UpstaffSign up
Roman K., Active Directory, Cloud Infrastructure & Security Engineer
Roman K.
🇸🇰Slovakia (UTC+01:00)
Created AtUpstaffer since April, 2026
🔥 Get Roman K. rates & availability. We respond within one business day
Book a Call Download Profile PDF

Roman K. — Active Directory, Cloud Infrastructure & Security Engineer

Expertise in Cloud Infrastructure Engineer, Scripting and Automation.

 Last verified on April, 2026
Upper-Intermediate English

Core Skills

Entra ID
Azure
Azure
MDM
Microsoft Intune
PowerShell

Bio Summary

  • 6+ years managing IT infrastructure across Azure, AWS, and GCP, with hands-on expertise in Microsoft Intune for Windows, macOS, and Linux environments.
  • Strong background in hybrid identity (Active Directory + Microsoft Entra ID), including user lifecycle management, RBAC, OU design, and GPO administration. Experienced in building secure Entra ID environments with PIM, Conditional Access, and Identity Protection for 300+ users.
  • Contributed to AD to Azure AD migrations, ensuring secure identity transformation. Skilled in security automation, endpoint protection, and PowerShell/Graph API scripting.

Technical Skills

Security AD Connect, Autopilot, AWS Security Groups, Azure Network Security Groups, BitLocker, Compliance Policies, Conditional Access, Data Loss Prevention, DLP, Enterprise Application registration, Federation, FileVault, IAM, Identity Protection, MDE, Microsoft Defender for Endpoint, Microsoft Entra, Microsoft Intune, NetBird VPN, Patch Management, Privileged Identity Management (PIM), RBAC, Security policy, Sentinel (Microsoft Sentinel), Sign-in log analysis, Site-to-Site VPN, Wireguard
Cloud Platforms, Services & Computing AWS, Azure, GCP, Hetzner
Azure Cloud Services AAD, Azure AD hybrid identity, Azure Cloud Functions, Azure Key Vault, Azure Network Security Groups, Azure resource management, Azure Site Recovery, Azure Virtual Desktop, Azure VM, Azure Vnet, Entra ID, Microsoft Azure API, VMs, Windows Admin Center
Amazon Web Services AWS IAM, AWS Security Groups, AWS WorkSpaces
Google Cloud Platform Google Workspace
Adobe Experience Manager (AEM) AEM
Platforms ABM (Apple Business Manager), AEM, Microsoft, PIM, Power Automate, SharePoint, SharePoint Admin
Collaboration, Task & Issue Tracking Atlassian Confluence, Jira
Deployment, CI/CD & Administration Automation deployment CI, CD, CI/CD, Configuration Policies, OMA-URI, Win32 app packaging
Backup Backup
Mail / Network Protocols / Data transfer CIDR, Networking, Routing, SMTP log analysis, Subnets
SDK / API and Integrations Context API, Microsoft Azure API, Microsoft Graph API
QA, Test Automation, Security DLP, SSO
Virtualization, Containers and Orchestration Docker, Terraform
Methodologies, Paradigms and Patterns IaC
Web/App Servers, Middleware Internet Information Services (IIS)
Project Management & Administration L1/L2/L3 support, License management
Operating Systems Linux, macOS, Windows
iOS Libraries and Tools MDM
Third Party Tools / IDEs / SDK / Services Office 365
Scripting and Command Line Interfaces PowerShell

Active Directory Specialist Skills and Tech Stack

Identity & Directory Services:

  • Active Directory (User & Group Management, OU Design, RBAC)
  • Microsoft Entra ID (Azure AD), Conditional Access
  • Hybrid Identity & AD Migration
  • Group Policy (GPO) Management & Troubleshooting

Networking (Windows / Identity-related):

  • DNS (A, MX, SPF, DKIM records)
  • DHCP (IP allocation, reservations, troubleshooting)

DNS / MESSAGING

  • Managed enterprise DNS configurations, including internal A records and public DNS records (MX, SPF, DKIM) for secure email delivery and anti-spoofing protection.
  • Supported identity-related DNS troubleshooting impacting authentication and service availability.

