Srinivas Yenuganti
IT infrastructure, cloud & security architect · 20+ years · Los Angeles
I've spent 20+ years across nine organisations, on both sides of the wire — from racking servers and running Exchange and SAN storage in the mid-2000s, through leading infrastructure, cloud, and security teams, to designing and operating multi-tenant Azure platforms for healthcare today.
That range is the point. I've owned networks, servers, storage, and data centres; built SOC and NOC functions and led teams of 20+ engineers; taken three organisations through ISO 27001, HITRUST, and SOC 2 certification; and migrated estates off on-premises hardware into Azure. Today I design landing zones, Kubernetes platforms, Zero Trust networking, and DevSecOps pipelines across Azure and AWS.
I work at architecture level and stay close enough to the build to prove a design before anyone else depends on it. Two decades of running the systems underneath is what makes those decisions sound — I've been paged for most of the failure modes I now design out.
I write up the useful parts on the blog — practical architecture notes, and the mistakes worth avoiding.
What I work with
- Cloud & platformAzure (IaaS/PaaS), AWS, GCP · landing zones, management groups, multi-subscription and multi-tenant isolation · hybrid and cross-cloud architecture · FinOps and cost governance
- Containers & infrastructure as codeAKS, Azure Container Registry, Container Apps, Helm · Terraform (remote state, multi-env), Bicep/ARM · GitOps, Ansible, PowerShell
- Networking & edgeHub-and-spoke VNets, NSGs, routing, private DNS · Azure Firewall and Firewall Policy · Application Gateway and Front Door with WAF (OWASP CRS tuning) · Private Link / Private Endpoints · S2S and P2S VPN, MPLS, egress control
- Identity & securityZero Trust, Microsoft Entra ID, Conditional Access, PIM, RBAC, Azure AD B2C · Defender for Cloud and Endpoint, Microsoft Sentinel, Splunk · CyberArk PAM, Fortinet NGFW, Forcepoint DLP, SentinelOne · SOC/NOC operations, vulnerability management, penetration testing (CEH)
- Data & AIAzure SQL, Cosmos DB, Data Factory, Databricks, Data Lake (medallion) · Kafka, Event Grid, Storage Queues · Azure OpenAI and AI Foundry · Power BI, Microsoft Fabric
- DevOps & deliveryAzure DevOps pipelines, GitHub Actions · SonarQube quality gates, SAST/DAST, vulnerability scanning, drift detection · release management, feature flags, test automation
- Observability & resilienceAzure Monitor, Log Analytics and KQL, Application Insights, Managed Grafana, Datadog · Azure Backup, Site Recovery, dedicated DR topologies, RPO/RTO design and recovery drills
- Compliance & governanceHIPAA, HITRUST CSF, ISO 27001, SOC 2, PCI DSS, GDPR · Azure Policy, audit readiness, certification programme leadership
Experience
- Own the enterprise Azure architecture for a healthcare payment-integrity portfolio — multiple payer-facing SaaS products delivered as isolated, per-customer environments to national health plans, each carrying its own regulatory and contractual obligations.
- Define the multi-subscription landing zone and tenancy model — management group hierarchy, subscription topology, RBAC, and Azure Policy guardrails — so every new customer environment onboards to a governed standard instead of being hand-built.
- Set the reference architectures and platform standards the delivery teams build to, spanning network, identity, secrets, container platform, and release patterns across the portfolio.
- Design and run the AKS container platform behind the claims editing, medical-record review, OCR, and document-intake workloads — private registry, managed identities, and shared platform observability consumed by multiple product teams.
- Led migration of the microservice estate — auth, coordination of benefits, rule engine, shared services, and UI — onto App Service and Azure Container Apps behind per-tenant Application Gateway and WAF.
- Define the zero-trust network architecture across hub-and-spoke VNets: Azure Firewall under centralised policy, Private Endpoints and Private DNS as the default path to data services, and inspected, controlled egress.
- Own the PHI/HIPAA-aligned security and observability posture across the estate — Defender, Sentinel, Key Vault, encryption, and WAF policy, with Azure Monitor, Log Analytics, and Application Insights supplying the evidence customer security reviews and regulatory audits depend on.
