Anuj Varma
@anujvarma
Enterprise security architect and multi-cloud architect delivering secure landing zones, migrations, and API/ML protection.
What I'm looking for
I’m an enterprise security and cloud architect with “28 years of n-Tier Apps, SOA, EAI and Database Development/Architecture” and “28 years of experience in designing, developing, and securing enterprise applications, distributed applications, web applications, Win32 software” and large database systems. I work at architect level design with hands-on delivery, mentoring, and performance-focused engineering across .NET and J2EE environments.
My core specialty is securing multi-cloud platforms end to end—public, hybrid, and containerized. I’ve owned “overall public cloud security posture,” “Threat Modeling,” encryption and key management (KMS, TLS/SSL automation), and landing zone designs (including “Cloud Landing Zones” and “Complete landing zones”), while building/leading zero-trust and identity foundations such as “Azure RBAC,” “SSO,” “Federation,” and “AD/ADFS to AAD Migration.” I also bring FinOps discipline (“FinOps Certified” / “FinOps Practitioner”) to balance security and cost.
In recent roles, I’ve architected and secured API and ML workloads—“AI/ML Security - Fraud and Anti Money Laundering SaaS security,” GCP/AWS/Azure networking, IAM, and encryption for ECS/GKE/Cloud Run style environments, plus MLOps and governance foundations (drift monitoring, audit frameworks, and responsible-AI style evaluation). From “Azure Landing Zone with AVD Implementation” and ExpressRoute/NSG/Fortinet designs to AWS reference architectures (Shared VPCs, Firewall Manager, GWLB) and Terraform-based delivery, I’m the architect who turns security requirements into reliable systems.
Experience
Work history, roles, and key accomplishments
Enterprise Security Architect
Empower Finance
Oct 2023 - Present (2 years 7 months)
Served as Enterprise Security Architect for cloud and API security, including threat modeling and risk documentation for 3+ dozen acquisition-based applications. Designed AWS security reference architectures (Shared VPCs, GWLB firewall patterns) and architected fraud/anti–money laundering AI/ML security using Vertex AI and SageMaker workflows with IAM and encryption controls.
API & ML Security Architect
CHS.net
Jun 2023 - Oct 2023 (4 months)
Owned API security for a healthcare HIPAA data pipeline, securing GKE clusters and healthcare API integrations and performing threat modeling for hosted and consumed APIs. Supported ML/dataflow transformations for reshaping and preparing datasets used by patient processing workloads.
Defined multi-cloud security standards for a SAP ecosystem migration and remediated over 1,000 Prisma CSPM findings across AWS and GCP. Led zero-trust evaluation and PoCs to reduce VPN reliance and created a GCP CIS benchmarking matrix covering 115 benchmarks, routing CIS violations through Security Command Center dashboards and remediation plans.
AD and Azure Identity Specialist
Andersen Corp
Oct 2020 - Mar 2021 (5 months)
Migrated 80+ SaaS and on-premises applications from ADFS SSO to Azure AD, implementing AAD Connect Sync/Cloud Sync, SCIM-based provisioning, and Conditional Access/RBAC. Built OAuth 2.0 provider protections and automated user/group onboarding with PowerShell and Microsoft Graph API.
Implemented a Terraform-driven GCP deployment of F5 instances across 3 zones for high availability, including health checks, static/NAT IPs, SSH key setup, and automated F5 onboarding. Configured FedRAMP FIPS-2 compliant settings, APM module, HA, and modularized Terraform for repeatable environment provisioning.
Designed and implemented AWS and GCP security and infrastructure patterns, including EC2 automation with IAM roles and SSM profiles and Terraform-based DevSecOps workflows. Automated certificate lifecycle and encryption controls using AWS PKI/KMS, Venafi, AWS ACM, LetsEncrypt/Certbot, and GCP KMS/IAM for encrypted workloads and compliant key management.
Led a team of 8 cloud architects delivering 2+ dozen complex customer projects spanning AWS, Azure, and GCP landing zones, security audits, and cloud migrations. Provided FinOps cost-optimization and migration readiness assessments using multi-cloud governance, monitoring, and rightsizing tooling.
Containerized a .NET/SQL Server gas monitoring sensors application using Docker (Compose/Swarm) with production-ready Dockerfiles for SSL/TLS and Windows gMSA configuration. Automated host configuration via PowerShell and delivered monitoring and CI/CD using Prometheus-based container metrics and ADO pipelines.
AWS Cloud Migration Architect
DSHS
Jun 2013 - Jan 2017 (3 years 7 months)
Conducted cloud readiness and migration strategy discovery by assessing ~200 applications (COTS/SaaS/custom) and mapping on-prem-to-cloud dependencies. Performed security architecture activities including HP Fortify/WebInspect assessments, WAF PoCs, IAM evaluations, and performance troubleshooting with centralized reporting via Tableau and CMDB approaches.
Education
Degrees, certifications, and relevant coursework
Cornell University
Master of Engineering, Electrical Engineering
1995 - 1996
Completed a Master of Engineering in Electrical Engineering at Cornell University. (1995–1996)
University of Florida
Master of Science, Physics
1992 - 1995
Completed a Master of Science in Physics at the University of Florida with a full assistantship. (1992–1995)
Angelo State University
Bachelor of Science, Physics and Mathematics
1988 - 1992
Earned a B.S. in Physics and Math at Angelo State University as a full scholarship recipient. (1988–1992)
Tech stack
Software and tools used professionally
Splunk
AWS Glue
Data Studio
Dialogflow
Azure RBAC
Microsoft Azure
CloudCheckr
GitHub
Docker Compose
Docker Swarm
GitHub Actions
Salesforce
Jupyter
F5
DB
Hadoop
Node.js
.NET
Terraform
Visual Studio
Azure DevOps
JavaScript
Java
ASP.NET
PowerShell
Log4j
WCF
Prometheus
Linux
Windows
New Relic
Prisma
AWS WAF
Qualys
Zscaler
CrowdStrike
Sophos
OpenSSH
AWS Lambda
JUnit
OAuth2
sso
Bandwidth
NGINX
Root Cause
Typemock
SQL
XGBoost
AWS Trusted Advisor
Coupa
Port
Wiz
Imperva
Bash
Aqua Security
Enhance
Loops
Column
Cloud-Init
Task
Factory
Matrix
Remote
Vital
Safe
Method
Numeric
Jan
Phrase
X++
ASP.NET MVC
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Anuj?
You can contact Anuj and 90k+ other talented remote workers on Himalayas.
Message AnujFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
