 2024
Azure and Microsoft cloud Security Architecture
Alchemy Techsol India Pvt Ltd.
Focus: Microsoft Security Supply Chain Security Purview DLP Delivery OCR Security CoPilot Security Compliance Enablement
● Designed and deployed strict identity perimeters using Microsoft Entra ID (Azure AD), advanced Conditional Access policies, and phishing-resistant Multi-Factor Authentication (MFA).
● Enforced least-privilege administrative access controls by implementing Microsoft Entra Privileged Identity Management (PIM) and Just-In-Time (JIT) VM access.
● Architected secure internet-facing perimeters using Azure Firewall Premium and Azure Front Door to block malicious traffic and provide IDPS capabilities.
● Configured advanced platform security controls including Azure Disk Encryption, Azure Key Vault RBAC models, and confidential computing nodes.
● Secured multi-cloud workload identities and managed service principals, eliminating hardcoded credentials through Azure Managed Identities and Key Vault integration.
● Remediated cloud security posture gaps by analyzing Microsoft Defender for Cloud Recommendations, increasing the corporate Secure Score.
● Enforced zero-trust network isolation utilizing Virtual Networks (VNets), Network Security Groups (NSGs), and Application Security Groups (ASGs) to isolate sensitive tiers.
● Designed global web protection layers by deploying Azure Web Application Firewall (WAF) policies, mitigating OWASP Top 10 risks for public applications
● Designed secure hub-and-spoke topologies with Azure Virtual WAN, isolating corporate traffic and routing all cross-vnet communication through centralized security appliances.
● Eliminated public internet exposure for backend databases and API endpoints by implementing Azure Private Endpoints and Private Link services.
● Deployed Azure Bastion hosts across enterprise environments, enabling secure, seamless RDP/SSH administrative access without exposing public IP addresses.
● Engineered secure hybrid cloud tunnels via high-availability Azure ExpressRoute and Route Server configurations, ensuring encrypted, predictable site-to-site transit.
● Defended critical infrastructure assets against volumetric network attacks by implementing Azure DDoS Protection standard tier across public IP spaces.
● Performed migrations of legacy information protection technologies to Microsoft stack (DLP, discovery, classification & labelling, CASB).
● Streamlined network threat hunting by capturing Azure VNet Flow Logs and routing telemetry into Microsoft Sentinel for automated SIEM/SOAR incident response.
● Eliminated false positives from Nessus reports via manual verification, ensuring patching teams focused strictly on validated threats.
● Enforced strict network compliance policies at scale using Azure Policy, preventing the accidental provisioning of public IPs or unencrypted ingress routes.
● Strengthened data security during Azure landing zone migrations by incorporating Microsoft Purview Information Protection, sensitivity labeling, and DLP-aligned controls for critical applications, standardizing classification, labeling, and validation workflows across Dev/UAT/Prod; improved sensitive-data visibility.
● Improved enterprise GenAI security readiness for customers by standardizing AI security guardrails (Entra identity boundary, private access patterns, Key Vault secret handling, audit/logging into Sentinel), resulting in high-risk gaps mitigated (public exposure, over- privileged access, weak secret handling, missing audit trails).
● Implemented AI threat modelling for GenAI workloads covering prompt injection, data poisoning, model inversion, and indirect prompt attacks; mapped risks to NIST AI RMF and ISO/IEC 42001 controls to establish a Responsible AI and Copilot governance baseline.
● Hardened cloud access controls by implementing/tuning Conditional Access and privileged access principles (least privilege
+ JIT mindset), reducing credential-theft blast radius and improving admin access hygiene.
● Architected and enhanced Microsoft 365 security across Exchange Online, SharePoint, OneDrive, Teams, Entra ID, Defender, and Purview for enterprise environments, reducing data leakage and oversharing risk by 15% while improving control standardization and audit readiness.
● Supported SOC operations for enterprise customers by validating alert fidelity, tuning Sentinel use cases, and standardizing triage/escalation workflows across 10+ onboarded data sources; reduced alert noise by 15% and improved analyst readiness. IT Infrastructure Manager, Jun 2021 - Jun 2023
Microsoft Solution Architect & Cloud Security
E-Commerce Consultants Pvt. Ltd.
Focus: Cloud security IAAS PAAS SAAS SOC Visibility & Compliance Azure Network Security Purview Intune Governance.
● Designed resilient hub-and-spoke network topologies using Azure Virtual WAN and ExpressRoute, establishing secure connectivity for hybrid corporate sites.
● Authored high-level design (HLD) documentation and architectural diagrams, aligning business stakeholders and development teams on multi-region cloud strategies.
● Designed high-availability architectures utilizing Azure Traffic Manager, Front Door, and multi-region failovers, achieving an overall availability SLA.