- Own the DevSecOps standard — CI/CD with SonarQube quality gates, automated compliance and vulnerability scanning, and drift detection — so findings surface at build time rather than at audit.
- Design the resilience and continuity posture to contracted recovery objectives — Recovery Services and Backup vaults, dedicated DR topologies, and geo-redundancy sized per product.
- Led a team of 15 across infrastructure, cloud operations, and information security, supporting 24×7 SaaS delivery.
- Established SOC and NOC frameworks with Microsoft Sentinel, SentinelOne, CyberArk PAM, and Splunk — improving threat visibility and cutting detection and response times.
- Implemented Zero Trust, IAM, and PIM using Microsoft Entra ID, reducing over-privileged access and reaching least-privilege governance at scale.
- Introduced DevSecOps across the delivery teams — moved security and compliance checks into the pipeline and established the vulnerability management and remediation cycle behind them.
- Led ISO 27001, HITRUST, and SOC 2 certification programmes — auditor coordination, remediation, and continuous compliance.
- Headed IT across the group of companies — infrastructure, cloud, and data centre operations — leading the internal team spanning the group's businesses.
- Owned the design direction for the manufacturing execution system (MES) supporting one of the group's electronics manufacturing operations, working alongside the internal development team.
- Ran data centre operations and led the migration of workloads to Azure, moving the group off self-hosted infrastructure.
- Oversaw security administration, Active Directory identity and access, and backup / DR readiness.
- Owned cloud, infrastructure, and security strategy across Azure and GCP, leading organisation-wide transformation over a seven-year tenure.
- Ran full data centre modernisation and migration to Microsoft 365 and Azure, decommissioning on-premises workloads.
- Achieved ISO 27001, HITRUST, and SOC 2 certifications through governance design, risk management, and audit readiness.
- Implemented Fortinet NGFW, EDR, and DLP to strengthen perimeter security and data protection.
- Built automation with PowerShell, Ansible, and Azure Policy for configuration management and compliance tracking.
- Led the systems team managing enterprise servers, VMware vSphere clusters, and Exchange environments across global offices.
- Designed secure site-to-site VPN connectivity between offices and tiered backup strategies underpinning business continuity.
- Improved infrastructure efficiency through proactive monitoring, capacity planning, and performance tuning of the virtualization estate.
- Ran full data centre operations for the group — Exchange, SAN storage, network security, and enterprise application hosting.
- Led the mail platform migration from Linux to Exchange 2010, and implemented MPLS WAN connectivity linking branch offices to the data centre.
- Owned server, storage, and network administration end to end: hardware and environmental monitoring, scheduled maintenance, change windows, and vendor/OEM coordination.
- Administered Active Directory identity and access, and ran backup, recovery, and continuity for data-centre-hosted services.
- Administered Windows and Linux systems, Active Directory and Group Policy, and campus network infrastructure.
- Tuned LAN/WAN performance and implemented security and access controls across the estate.
- Handled backup and recovery readiness and endpoint protection for staff and lab systems.
- Managed Windows and Linux infrastructure, Active Directory, and file services across a multi-office environment.
- Ran the antivirus, backup, and patch management programmes keeping the estate secure and available.
- Handled connectivity troubleshooting, access administration, and day-to-day support for staff across sites.
- Administered SQL Server databases — installation, configuration, backup, recovery, and query performance tuning.
- Supported the systems and users behind them: incident logging, troubleshooting, and resolution of hardware, software, and connectivity issues.
Certifications
- AZ-305 Azure Solutions Architect Expert Microsoft
- AZ-400 Azure DevOps Engineer Expert Microsoft
- AZ-500 Azure Security Engineer Associate Microsoft
- AZ-104 Azure Administrator Associate Microsoft
- AI-102 Azure AI Engineer Associate Microsoft
- AWS Certified SysOps Administrator – Associate Amazon Web Services
- CEH Certified Ethical Hacker EC-Council
- FortiGate Network Security Engineer Fortinet