# Infra-stack Experience Topology--Full
SKILLS & EXPERIENCE CLOUD CORE IOT LINUX NETWORKING IDENTITY ITSM ON-PREM HARDWARE AI-INFRA IT-OPS SECURITY GRC AZURE ORACLE AWS ALIBABA RHEL UBUNTU SERVER AZURE LINUX SWITCHING VLAN VPN FIREWALL ENTRA ID PAM INTUNE AD-DC DHCP-DNS FILE STORAGE WDS SERVER SERVERS STORAGE ENDPOINTS VC SYSTEMS H100/H200 DGX EDGE AI-FOUNDRY MONITORING CHANGE MGMT ASSET MGMT CROWDSTRIKE NETSKOPE ZSCALER POLICIES AUDIT COMPLIANCE SECURITY GOVERNANCE
IT INFRASTRUCTURE ENGINEER

Hi, I'm Gokulakrishnan.
I Build & Secure the systems between the users and the services.

With over 5+ years of Enterprise experience spanning on-premises infrastructure, cloud environments, and high-performance AI infrastructure. I currently hold a critical, multi-disciplinary role within IT Operations and Cybersecurity, primarily responsible for the governance and administration of core infrastructure. Accountable for the end-to-end management of mission-critical server environments, ensuring high availability and strong operational performance. In addition to infrastructure implementation and oversight, I am experienced in datacenter operations and migrations. All of this backed by 6 years of STEM education in Electronics and Communication Engineering.

# Experience Topology
AI-INFRA IT-OPS ITSM SECURITY ON-PREM HARDWARE GRC CLOUD CORE LINUX IDENTITY IOT NETWORKING SKILLS & EXPERIENCE
~/Work

Experience

IT Infrastructure Engineer

FEB 2025 — PRESENT
Larsen & Toubro Construction
  • Translated business specifications into functional infrastructure designs, collaborating with software developers, DevOps, and cloud architects to ensure smooth, secure distributed hardware implementations.
  • Provision and maintain multi-cloud and on-premises environments across Microsoft Azure, AWS, and on-prem datacenters, configuring VPCs, subnets, route tables, firewalls, and VPNs to ensure high availability and network segmentation.
  • Execute physical datacenter operations, including rack installations, hardware provisioning, network cabling, and component-level diagnosis and replacement for high-density enterprise servers and switches.
  • Deploy, configure, and patch enterprise Windows Server and Linux environments (RHEL, CentOS, Ubuntu), hardening operating systems and automating core service roles across bare-metal and cloud infrastructure.
  • Provision, configure, and isolate dedicated computing environments for enterprise AI applications, implementing strict compute-hardening and access controls to protect sensitive model data and endpoints.
  • Architected, provisioned, and optimized enterprise compute clusters powered by NVIDIA H100 and H200 GPU servers, deploying specialized driver stacks, container runtimes, and host virtualization to accelerate model training and high-throughput inference workloads.
  • Designed and deployed resilient enterprise network topologies, configuring multi-tiered VLANs, ACLs, inter-VLAN routing, and firewall policies across physical core/access switches and cloud VPCs to enforce network isolation and prevent unauthorized lateral movement.
  • Monitor server fleets in coordination with the SOC and EDR platforms, executing rapid vulnerability remediation, patch management, and security controls to maintain ISO 27001 regulatory audit readiness.
  • Provisioned, hardened, and maintained heterogeneous enterprise environments across Windows Server and Linux distributions, configuring core server roles and executing proactive maintenance to uphold high system availability.
  • Architecture Translation & Operational Delivery: Collaborated across multidisciplinary engineering pods (spanning database administrators, developers, and security analysts) to translate high-level architectural designs into scalable, compliant hybrid cloud infrastructure under strict ITIL governance.
  • Collaborated with SecOps, IAM, and network engineering teams to enforce enterprise security baselines.

Senior System Engineer

APR 2023 — JAN 2025
Larsen & Toubro Construction -CIELHR
  • Administered CrowdStrike Falcon EDR across 35,000+ endpoints, overseeing threat detection, policy enforcement, sensor health, and rapid incident response to secure global operations.
  • Deployed and troubleshot Zscaler Zero Trust services (ZIA and ZPA), configuring secure application segmentation and user tunnels to enforce least-privilege remote access.
  • Provisioned and managed hybrid infrastructure across Microsoft Azure and on-premises environments (VMware ESXi, Hyper-V), deploying virtual machines and containerized workloads (Docker, LXC, Azure Container Instances).
  • Configured, tested, and maintained critical Windows Server roles and Linux services across bare-metal and virtual platforms.
  • Administered identity lifecycles across hybrid Active Directory and Azure AD (Entra ID), managing authentication protocols, SaaS application domain integrations, and compliance policies via Microsoft Intune.
  • Enterprise-wide migration from Zscaler to Netskope across 35,000+ global endpoints, deploying high-availability NPA publisher connectors to establish seamless ZTNA to internal applications.
  • Configured Netskope DLP policies to prevent unauthorized data exfiltration and ensure regulatory compliance.
  • Led technical audit-readiness workflows for ISO 27001 and external audits, participating in formal CAB reviews and executing thorough RCA to remediate recurring system incidents.
  • Partnered with vendors to evaluate emerging technologies, conduct technical PoCs, and execute hardware and network redesign initiatives across facilities.
  • Centralized and maintained mission-critical core network services globally including DHCP, WDS, Print Services, and IPAM, ensuring uniform standards.
  • Managed enterprise video conferencing infrastructure, configuring and supporting Polycom and Cisco VC hardware, codecs, and software across boardroom environments.

