Open to DevOps / Platform roles

Hi, I'mTarun

>DevOps & Cloud Engineer

DevOps & Cloud Engineer working in Azure, AWS, and Kubernetes. I build zero-trust landing zones, CI/CD pipelines, and observability stacks for regulated environments.

GitHubLinkedInDelhi, India
tarun@infra — zsh
$
TG
01impact

Measured outcomes

Numbers from production systems I own end to end — not estimates.

86%
p99 latency cut

API response times across client workloads

80%
lead time cut

Commit to production on OIDC-federated pipelines

65%
MTTR cut

Mean time to recovery on managed environments

100%
VAPT closure

Findings closed on the first re-test

02about

What I actually do

I'm the sole DevOps and cloud engineer at NirJai Technologies, where I own architecture, security, and delivery across 9 client engagements in healthcare, pharma, fintech, and IoT. Most of the work is Azure and AWS: zero-public-IP landing zones written in Bicep, AKS microservices shipped with Helm on OIDC-federated pipelines, and Zero-Trust hardening that has closed 100% of VAPT findings on the first re-test. Along the way I've cut p99 API latency by 86%, commit-to-production lead time by 80%, MTTR by 65%, and logging costs by 80%.

Based in
Delhi, India
Currently
DevOps Engineer @ NirJai
Engagements
9 delivered · 3 active
Focus
Zero-Trust & DevSecOps
03stack

Core technologies

The tools I reach for daily across cloud, orchestration, infrastructure-as-code, and application work.

Azure (AKS, ASE v3)
AWS (EC2, RDS, VPC)
Kubernetes
Docker Compose
TerraformTerraform & Bicep
LinuxLinux & Windows Server
NginxNginx
PostgreSQL
Python
C#
GitHubCI/CD & GitOps
Zero-Trust Security
React
Next.js
04work

Experience

NirJai Technologies Pvt. Ltd.
NirJai Technologies Pvt. Ltd.
DevOps Engineer
Delhi, India
CurrentMarch 2025Present

Sole DevOps and cloud engineer, owning architecture, security, and delivery for 9 engagements (3 active) across regulated Azure and AWS environments in healthcare, pharma, fintech, and IoT. Design zero-public-IP Azure landing zones in Bicep and CloudFormation, ship Kubernetes (AKS) microservices via Helm on OIDC-federated CI/CD pipelines, and enforce DevSecOps and Zero-Trust hardening. Headline results across the portfolio: p99 latency down 86%, lead time down 80%, MTTR down 65%, logging cost down 80%, observability spend down 45%, and 100% VAPT closure on first re-test.

05projects

Infrastructure I've shipped

Nine client engagements across healthcare, pharma, fintech, and IoT.

Drifting — swipe to take it yourselfAll 9 projects, filterable

Solutions architect and DevOps lead for an edge-compute AI surveillance platform sustaining 99.9% uptime across 21 live telemetry feeds over 90+ days, after GPU benchmarking and provisioning NVIDIA RTX 4000 servers and PtP/PtMP wireless networks. Runs YOLOv8/TensorRT inference engines with PostgreSQL and MediaMTX (RTSP/RTMP) containerized in Docker Compose, with Zero-Trust enforced through a split-tunnelled WireGuard VPN, strict egress, and Pi-hole DNS sinkholes.

Case study
Docker Compose
YOLOv8
TensorRT
PostgreSQL
MediaMTX
+4

Codified a zero-public-IP Azure landing zone in Bicep (4 zoned subnets, deny-all NSGs, Private Endpoints), eliminating 100% of standing credentials and reducing the attack surface to 0 reachable public assets, validated by Microsoft Defender. Operates an OIDC-federated GitOps pipeline promoting SHA-tagged containers across 30+ deployments a month. Migrated 2.8 TB of on-prem SharePoint data to M365 with 0 data loss using a throttling-aware, multi-threaded Python engine (MSAL, REST APIs) that recovers gracefully from 429/503 tenant responses, alongside MuleSoft API and Intune MDM integration.

Case study
Azure
Bicep
Private Endpoints
NSGs
GitOps
+6

Resolved 26 security-audit findings across 37 endpoints and servers by architecting a default-deny WireGuard VPN, deploying Wazuh SIEM, and automating UFW and Bash rules with Ansible for SSH GeoIP anomaly blocking. Cut release cycles 73% (45 to 12 minutes) across 6+ production apps by standardizing Jenkins and GitHub Actions pipelines with SonarQube quality gates, tuning Linux kernels via sysctl, and engineering Restic encrypted backups.

