Azure cloud engineering portfolio

Yossef Mohammed Ali

Infrastructure Engineer transitioning into Azure Cloud Engineering

I operate factory and enterprise infrastructure across servers, identity, L2/L3 networking, virtualization, security, backup, and recovery. I am applying that operations foundation to Azure administration, cloud networking, monitoring, and infrastructure automation.

Professional profile

A practical infrastructure foundation for cloud operations

My experience spans on-premises and hybrid environments where availability, secure access, clear troubleshooting, and recoverability matter. The next step is focused: Azure administration and cloud infrastructure roles that benefit from that operational context.

Operate reliably

Support physical and virtual servers, LAN/Wi-Fi, workplace and factory technology, storage, and core Windows services.

Secure and recover

Work with segmentation, firewalls, access controls, patching, backup validation, recovery testing, and disaster recovery planning.

Automate and document

Build automation capability through PowerShell and Azure CLI training, Bash labs, compiled Bicep, Git, and GitHub Actions.

Professional focus
Cloud operations · Hybrid infrastructure · Azure administration
Languages
Arabic — Native · English — Professional working proficiency

Selected engineering work

Projects with inspectable evidence

Each project links to code or documentation. Status labels distinguish deployed work, lab implementations, and future plans.

Locally and CI validated

Azure networking · Private Link · Bicep · GitHub Actions

Secure Azure Hub-Spoke Reference Lab

An original, private-by-default Azure network foundation expressed as modular Bicep. Repository automation validates the templates and shell tooling; Azure deployment and runtime evidence remain pending until an authorized subscription is available.

Animated delivery path

From commit to private cloud foundation

CI validated
01 Engineer Commit modular Bicep
02 GitHub Actions Lint, compile, ShellCheck
03 Bicep + ARM Validate and what-if
04 Azure Guarded deployment
Hub 10.0.0.0/16 Management + shared services
App spoke 10.10.0.0/16 Workload + private endpoint
Data spoke 10.20.0.0/16 Segmented data workloads
Private DNS Private Endpoint Azure Monitor Log Analytics
  • No public IPs by default
  • NSG segmentation
  • Private storage access
  • Cost-aware optional services

Architecture

Creates hub, application, and data VNets with bidirectional peering connections, subnet-level controls, centralized private DNS, and private storage access.

Delivery safety

Deployment scripts verify the active subscription, run validation and Resource Manager what-if, require confirmation, and use ownership-checked teardown.

Evidence boundary

Bicep, parameters, Bash, PowerShell, links, and secret scanning pass in GitHub Actions. Azure deployment and runtime evidence remain pending.

  • Azure VNets
  • Private Link
  • Private DNS
  • NSGs
  • ASGs & route tables
  • Bicep
  • GitHub Actions
  • Azure Monitor
Difficulty
Intermediate
Certification areas
AZ-104 · AZ-700 · AZ-500
Live status
Not yet deployed · evidence pending
Lab repository

Identity · Linux · Automation

Samba Active Directory Domain Controller Lab

A documented, script-driven lab for provisioning Samba Active Directory Domain Services on Ubuntu 24.04 with internal DNS, Kerberos, organizational units, user creation, and repeatable verification steps.

What is implemented

Ordered Bash scripts cover prerequisites, package installation, domain provisioning, DNS forwarding, object creation, and service checks.

Operational thinking

Documentation covers time synchronization, DNS and Kerberos tests, SYSVOL/NETLOGON checks, password prompting, and common failure modes.

Evidence boundary

Code and documentation are published as a lab implementation; no production deployment or business environment is claimed.

  • Ubuntu 24.04
  • Samba AD DC
  • Bash
  • DNS
  • Kerberos

Professional experience

Infrastructure operations in business-critical environments

Responsibilities are condensed from the CV and emphasize infrastructure, networking, security, recovery, and cross-functional delivery without invented metrics.

