Tuamene Tenalo
Solution Architect | Security Engineer
Experience
Solution Architect | Security Engineer
CLOUDWARE
- Engineered network segmentation and load balancing using NGINX and F5, ensuring traffic resilience, eliminating bottlenecks, and maintaining 99.98% uptime across enterprise environments.
- Architected secure multi-tenant Azure infrastructure (AKS, Key Vault, Sentinel, Defender) while ensuring compliance with NIST, ISO 27001, CIS, and SOC 2 standards across regions.
- Automated Azure-native CI/CD pipelines using Jenkins, GitLab CI/CD, and GitHub Actions, enabling seamless integration, faster release cycles, and reducing deployment failures by 60%.
- Led containerized security modernization using AKS and Azure Container Registry integrated with Docker and Kubernetes Operators, improving orchestration efficiency and reducing manual patching efforts across clusters.
- Enhanced endpoint defense posture through Microsoft Defender for Endpoint and CrowdStrike, achieving zero critical breaches in two consecutive years.
- Directed cross-functional collaboration between Azure infrastructure, DevOps, and security teams to align modernization roadmaps, optimize governance, and accelerate delivery goals.
- Developed monitoring and alerting mechanisms using Azure Monitor, Application Insights, and ServiceNow ITOM, enabling proactive remediation and predictive capacity planning.
- Integrated Azure Key Vault and API Gateway for centralized secret management, reducing token misuse by 70% and improving API access control and data governance.
- Championed continuous improvement and risk mitigation frameworks within agile sprints to enhance process transparency and drive consistent value delivery.
- Mentored six engineers on Azure DevSecOps practices, fostering knowledge-sharing, developing leadership pipelines, and reducing onboarding time by 35%.
- Implemented SOAR automation using Sentinel playbooks and Cortex XSOAR, reducing mean time to detect by 45% and mean time to respond by 55%.
Global Infrastructure Architect & Security Modernization
Reliance Infosystems Limited
- Designed and implemented a highly scalable and cost-effective Azure based architecture for a high traffic customer facing application, resulting in a 30% reduction in infrastructure cost.
- Implemented CIS benchmark compliance for Azure subscriptions and resources to harden configurations, standardize baselines, and improve overall security posture through automated auditing.
- Established Azure Monitor and Log Analytics–driven observability integrated with Grafana and Prometheus to enhance incident visibility, reduce false positives, and strengthen service reliability.
- Drove enterprise-wide Zero Trust Architecture adoption using Azure AD Conditional Access, Defender for Cloud, and Palo Alto integration, strengthening access control, improving data integrity, and reducing unauthorized access incidents by 40%.
- Designed and implemented Hybrid & Multi-Cloud Architecture prioritizing Azure (AKS, Key Vault, Sentinel, Policy, Blueprints) while leveraging AWS for specific workloads, achieving 30% greater efficiency and 25% cost savings.
- Engineered and deployed a virtualization solution using Hypervisor/VMware, consolidating server resources and reducing hardware costs by 20%.
- Collaborated with software developers to identify and address recurring software bugs, leading to a 25% reduction in customer-reported issues.
- Implemented a robust backup and recovery system, reducing data loss risks and streamlining the restoration process in case of hardware or regional failure.
Cloud Security Engineer
Microsoft Nigeria
- Automated Azure Resource Manager (ARM) templates and AWS CloudFormation to standardize infrastructure builds, ensure version-controlled provisioning, and maintain zero-drift environments.
- Built secure data platforms on Azure and GCP (GKE, Compute Engine, IAM), achieving 99.99% uptime while optimizing compute costs by 20% through right-sizing and auto-scaling policies.
- Designed and enforced Azure vulnerability management using Qualys and Tenable, reducing open vulnerabilities by 60% in the first year.
- Managed Azure VPN Gateway and SD-WAN integrations to enhance remote connectivity and performance consistency across global networks.
- Orchestrated Azure Files and Blob Storage upgrades, improving data throughput by 40% and enhancing redundancy for mission-critical workloads.
- Developed PowerShell and Bash scripts leveraging Azure CLI and Graph API for compliance reporting, saving over 200 engineer-hours per quarter.
- Integrated Azure Monitor and Datadog for hybrid observability, optimizing root-cause analysis and reducing incident resolution time.
- Streamlined collaboration workflows using Jira, Confluence, and Trello, improving visibility, reducing handoff delays, and fostering accountability.
