Senior DevOps, Infrastructure & Platform Engineer - A+E Global Media
(2016-10 - 2026-08)
Built and operated the cloud and on-premises infrastructure platform for a global media company — owning platform design, enterprise deployment architecture, Kubernetes operations, IaC, CI/CD, observability, and security across AWS, Azure, and a 1,200+ node hybrid environment.
- Designed and maintained the infrastructure platform that product and engineering teams shipped on — reusable Terraform and Pulumi modules for VPC, EC2, ECS, Lambda, RDS, IAM, S3, Transit Gateway, and Direct Connect; platform abstractions that let engineers provision standardized, compliant cloud environments without becoming infrastructure experts
- Built self-service provisioning workflows through modular IaC — eliminating manual toil and enabling application teams to deploy production-equivalent environments independently; treated internal platform as a product with clear ownership and lifecycle governance
- Designed GitOps/AZURE Pipeline-driven deployment automation and CI/CD pipeline integrations — staged rollouts with health-gate validation, automated rollback triggers, and version-controlled infrastructure changes; ensured every deployment was auditable and reversible
- Led migration from Chef to Ansible across 1,200+ Linux servers — converted all configuration management to idiomatic, reusable playbooks; established fleet-wide configuration baselines and drift detection that scaled reliably as the environment grew
- Leveraged AI-assisted tooling to accelerate infrastructure code generation, runbook authoring, and operational workflow design — actively promoted team adoption of AI-driven productivity improvements across the engineering function
- Architected and operated AWS deployments inside locked-down enterprise network environments — VPC configuration, security group and NACL design, IAM permissions with least-privilege enforcement, private endpoint routing, and hybrid connectivity via Direct Connect over MPLS backbone
- Redesigned AWS network from VPC peering mesh to Transit Gateway — consolidated routing across MPLS backbone between on-premises and cloud, enforcing strict traffic boundaries between workload tiers; presented architecture and outcomes to senior leadership
- Implemented AWS Network Firewall with policy-as-code enforcement — automated security boundary management across workload tiers, decoupling internet-bound traffic from internal infrastructure and eliminating manual firewall rule management
- Designed enterprise deployment architectures supporting regulated workloads: isolated VPC topologies, data residency controls, private link patterns, and IAM delegation models suitable for customer-owned cloud environments
- Managed Kubernetes cluster operations across hybrid cloud environments — cluster provisioning and upgrades, RBAC and namespace isolation, resource quotas, CNI networking, ingress controller management, PV/PVC storage with CSI integration, and workload lifecycle management
- Operated Docker container environments at scale — image lifecycle, multi-stage build pipelines, registry management, and security-hardened runtime configurations for production deployments across hybrid infrastructure
- Deployed ephemeral, isolated compute environments using Terraform and Kubernetes namespace isolation — on-demand provisioning for development, testing, and customer sandbox use cases without impacting production systems
- Deployed and owned Datadog as the primary observability platform — custom dashboards, APM monitors, alerting policies, and SLI/SLO definitions covering Kubernetes workloads, cloud services, and on-premises infrastructure; treated monitoring, alerting, and rollback capabilities as first-class parts of every system shipped, not afterthoughts
- Integrated Splunk for unified log aggregation and SIEM alerting — compliance-grade audit trail and structured forensic capability across the full infrastructure stack; essential for incident triage in distributed environments
- Participated in on-call rotations and led incident response for complex distributed infrastructure failures — triaged compute, network, storage, and Kubernetes incidents; coordinated cross-team escalations; drove blameless post-incident reviews and implemented systemic improvements to prevent recurrence
- Authored runbooks, incident playbooks, and operational documentation — reducing meantime-to-resolution and enabling engineers to respond confidently to production alerts regardless of where the failure originated
- Deployed Wiz and Qualys for continuous cloud security posture monitoring — integrated findings into automated remediation workflows; security posture treated as an operational metric, not a point-in-time audit
- Designed and enforced IAM least-privilege access controls, RBAC policies, secrets management practices, and encryption-in-transit/at-rest across all cloud environments — consistent with enterprise compliance requirements and applied with a security-minded IaC approach
- Operated consistently within ITIL-aligned Change Control frameworks — every infrastructure change is reviewed, documented, and auditable; the discipline required to navigate enterprise customer security reviews and compliance change management processes
- Managed network segmentation and isolation across multi-tenant compute environments — enforcing strict workload boundaries and access controls across shared infrastructure running workloads for different teams and applications
Solution Architect, System Engineering - A+E Television Networks
(2005-05 - 2016-10)
Senior technical leader for enterprise infrastructure supporting mission-critical broadcast and business applications — platform governance, engineering standards, compute, storage, HA clustering, monitoring, and data protection across a 24/7 production environment.
- Defined infrastructure standards and operational practices for the engineering organization — server build standards, SAN fabric governance, monitoring requirements, and change management procedures adopted as team-wide baseline
- Deployed and governed Cisco UCS 5108 blade chassis in VMware vSphere environments — HA/DRS/vMotion, VMFS/NFS datastores, VDS networking; maintained platform lifecycle and operational readiness documentation
- Owned enterprise storage governance (HP 3PAR, EMC CLARiON, HP/Brocade SAN) and data protection strategy (EMC Avamar + Data Domain) — RPO/RTO enforcement, capacity planning, and business continuity posture for mission-critical workloads
- Implemented Zenoss and Nagios monitoring platforms — established alerting standards, service health indicators, and on-call operational playbooks; built observability capability from reactive alerting toward proactive capacity and reliability management
- Supported mission-critical back-office applications including CPO/OPE, Computron, Gabriel, and WebLogic application servers — infrastructure governance for business-critical enterprise platforms
Senior Infrastructure Administrator - Citibank N.A., Singapore - Singapore
(2004-10 - 2005-05)
Operated enterprise infrastructure in a Tier-1 banking data center serving 76 countries — high-availability systems, strict Change Control governance, compliance-driven operations, and zero-tolerance reliability standards directly applicable to AT&T enterprise platform governance.
- Administered 200+ HP-UX servers for financial processing workloads — HA cluster management, access control administration, performance diagnostics, and audit-grade change documentation; direct financial enterprise operational discipline
- Operated within rigorous IT governance frameworks — every infrastructure changes reviewed, approved, and auditable before execution; the compliance discipline and operational rigor required in large enterprise platform environments
IT Analyst - Tata Consultancy Services | State Bank of India
(2002-12 - 2004-09)
Lead architect for the greenfield central data center build of India's largest bank (6,000+ branches). Responsible for server sizing, HP Superdome SD3200/SD6400 provisioning, HP XP1024 disk array commissioning, ESL9595 tape library, SAN fabric cabling and zoning, OS deployment (Ignite-UX), Oracle Data Guard replication, MC/Service Guard HA cluster configuration, and DR site design. Implemented HP Data Protector v5, Business Copy XP, and Continuous Access XP.
Delivered a fully operational, documented data center facility under regulated financial governance — end-to-end infrastructure delivery at scale.