Personal Summary
Accomplished IT Architect with hands-on experience since 2005, former Microsoft employee, leading in delivering international flagship projects for Core Infrastructure since 2011, and specializing in Azure Cloud since 2015.
[see my rich history of projects for more details on my roles, technologies, and project scales]
I help global enterprise-scale customers on their cloud adoption journey by designing and implementing effective, reliable, scalable, and secure solutions.
Typical roles: Technical / Cloud / Platform / Infrastructure / Systems / Solution Architect, Consultant, DevOps Team Lead
Experience level: Senior Manager
Competencies:
Non-technical
- Estimating, planning, and delivering complex, large-scale projects
- Building trusted relationships with customer technical teams up to C-level
- Technical leadership, interviewing, hiring, and developing project team members
- Collaborating productively with external teams, partners, and vendors
Azure Infrastructure Solutions
- architecture patterns and practices [well-architected & cloud adoption framework, agile, DevSecOps, SDLC]
- governance [landing zones, role model, naming, policies]
- compute [virtual machines, scale sets, big compute, HPC, auto-scaling]
- advanced networking [ExpressRoute, VPN, routing topologies, VWAN, high availability]
- network security [firewalls, NVA, NSG, DMZ, segmentation, zero trust]
- management & automation [ARM, Bicep, Terraform, PowerShell, Bash, DSC, CI/CD, DevOps tools]
- operational & security monitoring [Log Analytics, Sentinel]
- identity & access management [Azure AD, ADFS, hybrid AD integration, RBAC, conditional access]
- backup & disaster recovery [IaaS, PaaS, BCDR, SLA, SLO]
- datacenter migration [Azure Migrate]
- advanced workloads [Azure Virtual Desktop (AVD), Azure Kubernetes Service (AKS), SAP HANA]
Legacy Technical Acumen
Core Infrastructure Solutions based on Windows Server and Linux [AD/DNS & supporting services, Failover & HA Clusters, File & Print Services, SQL Server clustering]
Server and Presentation Virtualization: networking, management, high availability, site resiliency, scalability, deployment, migration, and hardware sizing [Hyper-V, IaaS solutions, Remote Desktop Services]
Network Infrastructure: network devices & services, routing, and remote access [Windows Server components, firewalls, network virtual appliances & hardware]
Unified communications: messaging, voice & video, and conferencing [Lync, Exchange]
Hardware: server and storage sizing, configuration, diagnostics, and servicing [HP, IBM, …]
Location
Region: London Area
Work Experience
Technical leadership in lighthouse Azure Infrastructure projects.
Customer-facing: gathering requirements, delivering design workshops, handling technical discussions, presenting solutions, and serving as a trusted advisor up to the CTO.
Internally: ensuring system designs and implementations meet requirements; maintaining integrity, scalability, and security; keeping team spirit levels high.
Business development: pre-sales, responding to RFP and RFI, suggesting project team compositions, contributing to solution accelerators, learning, and development materials.
[refer to my project history for details]
Provided technical leadership in enterprise-scale Cloud Infrastructure projects across Europe.
Delivered the largest Core Infrastructure projects in the CEE region, from pre-sale to customer handover.
Pre-sales, planning, designing, and implementing IT infra projects for medium companies.
[typical projects: server infrastructure, virtualization with high availability, Exchange, and Lync]
Designed, implemented, and maintained the whole IT infra of a medium-sized company.
[100+ workstations, 20+ servers, VoIP, IP-cameras, active network devices]
Administered the IT infra of the biggest chemical factory in the region. Developed a real-time monitoring solution for a production process.
Education
- Over 40 industry-recognized Microsoft certifications since 2008
- Including Azure Cloud, Hybrid + Core Infrastructure, and Linux. For details visit mcp.irom.info
Awards
References
Igor was the lead solution architect (I was the customer) on the project where we broke ground with an innovative solution to a business problem.
Igor was able to deliver an advanced technical solution which was performant and stable which the client used as a leap board to mass cloud migration. He also ensured that when he left the project there was sufficient skills in the team to maintain and develop the solution going forward.
I recommend Igor without reservation
Igor is the best consultant I have ever worked with. He brings competence, knowledge and calm to complex projects and situations. His ability to clearly communicate with customers, his field experience and his technical expertise are just exceptional. Bring him to your team and he will make you successful. I highly recommend him for any technical leadership roles.