Case study
WireGuard
Wazuh SIEM
Ansible
UFW
Jenkins
+5

Led an ELT-over-ETL data platform scaling to 24.7M time-series records, designing a resilient 3-tier PostgreSQL warehouse with star-schema modelling across 10+ sources, building delta-load transformers, and managing a Next.js/Plotly monorepo. Reached 99.9% execution success on data-acquisition pipelines by orchestrating headless-browser automation (Selenium/Chromium) through multi-profile Docker Compose and running 19+ idempotent SQL migrations.

Case study
PostgreSQL
Python
Docker Compose
Selenium
Chromium
+3

Reduced commit-to-production lead time 80% for an AI algorithmic-trading platform by orchestrating a React/C#/Python microservices stack on Azure Kubernetes Service with Helm templates and Azure Pipelines. Engineered horizontal scalability with HPA autoscaling and namespace-scoped RBAC, configured Kubernetes CronJobs for Apache Arrow Flight workloads, and deployed cache-busted Docker builds via Azure Container Registry.

Case study
Azure Kubernetes Service
Helm
Azure Pipelines
Azure Container Registry
HPA Autoscaling
+5

Cut logging-infrastructure costs 80% and removed cluster overhead for 5 GB/day of logs by retiring Elasticsearch and building a lightweight full-text search and trace-correlation engine on SQLite FTS5 and FastAPI. Achieved a validated 24-hour RPO and 2-hour RTO for Supabase/PostgreSQL through a nightly automated dump-and-restore pipeline that strictly verifies schema, role, and sequence integrity.

Case study
SQLite FTS5
FastAPI
Python
Supabase
PostgreSQL
+2

Reduced p99 API latency 86% (850 to 120 ms) for a healthcare ecosystem by migrating .NET and SQL microservices into a single-tenant Azure App Service Environment (ASE v3) behind Front Door, WAF, and APIM, guided by KQL telemetry. Closed 100% of VAPT findings on the first re-test by mitigating LUCKY13 CBC timing attacks with TLS 1.3, enforcing HSTS, centralizing secrets in Key Vault, and provisioning Mirth Connect with Azure Data Factory SSIS.

Case study
Azure ASE v3
Azure Front Door
WAF
APIM
Key Vault
+6

Drove MTTR down 65% by engineering a proactive, self-healing observability pipeline that uses CloudWatch telemetry to trigger SNS alerts and event-driven Lambda functions for automated EC2 remediation. Achieved a sub-5-minute RPO in live recovery drills by architecting a highly available multi-tier AWS environment with parameterized CloudFormation, least-privilege IAM, and isolated RDS with point-in-time recovery.

Case study
AWS
CloudFormation
Lambda
CloudWatch
SNS
+4

Trimmed cloud observability spend 45% and drove MTTD down to 2 minutes by replacing Azure Application Insights with a self-hosted ELK, Prometheus, and Grafana stack, including custom C# Serilog middleware for the Elastic APM cutover. Accelerated BI releases from 2 hours to under 10 minutes with modular Jenkins declarative pipelines, Apache Superset provisioning, and a custom Python CLI that promotes dashboards with zero standing credentials.

Case study
ELK Stack
Prometheus
Grafana
Elastic APM
Serilog
+4
07recognition

Academic & foundational work

Before specializing in cloud infrastructure, I built a strong core engineering foundation — published research on electromagnetic reactive power, won national robotics championships, and gained exposure to large-scale grid management at India's premier electricity authorities.

  1. Pseudo-Static Electromagnetic Reactive Power Compensator

    Publication: IEEMA Journal

    Published research on a pseudo-static electromagnetic approach to reactive power compensation.

  2. 2nd Prize — GGSIPU Inter-College Major Project Competition

    GGSIPU, Delhi

    Runner-up across GGSIPU colleges for the final-year engineering major project.

  3. 1st Place, North Zone — Robo-Mania National Robotics Championship

    Delhi Technological University (DTU)

    Won the North Zone round of the national robotics championship hosted at DTU.

  4. Engineering Intern

    Central Electricity Authority of India (CEA)

    Completed a foundational engineering internship at the CEA, a premier institute of national importance, gaining exposure to national power infrastructure standards.

  5. Engineering Intern

    Northern Regional Load Dispatch Center (NRLDC)

    Engaged in technical training and observation at NRLDC, gaining early exposure to large-scale power grid management and telemetry.

08contact

Let's build something reliable

Want to talk cloud architecture, infrastructure scaling, or DevOps? I respond to every technical inquiry.