Cloud Identity / Security

  • Implemented and managed Conditional Access policies in Microsoft Entra ID to enhance identity security and enforce access controls.
  • Worked with Identity Protection features to secure user authentication flows and mitigate identity-based risks.
  • Handled certificate-based configurations within cloud environments (Intune / Azure), supporting secure device and service authentication.

DHCP

  • Configured and maintained DHCP services, including IP address allocation, reservations, and network troubleshooting for enterprise environments.

Employment Experience

  • Technical System Administrator/Intune Specialist, Plan A Technologies
    2021 - present
  • IT Support Engineer, SoftServe
    2018 - 2021
  • Aviation Security, International Airport Kharkiv
    2012 - 2017

Work Experience

Plan A Technologies

Technical System Administrator/Intune Specialist, Administered Microsoft Azure and Entra ID

Duration: 2021 - present

Summary: Own the identity, security, and cloud infrastructure for a 320+ user company operating across Azure, AWS, and GCP. Responsible for the full IAM lifecycle - from provisioning and access governance to cost management and security posture. Daily communication with international teams across the US, Latin America, and Europe

Responsibilities:

  • Managed secured privileged access with PIM, detected risks with Identity Protection, and enforced security with risk-based.
  • Worked in enterprise-scale environments supporting distributed teams and cross-functional identity and access requirements.
  • Conditional Access policies.
  • Managed Azure resources (VMs, V-Nets, Storage) and governance (Azure Policy, Cost Management).
  • Managed multi-cloud AWS & GCP environments, focusing on IAM, resource provisioning, and billing.
  • Deployed a DefGuard (WireGuard-based) VPN.

Technologies: Microsoft Azure, Azure Entra ID, Azure Policy, AWS, GCP, PIM, Conditional Access.

Technical System Administrator/Intune Specialist, Endpoint Management with Microsoft Intune

Duration: 2021 - present

Summary: End-to-end endpoint management for a mixed Windows/macOS/Linux fleet using Microsoft Intune covering zero-touch provisioning, security hardening, app deployment, and automated patching.

Responsibilities:

  • Zero-Touch Deployment: Windows Autopilot, Apple Business Manager (ABM)
  • Policy & App Management: Complex Win32 apps, Settings Catalog, custom OMA-URI
  • Endpoint Security: Integrated Microsoft Defender for Endpoint with Intune compliance policies and security baselines.
  • Managed BitLocker and FileVault encryption enforcement, security score tracking, and remediation workflows using PowerShell and Graph API.
  • Patch Management: Automated 3rd-party application patching, Windows Update rings.
  • Device Lifecycle: Full management for Windows, macOS, & Linux endpoints

Technologies: Microsoft Intune, Windows Autopilot, Apple Business Manager, Microsoft Defender for Endpoint, Win32 apps, OMA-URI, BitLocker, FileVault.

Technical System Administrator/Intune Specialist, Google Workspace Administration and Automation

Duration: 2021 - present

Summary: Full ownership and end-to-end administration of Google Workspace for 320+ users, including DLP policies, Context-Aware Access, Gmail routing rules, and data governance via Google Vault. Built automated security alerting with Power Automate

Responsibilities:

  • Implemented advanced security (DLP, Context-Aware Access, Gmail routing), and managed data governance with Google Vault & Shared Drive policies.
  • Managed Jira for IT Service Management (workflows, templates) for efficient incident/request resolution.
  • Automated security notifications and user update alerts using Power Automate flows integrated with Google Workspace.

Technologies: Google Workspace, Google Vault, Jira Service Management, Power Automate.

SoftServe

IT Support Engineer, IT Support and Migration Assistance

Duration: 2018 - 2021

Summary: L2 support engineer handling domain account management, corporate services and workstation setup. Participated in the company-wide migration from on-prem Windows AD to Azure AD, assisting users through the transition. Managed warehouse and equipment repair organization.