● Spearheaded Azure FinOps initiatives, optimizing resource utilization via right-sizing, Azure Advisor, and Reserved Instances to cut monthly cloud spend.
● Engineered dynamic auto-scaling policies across App Services and Virtual Machine Scale Sets, ensuring zero latency degradation during multi-million user traffic spikes.
● Architected identity perimeters rooted in Microsoft Entra ID (Azure AD) and Conditional Access, enforcing strict Zero Trust and least- privilege principles.
● Enforced strict data protection compliance (GDPR/HIPAA/PCI-DSS) by implementing Azure Key Vault RBAC models, storage encryption, and Private Link endpoints.
● Automated resource governance compliance across subscriptions by deploying Azure Policies to prevent configuration drift and unauthorized resource SKUs.
● Administered scalable compute fleets using Azure Virtual Machines and Virtual Machine Scale Sets (VMSS), configuring auto scaling parameters to balance performance and cost.
● Managed scalable enterprise storage solutions, configuring Azure Blob Storage lifecycle management policies to automatically move stale data to archive tiers.
● Administered Azure SQL Databases, monitoring performance metrics, configuring automatic backups, and executing point-in time restores during drill scenarios.
● Created centralized operational dashboards in Azure Monitor and Log Analytics, using KQL (Kusto Query Language) to alert on infrastructure health and performance degradation.
● Designed and verified business continuity solutions using Azure Backup and Azure Site Recovery (ASR), protecting critical VMs against data loss.
● Configured and administered Microsoft Purview DLP policies, sensitivity labels, and data classification across Microsoft 365 workloads, extending Information Protection controls into the broader Microsoft 365 security and compliance posture alongside the landing zone migration program.
● Centralized SOC visibility using Microsoft Sentinel by onboarding log sources (identity, network, endpoint, cloud audit) and building baseline dashboards/queries for triage; improved investigation readiness by standardizing telemetry onboarding and ensuring consistent logging and audit coverage during migration waves.
● Integrated vulnerability and exposure findings into cloud security governance by prioritizing Defender for Cloud recommendations, internet exposure risks, misconfigurations, and remediation actions across landing zone, network, identity, and workload security baselines.
Lead Technology Consultant Aug 2020 - Jun 2021
Endpoint Security & Business Continuity
Kudzu InfoTech Pvt. Ltd.
Focus: Endpoint Security Business Continuity Performance Engineering Operational Risk & Compliance.
● Designed high-availability, fault-tolerant infrastructures using Azure Traffic Manager, Application Gateways, and Availability Zones, achieving 99.99% uptime for mission-critical client applications.
● Designed and tested business continuity and disaster recovery (BC/DR) strategies aligned with ISO 22301 standards.
● Established high-availability architectures and failover mechanisms, ensuring minimal downtime during critical incidents.
● Conducted deep-dive Azure cost optimization audits using Azure Advisor and Cost Management, saving enterprise clients an average of 25% to 30% in monthly cloud spend.
● Optimized system performance by conducting capacity planning, load testing, and tuning across cloud and on-prem environments.
● Conducted risk assessments, gap analysis, and compliance audits, ensuring adherence to regulatory requirements.
● Delivered executive dashboards and reports to leadership, providing visibility into risk posture, compliance status, and remediation progress.
● Implemented mobile device management (MDM) and mobile application management (MAM) policies to enforce compliance and protect corporate data.
● Designed and enforced conditional access policies integrated with Microsoft Entra ID, ensuring secure access based on device health and compliance status.
● Automated patching, updates, and configuration baselines through Intune, reducing vulnerabilities and improving endpoint resilience.
● Streamlined BYOD (Bring Your Own Device) adoption by applying app protection policies, balancing user productivity with data security.
● Conducted risk assessments and compliance audits using Intune reporting and analytics, aligning with ISO 27001, GDPR, and HIPAA standards.
● Reduced operational overhead by consolidating endpoint management into Intune, achieving cost savings and improved scalability.
● Secure hybrid-cloud networking topologies using Azure ExpressRoute, VPN Gateways, and Azure Hub-Spoke VNet peering to seamlessly bridge on-premises data centers with the cloud. Configured Azure compute, backup, storage, VNet, load balancers, Traffic Manager and SAML-based SSO.
● Conducted comprehensive technology assessments and maturity gap analyses for enterprise clients, delivering actionable multiyear roadmaps.
● Implemented comprehensive cloud security frameworks utilizing Azure Policy, Microsoft Defender for Cloud, and Azure Key Vault to enforce strict regulatory compliance (CIS/ISO 27001).
● Architected and deployed endpoint protection solutions using Microsoft Defender for Endpoint, ensuring advanced threat detection and response across enterprise devices.
● Automated patch management and vulnerability remediation, improving endpoint resilience and reducing exposure windows. Azure Consultant Jan 2020 - Jul 2020
Project Management & Secure Data Handling
Main Value Training & Consulting Pvt. Ltd.