- Supported Agile/Scrum transitions and aligned Azure DevSecOps operations with ITIL practices to maintain flexibility and compliance.
- Created Azure dashboards in Power BI and Sentinel to visualize compliance posture, incident trends, and risk metrics for leadership visibility.
System Engineer
Invar Technologies
- Managed Azure Active Directory, DNS, TCP/IP, and on-prem Active Directory environments to optimize identity security and internal communication flows.
- Designed Azure CDN and Cloudflare solutions, improving content delivery by 45% and reducing latency globally.
- Administered VMware, OpenStack, and Azure virtual environments, providing highly available virtualization services with 99.95% uptime.
- Deployed Fortinet firewalls and Azure Key Vault encryption to enhance data confidentiality and compliance readiness.
- Conducted capacity planning and infrastructure audits to anticipate Azure workload growth and ensure proactive scalability.
- Established ServiceNow workflows for incident management and change control, reducing SLA breaches by 25%.
- Facilitated strategic planning and problem-solving sessions aligning Azure adoption strategies with business goals.
- Mentored four junior engineers to build operational excellence, increasing technical acumen and fostering collaboration.
Summary
Global Infrastructure Architect & Azure Security Modernization Expert with over 10 years of experience designing, securing, and optimizing enterprise-scale hybrid and multi-cloud environments—specializing in Microsoft Azure with cross-platform expertise across AWS and GCP. Proven success architecting Zero Trust, identity-driven security, and compliance frameworks while leading large-scale migrations, IaC automation, and observability implementations. Skilled in Azure-native security controls (Sentinel, Defender, Key Vault, Security Center), infrastructure automation using Terraform, Ansible, and CI/CD pipelines, and CIS/NIST benchmark compliance. Adept at driving modernization initiatives, implementing end-to-end governance, and aligning infrastructure strategies with organizational goals to enhance scalability, resilience, and compliance in global enterprises.
Skills
- Cloud & Infrastructure: Azure (Aks, Key Vault, Sentinel, Defender, Security Center, Policy, Blueprint, Arc), Aws (Ec2, S3, Eks, Iam, Cloudformation), Gcp (Gke, Compute Engine, Iam), Vmware, Openstack, Hybrid & Multi-cloud Architecture, Cloud Cost Optimization
- Security & Compliance: Zero Trust Architecture, Azure Sentinel, Defender For Cloud, Microsoft Purview, Siem (Splunk, Sentinel), Soar (Cortex Xsoar), Iam (Azure Ad, Okta, Ping Identity), Firewalls (Palo Alto, Fortinet), Vulnerability Management (Qualys, Tenable), Compliance (Nist, Iso 27001, Cis, Soc 2), Encryption (Kms, Key Vault, Hsm)
- Infrastructure As Code (Iac) & Automation: Terraform, Ansible, Azure Bicep, Arm Templates, Aws Cloudformation, Puppet, Jenkins, Gitlab Ci/cd, Github Actions, Powershell, Bash, Kubernetes Operators
- Networking & System Architecture: Azure Networking (Vnet, Nsg, Application Gateway, Firewall), Dns, Tcp/ip, Vpn, Sd-wan, Load Balancing (F5, Nginx), Network Segmentation, Cdn (Cloudflare), Storage Systems (Nas, San), Linux/unix Administration, Active Directory
- Monitoring & Observability: Azure Monitor, Log Analytics, Application Insights, Sentinel Dashboards, Prometheus, Grafana, Datadog, Splunk, Cloudwatch, Servicenow Itom, Capacity Planning
- Collaboration & Devops Tools: Jira, Confluence, Servicenow, Trello, Slack, Git, Nexus, Sonarqube, Docker, Kubernetes, Vault, Api Gateway
- Leadership & Soft Skills: Strategic Planning, Cross-functional Collaboration, Stakeholder Engagement, Risk Mitigation, Communication & Presentation, Mentorship, Agile/scrum, Itil Practices, Problem Solving, Continuous Improvement
Languages
Education
Rivers State University
Bachelor of Science, Computer Science & IT · Computer Science & IT · Port Harcourt, Nigeria
Certifications & licenses
AWS Certified DevOps Engineer – Professional
MCSE | MCSA
Microsoft Certified: Azure Administrator Associate (AZ-104)
Microsoft Certified: Azure Fundamentals (AZ-900)
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
Microsoft Certified: DevOps Engineer Expert (AZ-400)
Similar Freelancers
Discover other experts with similar qualifications and experience