Open to new opportunities

Dmitriy Kerget

Cloud Network Engineer & Infrastructure Specialist

10+ years designing, deploying, and securing hybrid and cloud-native infrastructure on Microsoft Azure. I build environments that are resilient, automated, and ready for the AI era, Zero Trust by default, cost-optimized by design.

dmitriy@kerget ~
$ whoami
cloud-engineer, azure-specialist, iac-architect
──────────────────────────
$ skills --top
Azure · Terraform · Zero Trust · Entra ID · Sentinel
──────────────────────────
$ status
available_for_hire=true && open_to_consulting=true
// 01 — About

Cloud engineer who builds infrastructure others rely on

My IT journey began in 2007 as a network administrator — working in budget-tight environments wearing many hats, securing systems without room for mistakes. That pressure shaped how I think: understand every layer, secure from day one, automate everything repeatable.

Over the years I've focused on Azure infrastructure, identity, governance, and increasingly on AI-powered operations. Most recently I supported Alcoholics Anonymous through cloud transitions in mission-critical environments where uptime and security aren't optional.

Today I help organizations cut through cloud complexity: clean architecture, Zero Trust security, IaC-driven consistency, and practical AI adoption, whether that's Microsoft Copilot, Azure OpenAI, or the agentic AI patterns emerging now.

10+
Years in IT
28%
Cloud cost reduction achieved
Azure
Primary platform
SMB+
Enterprise-grade for any size

> Core expertise

  • Azure Infrastructure & Security (Defender for Cloud)
  • Hybrid Networking, VPN, ExpressRoute, NSGs, Private Link
  • Infrastructure as Code, Terraform, Bicep, GitHub Actions
  • Identity & Access, Entra ID, SSO, Conditional Access
  • Automation, PowerShell, Azure CLI, Logic Apps
  • Governance & Compliance, Azure Policy, Blueprints, Purview
  • Monitoring & IR, Azure Monitor, Log Analytics, Sentinel
  • AI-Powered Cloud Ops, Azure OpenAI, Copilot, Cost Advisor
  • DevSecOps, GitHub Advanced Security, Defender for DevOps
  • Backup & DR, Azure Backu, ASR, GRS, Cross-Region Failover
// 02 — Skills & Stack

Technical proficiency

Technologies and platforms I work with daily across cloud, security, and automation.

AZ
104
Microsoft Azure Administrator
AZ-104 — in progress
AZ
500
Microsoft Azure Security Engineer
AZ-500 — planned
Cloud Platform
Microsoft Azure Azure AD / Entra ID Azure Monitor Azure Sentinel Azure Functions Azure OpenAI Log Analytics
Infrastructure as Code
Terraform Bicep GitHub Actions ARM Templates PowerShell Azure CLI
Security & Identity
Zero Trust Conditional Access MFA / SSO Defender for Cloud Microsoft Intune Purview
Networking
VPN Gateway ExpressRoute NSGs Private Link Azure Firewall DNS
AI & Modern Tech
Microsoft Copilot Azure OpenAI Security Copilot M365 Copilot Fabric API Management
Governance & Compliance
Azure Policy Blueprints Policy-as-Code Cost Management Azure Advisor
// 03 — Projects

Featured work

Real-world infrastructure projects demonstrating secure, cost-effective Azure solutions.

PROJECT_01

Hybrid Azure Infrastructure Deployment

Designed and deployed a hybrid environment for a mid-sized enterprise, enabling seamless integration of on-prem infrastructure with Microsoft Azure using VPN Gateway and Entra ID Connect. Focused on authentication continuity, scalability, and minimal migration downtime.

Seamless hybrid identity & network integration
AzureVPN GatewayEntra IDPowerShell
PROJECT_02

IaC Cost Optimization with Terraform

Built reusable Terraform modules to automate Azure infrastructure provisioning end-to-end. Implemented autoscaling policies and reserved instance planning to eliminate waste. Reduced monthly cloud spend by 28% while improving deployment consistency and repeatability.

28% monthly cost reduction achieved
TerraformAzure MonitorGitHub ActionsIaC
PROJECT_03

Zero Trust Security Implementation

Implemented Conditional Access policies, MFA, and identity-based segmentation across Microsoft 365 and Azure. Hardened infrastructure using Defender for Cloud and Microsoft Sentinel for threat detection and automated incident response workflows.

Full Zero Trust posture — identity to workload
Entra IDDefenderSentinelIntune
PROJECT_04

SMB Cloud Onboarding Framework

Building reusable cloud onboarding frameworks for small and mid-sized businesses. Templates covering secure baseline configuration, identity setup, cost governance, and Microsoft 365 integration — designed for fast-paced environments with lean IT teams.

Repeatable, secure cloud entry for SMBs
TerraformAzure PolicyM365Governance
// 04 — Contact

Let's build something secure

Available for full-time roles, consulting engagements, and freelance cloud projects. If you're looking for a senior Azure engineer who can own infrastructure from design to delivery — I'd love to connect.