Responsibilities:

  • Installed and configured workstation software.
  • Supported network/domain user accounts, mailboxes, and corporate printing services.
  • Assisted users with migration from Windows AD to Azure AD.
  • Managed warehouse and organized equipment repairs.
  • Managed Active Directory environments at L2 level, including full lifecycle of user accounts, security groups, and access permissions.
  • Designed and maintained Organizational Unit (OU) structures and implemented role-based access control (RBAC) across multiple departments.
  • Administered and troubleshooted Group Policy Objects (GPO), ensuring consistent policy enforcement across endpoints.
  • Supported enterprise identity migration from on-prem Active Directory to Microsoft Entra ID, contributing to hybrid identity architecture.
  • Collaborated with cloud teams to align on identity and access strategies across on-prem and cloud environments.

Technologies: Windows AD, Azure AD, workstation software, network services.

International Airport Kharkiv

Aviation Security, Access Control, Passenger Screening

Duration: 2012 - 2017

Summary: Performed security duties at airport terminals including computer and automation systems management, personnel access control, screening of passengers and luggage to ensure compliance with aviation security regulations.

Responsibilities:

  • Carried out access control duties at terminals.
  • Screened passengers, hand-held luggage, and checked-in luggage for prohibited items.

Education

  • Specialized Computer Systems Engineer
    National University of Radio electronics, Ukraine
    2007 - 2012

How to hire with Upstaff

1

Talk to Our Talent Expert

Our journey starts with a 30-min discovery call to explore your project challenges, technical needs and team diversity.

2

Meet Carefully Matched Talents

Within 1-3 days, we’ll share profiles and connect you with the right talents for your project. Schedule a call to meet engineers in person.

3

Validate Your Choice

Bring new talent on board with a trial period to confirm you hire the right one. There are no termination fees or hidden costs.

Why Upstaff

Upstaff is a technology partner with expertise in AI, Web3, Software, and Data. We help businesses gain competitive edge by optimizing existing systems and utilizing modern technology to fuel business growth.

Real-time project team launch

<24h

Interview First Engineers

Upstaff's network enables clients to access specialists within hours & days, streamlining the hiring process to 24-48 hours, start ASAP.

x10

Faster Talent Acquisition

Upstaff's network & platform enables clients to scale up and down blazing fast. Every hire typically is 10x faster comparing to regular recruitement workflow.

Vetted and Trusted Engineers

100%

Security And Vetting-First

AI tools and expert human reviewers in the vetting process is combined with track record & historically collected feedbacks from clients and teammates.

~50h

Save Time For Deep Vetting

In average, we save over 50 hours of client team to interview candidates for each job position. We are fueled by a passion for tech expertise, drawn from our deep understanding of the industry.

Flexible Engagement Models

Arrow

Custom Engagement Models

Flexible staffing solutions, accommodating both short-term projects and longer-term engagements, full-time & part-time

Sharing

Unique Talent Ecosystem

Candidate Staffing Platform stores data about past and present candidates, enables fast work and scalability, providing clients with valuable insights into their talent pipeline.

Transparent

$0

No Hidden Costs

Price quoted is the total price to you. No hidden or unexpected cost for for candidate placement.

x1

One Consolidated Invoice

No matter how many engineers you employ, there is only one monthly consolidated invoice.

Roman K., Active Directory, Cloud Infrastructure & Security Engineer
Ready to hire Roman K.
or someone with similar Skills?
Roman K. is available
for hire 🔥
Book a call with Roman K.
Looking for Someone Else? Join Upstaff access to All profiles and Individual Match
Start Hiring
Request Roman K. Rates & Availability
Attachment File attachment Arrow

Upload File. Drag and Drop or Browse

{# when reCAPTCHA is disabled server-side (staging/local test), drop the g-recaptcha binding so the button submits directly — keeps front/back in sync via one flag #}
At Upstaff we respect confidentiality, privacy and value your information.

Confidential (C) UPSTAFF LTD, England and Wales, #12727246 17 Montgomery Drive, Tavistock, United Kingdom PL19 8KX

Terms, conditions and legal information.

Thank you! 🎉

Your message has been successfully sent. We’ll review it and get back to you as soon as possible.

Create an account to save your details and track your applications.

Sign up
Download Candidate Profile (PDF)

Please leave your details and we'll email you the resume right away.

At Upstaff we respect your privacy.

Confidential (C) UPSTAFF LTD, England and Wales, #12727246 17 Montgomery Drive, Tavistock, United Kingdom PL19 8KX

Terms, conditions and legal information.