← sumitatre.com
KQL Sandbox

Sumit Atre

Senior Cybersecurity Engineer · Cloud Security & Infrastructure
Greater Toronto Area, ON · [email protected] · LinkedIn ↗ · sumitatre.com

High-impact Cybersecurity Engineer with proven expertise architecting and securing multi-tenant Azure and hybrid cloud enterprise platforms. Specialized in FinOps-aligned telemetry architecture, DevSecOps pipeline automation, Identity & Access Management (Entra ID), and infrastructure-as-code (Terraform) governance. Proven track record collaborating with senior leadership and cross-functional engineering teams to remediate systemic vulnerabilities, establish cloud security baselines, and drive enterprise-scale OpEx reduction. Holds active CISSP and Azure Administrator Associate certifications, alongside previously held solutions architecture credentials.

Core Competencies

Cloud & Platform Security
Microsoft Azure, AWS, Azure Kubernetes Service (AKS), Terraform (IaC), Zero Trust Architecture, CIS Benchmarks, CSPM.
Security Operations & Observability
Microsoft Sentinel, Log Analytics Workspaces (LAW), Data Collection Rules (DCR), Telemetry & Ingestion Optimization (FinOps), BlueVoyant MDR Integration, EDR/XDR.
Identity & Access Governance
Entra ID (Azure AD), SAML / OAuth / OIDC, Conditional Access, Privileged Identity Management (PIM), Managed Identities, Least-Privilege Architecture.
Governance, Risk & Compliance (GRC)
SOC 2 Type II, ISO/IEC 27001, NFR Security Architecture, Technical Leadership & GRC Reporting, Incident Response & Root Cause Analysis (RCA).

Professional Experience

Cybersecurity Engineer

GS1 Canada April 2025 – Present | Greater Toronto Area, ON
Key Focus Areas & Impact:
  • Cloud FinOps & Telemetry Re-Architecture: Architected and implemented an enterprise-wide Azure Log Analytics and Sentinel ingestion overhaul, reducing monthly workspace ingestion overhead by over 90%, realizing over $100K+ CAD in annual recurring OpEx savings without degrading detection fidelity.
  • Kubernetes Log Optimization: Engineered surgical Azure Monitor Data Collection Rules (DCRs) to filter high-volume, low-signal container stdout/stderr at the edge, retaining actionable security and control plane telemetry while eliminating non-security operational noise from high-cost analytical tiers—slashing container telemetry ingestion costs by over 70% ($50K+ annually).
  • Data Lifecycle & Ingestion Governance: Redesigned retention policies across 15 core security tables from 365-day interactive storage into a 90-day interactive / 275-day archive tier, with an expanded plan capturing an additional 11 high-throughput tables.
  • Executive Security Visibility: Authored FinOps capacity models, data lifecycle policies, and architectural cost-efficiency baselines for senior technical leadership, establishing foundational KPIs for enterprise platform modernization.
  • Infrastructure-as-Code Hardening: Conducted end-to-end security reviews of Terraform deployments and Azure Functions execution models (e.g., Run From Package tokenization), authoring automated guardrails and migrating legacy SAS token configurations toward Azure Managed Identities.
  • MDR & Threat Attribution: Served as technical escalation lead partnering with BlueVoyant MDR; executed cross-platform investigations correlating external vendor ingress with Entra ID tenant telemetry and Azure DevOps pipelines to eliminate false positives and drive systematic root cause remediation.
  • Platform 3.0 Modernization: Established Non-Functional Requirements (NFR) and security guardrails across cloud-native application stacks, ensuring secure deployment and continuous compliance across enterprise microservices.
Technologies: Microsoft Azure Microsoft Sentinel Log Analytics (LAW) AKS Terraform Entra ID Managed Identities BlueVoyant MDR Azure Functions Azure DevOps