Electrolux Group

IT Infrastructure Analyst

–Present

  • Operate onsite server, network, workplace, and IT/server-room infrastructure supporting factory and office operations.
  • Manage local physical and virtual server environments and coordinate WAN connectivity with Global IT.
  • Design local L2/L3 switching, fiber, LAN, Wi-Fi, and server architecture in line with Global IT standards.
  • Provision infrastructure for labs, warehouses, machinery, and production equipment with Engineering, IoT, R&D, and Logistics teams.
  • Support OT security asset management, VLAN segmentation, local security controls, factory PC patching, and asset lifecycle management.

Aegis

IT Infrastructure and Systems Specialist

  • Configured Cisco switches and firewalls, monitored network traffic, and resolved network and security issues.
  • Administered Dell iDRAC, PowerScale storage, RAID, VMware ESXi, and Proxmox, including server maintenance and hardware upgrades.
  • Administered Active Directory Domain Services, Group Policy, domain trusts, and security configurations.
  • Supported SQL Server and Oracle operations, backup and recovery testing, and disaster recovery planning.

Technical capability

Skills grouped by how they are applied

Each list identifies its evidence source so training, CV-listed capability, and repository implementation are not presented as equivalent.

Repository-proven implementation

Cloud delivery & automation

Azure Static Web Apps, compiled Bicep resource definition, GitHub Actions, Git, Bash automation, Samba AD DC lab

Technical skills listed in CV

Azure & Microsoft Cloud

Azure VMs, VNets, Storage Accounts, Microsoft Entra ID, RBAC, NSGs, Azure Backup, Azure Monitor, Azure CLI, PowerShell, Microsoft 365 administration

Professional responsibilities in CV

Microsoft Infrastructure

Physical and virtual server operations, Active Directory Domain Services, Group Policy, domain trusts, and server security configuration

Professional responsibilities in CV

Networking & Security

L2/L3 switching, fiber, LAN/WAN, Wi-Fi, Cisco switching and firewalls, VLAN segmentation, traffic monitoring, and network troubleshooting

Professional responsibilities in CV

Systems, Data & Recovery

VMware ESXi, Proxmox, Dell PowerScale, RAID, SQL Server and Oracle operations, backup and recovery testing, and DR planning

Additional technical skills listed in CV

Infrastructure Toolkit

Windows Server 2016/2019/2022, DNS, DHCP, DFS, File Services, RDS, vCenter, Hyper-V, Proxmox PBS, Veeam, IBM SAN, NAS, VPN, NAT, Cisco ISE, FortiGate, Sophos

Credentials, training & education

Clear evidence, accurately labelled

Academy program completion and digital course badges are shown separately. They are not presented as proof of passing a vendor certification exam.

Verification boundary

The available public evidence confirms academy program completion and Cisco Networking Academy course badges. No vendor exam verification ID is published here, so Microsoft, CCNA, Fortinet, and Veeam tracks are described only as training objectives.

Preview of IT Gate Academy Academic Azure Cloud Engineering Program completion certificate
Program completed

Academic Azure Cloud Engineering Program

IT Gate Academy · 220 credit hours · Grade: Very Good

Training tracks covered CCNA 200-301, MCSA Windows Server 2019, AZ-900, AZ-104, AZ-500, AZ-700, and Veeam VMCE objectives.

View course-completion PDF
Preview of IT Gate Academy Academic IT Infrastructure Program completion certificate
Program completed

Academic IT Infrastructure Program

IT Gate Academy · 240 credit hours · Grade: Very Good

Training tracks covered CCNA 200-301, MCSA Windows Server 2019, and Fortinet NSE 4 objectives.

View course-completion PDF

Education

Bachelor of Science (BSc) in Management Information Systems (MIS)

El Shorouk Academy · Al Shorouk City, Cairo

Contact

Looking for strong infrastructure foundations with a clear Azure direction?

I am targeting Azure Cloud Engineer, Azure Administrator, Cloud Infrastructure, Hybrid Cloud, and infrastructure automation roles.