Systems Engineer

SEP 2021 — MAR 2023
Larsen & Toubro Construction -CIELHR
  • Directed daily operations for a multi-tiered support team (L0/L1), establishing standardized troubleshooting SOPs and training programs to elevate first-contact resolution rates.
  • Served as the dedicated technical advisor and support liaison to CEO, CFO, Directors, other C-suite ensuring 100% data confidentiality and zero-downtime executive workflows.
  • Administered enterprise infrastructure across headquarters, managing DHCP, Print Servers, and SolarWinds IPAM to uphold strict network reliability and high-availability service agreements.
  • Provided multi-region Tier-3 infrastructure support across distributed business units (India HQ, Middle East, and China), ensuring uniform system compliance and SLA adherence.
  • Maintained and optimized dedicated application servers running enterprise Robotic Process Automation (RPA) bots, coordinating across DevOps and security teams for patch management and deployment safety.
  • Coordinated with engineering teams to provision, configure, and harden host servers (including IIS and RPA platforms), ensuring seamless resource deployment and zero security regressions during application rollouts.
  • Maintained enterprise storage environments utilizing NetApp ONTAP and Dell EMC Isilon alongside hosting mission-critical internal web applications on Microsoft IIS.
  • Directed full technical production, AV infrastructure, and run-of-show logistics for 40–50 high-stakes executive town halls and board meetings annually without broadcast interruption.
  • Automated recurring system tasks, configurations, and maintenance routines using custom PowerShell and Batch scripts to eliminate manual overhead.
  • Configured, tested, and commissioned integrated video conferencing rooms, authoring technical deployment guides for operational handoff.
  • Enforced enterprise security baselines by administering McAfee Endpoint Security and configuring DLP policies to prevent unauthorized data exfiltration.
~/Skills

What I work with

Core Infrastructure

Systems & Virtualization

  • Windows Server / Active Directory
  • Linux (multiple distros)
  • Hyper-V, VMware ESXi, Proxmox
  • Docker, LXC, Azure ACI containers
Cloud & Identity

Azure & Microsoft 365

  • Azure & Azure AD / Entra ID
  • Microsoft 365, Teams, Intune
  • Google Cloud, Alibaba Cloud
  • Microsoft Foundry / RAG
Networking

Network & Connectivity

  • DHCP/DNS, SolarWinds IPAM
  • Cisco Meraki, 802.1x (WLAN/LAN)
  • Zscaler Zero Trust (ZIA/ZPA)
  • NetApp-ONTAP, Dell EMC Isilon
Security

Endpoint & Security

  • CrowdStrike Falcon (EDR)
  • McAfee endpoint security & DLP
  • Zero Trust tunnel administration
Automation

Scripting & Tooling

  • PowerShell, Batch, Python, C
  • Power Automate, Power BI
  • RSAT, Anaconda, WSL
IoT & Edge

IoT & Edge Computing

  • Raspberry Pi, Arduino
  • LoRA, IFTTT
  • Custom PCB design
~/Education
Bachelor of Engineering in Electronics and Communication
SSN College of Engineering
2018–2021
Technical diploma in Electronics and Communication
Panimalar Polytechnic College
2015–2018
~/key-achievements
~/certifications
MCSA · RHCE · CCNA
A+ & N+ Essentials
CompTIA Cloud+
Alibaba Cloud (ACA)
Azure — GUVI / IITM Research Park
Google IT Support
Enterprise System Management & Security — Coursera
Communication & Network Security — Cybrary
~/notable-technical-projects

Microsoft Foundry RAG Infrastructure

AZURE · AI SEARCH · BLOB STORAGE

Provisioned and configured Azure infrastructure for a Retrieval-Augmented Generation pipeline — Resource Group, Azure AI Search, and Blob Storage — including hub-level and project-level service connections. Worked through the distinction between hub and project scope, and validated managed identity vs. API key authentication paths.

Azure AI FoundryManaged IdentityRAG

Cross-Tenant OneDrive Migration

MICROSOFT 365 · POWERSHELL

Investigated cross-tenant OneDrive shortcut limitations and designed workarounds where native support fell short — including B2B guest access syncing and a scripted cross-tenant migration path via PowerShell.

Microsoft 365B2B Guest AccessPowerShell
~/About

A bit more about me

I'm a senior system engineer with 5 years of experience, currently supporting C-level executives at Larsen & Toubro's HQ through CIEL HR. My work sits at the intersection of reliability and reinvention — keeping core infrastructure like Active Directory, virtualization, and networking running solidly, while pushing into Azure, Microsoft 365, endpoint security, and now AI infrastructure like Microsoft Foundry.

I like being the engineer who can go from a network redesign to a RAG pipeline in the same week — that's the range I bring.

5years in infrastructure
35K+endpoints under EDR management
10+Core Services