Lead / Senior Cloud Security & Systems Administrator

IT Business Advisors (ITBA) August 2021 – March 2025 | Greater Toronto Area, ON
  • Spearheaded cloud infrastructure, security posture, and identity engineering for 40+ multi-tenant hybrid environments across financial, healthcare, legal, and manufacturing clients (800+ total seats).
  • Guided multilayered technical controls and audit readiness supporting successful SOC 2 Type II compliance and ISO/IEC 27001 certification programs for enterprise clients.
  • Re-architected client operating environments into cloud-first configurations using Microsoft Entra ID, Intune, Conditional Access, and Microsoft Purview DLP, driving 40%–60% reductions in on-premises infrastructure maintenance costs.
  • Designed and deployed automated PowerShell automation engines for zero-touch provisioning and role-based lifecycle access, reducing employee onboarding and deprovisioning cycles by 40%.
  • Directed incident response and remediation operations across major industry threats (including zero-day Kaseya VSA CVE-2021-30116), containing lateral movement and eliminating blast radius across exposed customer tenants.
  • Hardened cloud and hybrid environments to CIS Level 1/Level 2 benchmarks; instituted centralized enterprise PKI, enterprise domain certificate authorities, and RADIUS authentication over 802.1X.
Technologies: Microsoft Entra ID Intune Conditional Access Purview DLP PowerShell AD CS (PKI) RADIUS / 802.1X CIS Benchmarks SOC 2 Type II

Systems & Security Administrator

IT Business Advisors (ITBA) March 2020 – August 2021 | Greater Toronto Area, ON
  • Monitored, investigated, and triaged multi-tenant security events across modern EDR/XDR and SIEM tools (Rapid7, Sophos XDR, Okta, Duo, ConnectWise).
  • Led technical discovery, scoping, and deployment for complete on-premise-to-cloud migrations into Azure and Microsoft 365.
  • Standardized infrastructure configuration policies, authoring runbooks and technical documentation for system hardening and disaster recovery.
Technologies: Azure IaaS Microsoft 365 Rapid7 Sophos XDR Okta Duo ConnectWise

Systems Administrator

Some IT Guy January 2008 – December 2019 | Greater Toronto Area, ON
  • Maintained, secured, and administered Windows Server environments (2008–2019), Active Directory Group Policy, DNS, DHCP, and enterprise backup/DR platforms (Veeam).
  • Managed third-party external penetration testing engagements, translating technical findings into prioritized vulnerability remediation roadmaps.
  • Implemented physical and network security baselines across multi-site branch operations.
Technologies: Windows Server Active Directory (GPO) DNS / DHCP Veeam Backup & DR Penetration Testing Network Security

Certifications

CISSP – Certified Information Systems Security Professional (ISC)² · Active
Microsoft Certified: Azure Administrator Associate (AZ-104) Microsoft · Active
Microsoft Certified: Azure Solutions Architect Expert (AZ-305) Microsoft · Previously Held / Inactive
Microsoft 365 Certified: Enterprise Administrator Expert (MS-102) Microsoft · Previously Held / Inactive
CompTIA Security+ CompTIA · Previously Held / Inactive

Technical Skills

Cloud & DevOps
Microsoft Azure, AWS, Terraform, Docker, Kubernetes (AKS), Azure DevOps, CI/CD Security Integration.
Security & SIEM
Microsoft Sentinel, Azure Log Analytics, Kusto Query Language (KQL), BlueVoyant MDR, Rapid7, Sophos XDR, CrowdStrike, Nessus, Suricata.
Identity & Access Management (IAM)
Microsoft Entra ID, Active Directory, PIM, Conditional Access, SAML 2.0, OAuth 2.0, OIDC, Multi-Factor Authentication (MFA).
Scripting & Automation
PowerShell, Python, Bash, Azure Resource Manager (ARM), JSON.
Networking & Protocols
Zero Trust Network Access (ZTNA), VPN, 802.1X, PKI / CA, DNS, DHCP, TCP/IP, Next-Gen Firewalls (SonicWall, pfSense, WatchGuard).