Focus: Microsoft Azure Project Azure Migrated Azure security Operational Monitoring & Stability.
● Led the design and deployment of Azure cloud infrastructure, including virtual networks, storage accounts, and compute resources, ensuring scalability and high availability.
● Implemented Azure Active Directory (AAD) for identity and access management, integrating conditional access and multi-factor authentication.
● Designed and enforced Azure security policies using Defender for Cloud, Key Vault, and role-based access control (RBAC).
● Automated infrastructure provisioning with Azure Resource Manager (ARM) templates.
● Configured Azure Monitor, Log Analytics, and Application Insights to track performance, availability, and security events.
● Developed business continuity and disaster recovery (BC/DR) strategies using Azure Site Recovery and Backup, achieving near-zero downtime.
● Optimized workloads with Azure Cost Management and Advisor, reducing cloud spend by identifying unused resources and rightsizing services.
● Delivered executive dashboards and compliance reports through Azure Policy and Security Center, improving governance and audit readiness.
● Provisioned and managed high-performance Azure Virtual Machines and Virtual Machine Scale Sets (VMSS) to support fluctuating application traffic demands.
● Designed custom backup and disaster recovery plans via Azure Backup and Azure Site Recovery (ASR), successfully meeting strict client RPO and RTO metrics.
● Administered and optimized Azure SQL Databases and Cosmos DB instances, ensuring high availability, data replication, and fast query execution speeds.
● Enforced enterprise identity and access management controls using Microsoft Entra ID (formerly Azure AD), implementing Conditional Access policies and Multi-Factor Authentication (MFA).
● Secured sensitive application configurations, connection strings, and certificates using Azure Key Vault to eliminate hardcoded credentials in source code.
● Guided clients through the implementation of Azure Reserved Instances and Azure Savings Plans to optimize long-term compute expenses.
IT Manager Oct 2017 - Dec 2019
Project Management & Secure Data Handling
Marg ERP Ltd.
Focus: Microsoft Azure Administration Azure security Operational Monitoring & Stability Business continuity.
Spearheaded an organization-wide digital transformation strategy, migrating legacy operations to hybrid cloud environments ahead of schedule.
Formulated and executed the 3-year enterprise IT roadmap, aligning technology investments for corporate growth objectives.
Designed and deployed Azure solutions (VMs, storage, VNet, ASR, ASG, NSGs) focusing on high availability and auto-scaling.
Serves as the primary point of contact for external audits, successfully securing 100% compliance for ISO 27001, and GDPR.
Handled security technologies (ADFS, Entra ID, MFA, Azure Security Center, JIT, IAM, PKI) and SAML/SSO integrations.
Directs the entire corporate IT infrastructure, maintaining a 99.99% network uptime for 600 users.
Chairs monthly technical steering committees with the C-suite (CEO, CFO, CIO) to report on IT performance, risks, and ROI.
Owns and optimizes an annual operational and capital expenditure (Opex/Capex) budget, consistently tracking 5% under budget.
Conducted strict total cost of ownership (TCO) analyses for all hardware refreshes, reducing hardware capital expenditure by 18%.
Designed and executed a comprehensive corporate information security program, reducing security incidents by 60% year over-year.
Orchestrated the enterprise Incident Response Plan, establishing an incident command structure that minimized threat containment times to under 30 minutes.
Implemented a corporate Zero Trust architecture, securing remote access and enterprise endpoints for a hybrid workforce. Operations Manager Apr 2016 - Oct 2017
IT Operation Management
Main Value Training & Consulting Pvt. Ltd.
Focus: Microsoft Azure Azure security Operational Monitoring & Stability Business continuity.
Governed the enterprise ITIL framework, slashing Mean Time to Resolution (MTTR) by 35% for high-priority Tier 3 incidents.
Re-engineered the helpdesk escalation workflow, improving first-contact resolution rates by 25% and enhancing employee user satisfaction.
Chaired weekly change advisory board (CAB) reviews to evaluate risk, eliminating unauthorized production deployments and system regressions.
Automated repetitive service desk ticketing processes using advanced ITSM workflows, saving the support team 80+ manual hours weekly.
Established stringent internal Service Level Agreements (SLAs), achieving a 98.5% compliance rate across all corporate business units.
Recruited, coached, and managed a high-performing team of 20+ IT engineers, system admins, and service desk analysts.
Implemented a centralized KPI tracking matrix that boosted overall team technical productivity by 40% within 6 months.
Managed external Managed Service Providers (MSPs) and contractors, enforcing strict contract adherence and cutting vendor fees by 10%.
Enforced strict IT Asset Management (ITAM) protocols, ensuring complete lifecycle tracking for all corporate hardware and software assets.
Collaborated with cybersecurity compliance teams to pass external technical audits (CIS/ISO 27001