Publications
Projects
Role: Cloud Platform Architect for Networking
As a member of the Critical Cloud Infrastructure team, I focused on the Adoption of Azure Virtual WAN. Duties included advising on Azure Virtual WAN architecture, multi-regional traffic routing with 3 ExpressRoute Direct locations, migrating from traditional Hub-and-Spoke model, quality testing, monitoring, and collaborating with Microsoft for quality assurance. Developed scripts for network connectivity testing during migrations and contributed to IaC codebase for operational monitoring setup. During migrations, served as networking SRE, conducting live testing and status monitoring to minimize business disruption.
Keywords: High-security environment, Infrastructure as Code, quality gates, GitLab, Jira + Confluence, Containerized Deployment Agents, VS Code, PowerShell, REST API, custom Python solution for IaC deployment, ARM, Bicep, Terraform, Git.
Role: Systems Architect for Azure Infrastructure Design
Worked as a member of the CCoE team of technology area architects on enabling cloud capabilities for migration of existing assets and new workloads.
Keywords: Design reviews and advisory, knowledge transfer, POCs, landing zones structure, Citrix ADC/NetScaler, storage, backup databases, supporting new deployments and migrations.
Role: Role: Systems Architect for Azure Landing Zone Design
Provided tech leadership for designing and implementing Landing Zones for the future migrations of customer applications. Contributed to assessing existing customer portfolio, planning future datacenter migration, and establishing CCoE. Worked with a diverse team of 10+ tech folks on the EPAM side and 20+ on the Customer side.
Keywords: Keywords: multi-regional hub-and-spoke networking with core and extranet NVAs, Landing Zones design adopting and reworking Microsoft reference architecture, deployment automation with Terraform, deployment and integration with Azure China Soverign Cloud, designing Cloud Center of Excellence for customer.
Highlights: Business impact: Landing Zones design and implementation, along with establishing migration procedures enabled the biggest migration project for EPAM, eventually receiving 'Azure Migration Partner of the Year' award from Microsoft
Role: Stream Lead for Advanced Networking Design
Contributed to the design of a highly complex network solution in Azure Cloud which includes multiple routing domains encapsulation on the same redundant ExpressRoute circuits.
Keywords: ExpressRoute redundancy, Arista and Palo Alto NVAs, F5 load balancers, VXLAN, Kubernetes, CNI, Calico.
Role: Lead consultant
Planned and executed a Proof of Concept for various scenarios of virtual machine migrations with the Azure Migrate tool in a highly tight network security environment.
Keywords: Azure Migrate, private endpoints, availability zones, agentless & agent base discovery and migration, Windows, Linux.
Role: Lead consultant for Azure Infrastructure
Designed and delivered core infrastructure and landing zones for the future migrations of bank's applications.
Keywords: advanced hub-and-spoke networking with core and extranet NVAs, ExpressRoute private & Microsoft peerings with redundancy, governance with Enterprise-Scale, monitoring with Log Analytics, high security standards and compliance with policies and regulatory certifications, deployment automation with ARM and Terraform. Work alongside Modern Service Management and Windows Virtual Desktop teams of MCS.
Highlights: Business impact: enabling customer's migration to Azure cloud and future projects for MCS. Contributed to customer commitment for $27M Azure consumption over 3 years, the biggest contract in the area.
Role: Lead consultant for Azure Infrastructure
Primed by Microsoft Consulting Services and working alongside SAP specialist partner, we have been delivering a 12-month project to migrate the entire company's SAP estate of 17 different landscapes and over 100 physical servers from IBM AIX & Oracle to Windows, SQL Server & SAP HANA on Azure.
Keywords: SAP, HANA, IBM AIX, Oracle, Windows, SQL Server, Linux, giant size Azure Virtual Machines (Mv2), Backup, Site Recovery, High Availability with Load Balancers, Pacemaker and secondary regions, Log Analytics monitoring, NetApp files, ExpressRoute, Hub and Spoke networking, deployment automation, security, governance, and compliance.
Highlights: Business impact: successful migration of a complex, 10k+ cores estate of business applications with little downtime and no business interruption, over 50% of performance improvements, significant improvement in reliability, decreased over-head, increased manageability, reduced costs for Diageo and strong services and Azure revenue for Microsoft.
Role: Lead consultant for Azure Infrastructure
Designed and built a greenfield Azure Infrastructure to provide the Minimum Viable Product to start lift-and-shift migrations from the legacy environments. Worked on a tight schedule in Agile style using the DevOps tools.
Keywords: Azure DevOps, CI/CD, deployment automation via pipelines, Git repos, product documentation in wiki, working with backlog, subscriptions and management model, naming, resource policies, advanced networking (ExpressRoute, Hub-Spoke topology, Fortinet NVA), advanced ARM templates with conditional deployments, provisioning Windows/Linux VMs with custom scripts, monitoring and logging with Log Analytics, storing secrets in KeyVault, compliance with Security Center recommendations.
Highlights: Business impact: built a platform to host potentially ~10000 cores of compute resources. The first project at MCS to use the DevOps approach, and it became a baseline for future offerings called Hybrid Cloud Foundation and Azure Cloud Foundation, which eventually evolved into Azure Cloud Adoption Framework
Role: Lead consultant for Azure Infrastructure
Designed and built the Azure Infrastructure to provide the base for lift-and-shift migration of existing on-premises services for a government organization.
Keywords: subscriptions and management model, naming, resource policies, multiple regions, advanced networking (VPN, ExpressRoute, Hub-Spoke topology, Fortinet NVA), deployment automation
Highlights: Business impact: built a platform to host potentially ~5000 cores of compute resources.
Role: Lead consultant for Azure Networking
Designed and built advanced hub-spoke network infrastructure in Azure cloud to provide the base for lift-and-shift migration of existing on-premises services.
Keywords: ExpressRoute, multiple regions, advanced routing, BGP, Palo Alto NVA, NSGs, application isolation with ASGs, thousands of VNets/Subnets, automation with PowerShell /ARM templates.
Highlights: Business impact: built a platform to host potentially ~10000 cores of compute resources
Role: Lead consultant for Azure Infrastructure
Assisted in designing core infrastructure on Azure for moving the line-of-business applications.
Keywords: heavy multi-tier LOB application on-premise, multiple environments, CI/CD processes, networking, traffic filtering and publishing, governance, logging and monitoring, migration of existing on-premise parts to PaaS.
Role: Lead consultant for Azure Infrastructure
Planned, designed, and implemented Azure infrastructure and migration approach to move a global grid computing system to Azure cloud.
Keywords: 33k cores in scale sets (Linux), 6 regions, ExpressRoute and global peerings, integration with globally distributed on-premise infra, deployment automation with PowerShell, Linux configuration with BASH, designing and automated building of highly loaded and highly available NFS clusters based on Red Hat, compliance with security regulations. Dealing with technical challenges only visible at the highest scale in the Azure Cloud. Tight collaboration with account and engineering teams at MS.
Highlights: Business impact: 33000+ cores of compute consumption for at least 3 years. Largest grid computing deployment in the Azure cloud today. A successful business case to drive future (even bigger!) sales of Azure to the customer
Role: Lead consultant for Azure Infrastructure
Delivered on-site workshops and documentation for the architecture design of the Azure cloud platform.
Keywords: Subscriptions model and governance, naming, advanced networking (Hub and Spoke + NVA), compute, monitoring, and automation.
Role: Lead consultant for Azure Infrastructure
Built PoC for migration of a grid computing system based on Linux
Keywords: Up to 8k cores in scale sets (Red Hat Linux), 2 regions, deployment automation with PowerShell and Bash, Linux OS fine-tuning and troubleshooting. Sizing and tuning of shared storage solution on NFS servers, load tests with the very tight schedule to save on resource costs, performance analysis of scale set VMs of different sizes with OMS.
Highlights: Business impact: PoC was successful, unblocking the sales of a 3-year contract for 33000+ cores consumption, and production migration of the system (see other projects in this list)
https://news.microsoft.com/2017/04/26/ubs-taps-microsoft-cloud-power-business-critical-tech/
Role: Lead consultant for Azure Infrastructure
Planned, designed, and implemented the migration of a distributed grid computing system to Azure Cloud.
Keywords: 15k cores in scale sets (Windows), ExpressRoute, integration with on-premise infra, deployment automation with custom scripts, monitoring with OMS, role-based access control, compliance with security regulations. Tight collaboration with account and engineering teams at MS.
Highlights: Business impact: 15000 compute cores of consumption for at least 3 years. Largest grid computing system deployment in Azure at that date. Continued to work with the customer on PoC for migration of the even larger system (see other projects in this list)
Role: Consultant for Azure Infrastructure
Designed, piloted, and implemented the cloud platform based on Azure infrastructure in the German Cloud for the 'Digital Future' project.
Keywords: Advanced networking with Fortinet NVAs, UDRs, NSGs, load balancing, on-premise integration with BGP, multiple sites. Automation of resource deployment (IaaS, PaaS). Migration between Azure Cloud and Azure Germany.
Role: Consultant for Cloud Services
Conducted a PoC for Cloud Services integration using SSO with ADFS and Directory Sync.
Keywords: Azure AD, ADFS, Directory Sync
Role: Consultant for Directory and Messaging Services
Developed a conceptual architecture of target directory and messaging services, implemented a pilot migration, and proposed a staged plan for mass migration.
Keywords: Active Directory, Exchange, conceptual architecture
Role: Lead Consultant for Directory Services
Planned and designed a consolidation strategy for all users, computers, and applications from multiple Sberbank AD forests to a single AD domain. Implemented target design and validated migration approach with application testing and pilot migrations. Handed over mass migration to partners, providing support and oversight.
Keywords: Active Directory, Windows Server, migration, consolidation, testing, business continuity, applications, workstations
Highlights: Business impact: successfully delivered the largest AD migration project in CEE
Role: Consultant for IaaS
Provided technical advisory to partners of Microsoft in Russia to build Hosted Cloud solutions. Delivered conceptual architecture of IaaS for one of the first H-Cloud customers called 'Svyaznoy'.
Keywords: private cloud, IaaS, natinal program, conceptual architecture
Role: Technical Assessor for 'Server Platform, Management, and Virtualization' competence
Assessed technical expertise and project experience of partners’ architects to distinguish partners who meet all qualifying criteria for ESP status.
Keywords: skills assessment, technical interviews, partner certification
Role: Consultant for IaaS
Designed and deployed a pilot solution to implement Private Cloud IaaS at a service provider, a bleeding-edge technology at the time of implementation
Keywords: Private Cloud, IaaS, Windows Server 2012 R2, System Center VMM 2012 R2, Network Virtualization
Role: Architect for Directory Services
Successfully delivered 5 distinct projects to upgrade independent Active Directory forests from legacy versions to AD DS 2008 R2 ensuring the highest business continuity.
Keywords: Active Directory, Windows Server 2008 R2, business continuity, schema upgrade
Highlights: Business impact: improved security posture to the modern standards, built trust with the customer, prepared the foundation for the next ambitious project to globally consolidate all company branches to a single AD domain.
Role: Consultant for Directory Services
Assessed the current environment, prepared a short-term solution (trusts) and long-term strategy (migration to single domain/resource forest).
Keywords: Active Directory, environment assessment, trusts, domain migration, resource forest
Role: Lead Solution Architect, Consultant for selected services
Led the solution design team to prepare the modern conceptual architecture of IT infrastructure for the largest commercial energy company in Ukraine
Keywords: Directory Services, Core Network Services, Server Virtualization, Remote Desktop Services, IaaS approach for private and public clouds
Role: Architect for Directory Services
Designed the target architecture and migration approach from multiple AD forests to a single AD DS 2012 domain.
Keywords: Active Directory, Windows Server, ADMT
Role: Consultant for respective services
Performed successful presales for AD Design, Migration, Messaging, and Communications projects on the stages from discovering customer needs to team composition, work planning, and estimation.
Keywords: Windows Server, Active Directory, Exchange, Lync
Role: Infrastructure Owner
Led design and implementation of all technical aspects of TechEd Russia, the biggest MS technical conference in Russia with 3000+ attendees, 2 days, 16 breakout tracks.
Keywords: technical conference, core infrastrcucture on Windows Server, Hyper-V, clustering, server and storage hardware, public Wi-Fi, vendor selection, negotiations and logistics
Highlights: Business impact: highest attendee feedback score on the biggest MS technical conference in Russia ever.
Role: Consultant for Directory Services
Conducted directory services assessment for compliance with best practices for a modern commercial bank.
Keywords: AD DS 2008 R2, audit, assessment
Role: Consultant for RDS
Implemented highly available Remote Desktop solution for hosting business-critical application that is securely accessible over public Internet.
Keywords: Windows Server 2008 R2, Remote Desktop Services, Remote Desktop Gateway, Web Access, Connection Broker, PKI
Role: Consultant for Unified Communications
Led the implementation of the Unified Communication platform based on Microsoft technologies integrated with the existing Cisco telephony system.
Keywords: Lync Server 2010, Exchange 2010 UM, Cisco CCM
Role: Architect for Core Infra Services
As a member of the joint team consisting of Microsoft and Comitee's architects, contributed to design discussions and conceptual architecture of core infrastructure services providing IT platform for the Olympic Games.
Keywords: Remote Desktop Services (WS 2008 R2), Remote Access (TMG 2010), Backup (DPM 2010), Print Services, File Services