NF_ NICHOLAS FERNANDOPORTFOLIO / 2026
CLOUD SECURITY ENGINEER

Cloud.
Security.
Engineered.

I’m Nicholas Fernando. I work with Microsoft Azure to connect environments securely and bring clarity to cloud operations.

Explore my work ↗
MICROSOFT AZURENETWORK SECURITYOBSERVABILITY
THE SECURITY MINDSETAZURE ECOSYSTEM
Microsoft AzureCLOUD SECURITY
01ConnectivityNetworks & VPN
02VisibilityLogs & monitoring
03GovernanceSecurity-minded operations

Inside the
architecture.

01 — 09

SELECTED WORK / 2026

From governed cloud foundations to disaster recovery and security operations. Ordered by engineering scope, business relevance, and delivery evidence.

How the projects are ordered +

Projects are ordered by engineering breadth, business importance, and evidence of hands-on delivery. Effort labels are qualitative assessments of technical complexity, not logged hours. Business value describes relevance, not measured financial returns. Completed configuration, operational investigation, and proposed work are labeled separately.

01 / CLOUD FOUNDATIONDeployed foundation · Ongoing configuration

Enterprise Azure landing zone

A multi-subscription Azure foundation that separates shared platform services from identity, virtual desktops, and business workloads.

Platform & workload separation
Management groups organize platform and workload subscriptions. Shared management, hub connectivity and identity support AVD and business application landing zones.
Anonymized logical view · Not every policy or workload is confirmed complete
TerraformAzure FirewallAzure PolicyHub & spoke
Read case study +
ENGINEERING EFFORTVery highBUSINESS VALUEPlatform governance & reusable foundations

Broadest platform scope, with explicit confirmation of deployed subscriptions and detailed configuration work.

Challenge

Establish a governed Azure platform with clear separation of shared services and application workloads.

My work

Worked through Terraform-based subscription organization, hub-and-spoke connectivity, firewall IP Groups and rule collections, identity networking, and diagnostic-policy configuration. The history explicitly confirms that the platform and workload subscriptions had been deployed.

Project status

Deployed subscription foundation documented. Later conversations cover policy troubleshooting, firewall configuration, and planned workload enablement; those individual changes are not all treated as verified complete.

02 / BUSINESS CONTINUITYOperational DR · Recovery engineering

Hyper-V to Azure disaster recovery

Hands-on Azure Site Recovery work spanning replication, storage behavior, failover readiness, and difficult Hyper-V failback troubleshooting.

Replication & recovery lifecycle
Hyper-V virtual machines replicate to Azure storage under Azure Site Recovery orchestration. Azure recovery VMs are used during failover, and synchronized failback returns workloads to Hyper-V.
Logical DR flow · No achieved RPO/RTO or final recovery result claimed
Azure Site RecoveryHyper-VRecovery Services VaultVPN
Read case study +
ENGINEERING EFFORTVery highBUSINESS VALUEBusiness continuity & recovery readiness

High-stakes, cross-platform work supported by operational replication logs, disk diagnostics, and recovery planning.

Challenge

Maintain recoverability for on-premises workloads while preparing Azure operation and a controlled return to Hyper-V.

My work

Investigated replication interruptions and churn-related concerns, reviewed storage isolation, and worked through Hyper-V disk-chain diagnostics during failback troubleshooting. Prepared failover/failback planning, VM sizing, networking dependencies, and a separation of ongoing DR costs from failover compute costs.

Project status

The recovered chats demonstrate an operating DR environment and hands-on troubleshooting. A relocation failover plan was prepared; the records reviewed do not establish a completed final recovery, validated recovery-time target, or recovery-point target.

03 / INFRASTRUCTURE AS CODEImplemented controls · Operational tuning

Terraform application landing zone

An Azure application and SQL environment with network controls, workload protection, and monitoring brought together through infrastructure engineering.

Application platform & operational services
Application and SQL virtual machines form the workload platform. Azure Monitor collects operational telemetry, while Azure Backup provides the SQL protection service. Network security controls govern connectivity.
Simplified service relationships · Not a complete traffic or firewall map
TerraformAzure VMsAzure BackupAzure Monitor
Read case study +
ENGINEERING EFFORTHighBUSINESS VALUEWorkload protection & operational consistency

Implementation evidence includes applied network restrictions and live monitoring associations, with backup and alerting configuration work.

Challenge

Configure a production application foundation with workload monitoring, constrained connectivity, and database protection.

My work

Worked on the Terraform landing zone, SQL egress restrictions, Azure Monitor Agent and Data Collection Rule associations, backup-policy setup, and alert-gap review. Follow-up troubleshooting addressed missing performance data and SQL backup connectivity.

Project status

The chats contain a user-confirmed NSG restriction and actual monitoring associations. Backup configuration and initial-job monitoring were discussed; restore validation and completion of every recommended alert are not established.

04 / SECURITY OPERATIONSDeployment planning + Live workspace analysis

Microsoft Sentinel architecture & investigation

Security telemetry architecture, cost-aware onboarding, and KQL-based incident investigation across Sentinel and Log Analytics.

Security & operations telemetry separation
Security telemetry is routed to a Sentinel-enabled workspace for detection and incidents. Operational telemetry is routed to a separate monitoring workspace. Proposed automation handles notifications.
Proposed deployment architecture · Existing-workspace analysis is separate
Microsoft SentinelKQLLog AnalyticsAutomation design
Read case study +
ENGINEERING EFFORTHighBUSINESS VALUEThreat visibility & incident reporting

Security relevance is high, with direct evidence of investigation in an existing Sentinel workspace; the new deployment remains a documented plan.

Challenge

Scope a useful SIEM deployment without mixing all operational data into security ingestion, and turn alert records into meaningful incident reporting.

My work

Prepared a deployment plan covering separate security and monitoring workspaces, source onboarding, analytics, access, automation, and ingestion governance. In a separate existing Sentinel workspace, investigated domain-related records and developed correlation between alerts and incidents instead of equating raw log counts with incidents.

Project status

Deployment architecture and investigation work are documented. The recovered evidence does not confirm completed rollout of the new Sentinel environment or the final incident-report results.

05 / NETWORK SECURITYMigration preparation

Azure site-to-site VPN migration

Preparing secure Azure connectivity for multiple remote sites, with configuration mapping and a coordinated cutover approach.

Target connectivity
Three remote sites connect through IPsec tunnels to an active-active Azure VPN Gateway and an Azure virtual network.
Simplified target architecture · Cutover not verified
Azure VPN GatewayIPsec / IKEVirtual Network
Read case study +
ENGINEERING EFFORTHighBUSINESS VALUESecure hybrid connectivity

Multi-site migration preparation with concrete Azure-side configuration work.

Challenge

Move existing site-to-site connectivity toward an Azure gateway while preserving compatibility with remote environments.

My work

Reviewed existing VPN settings, mapped remote-site requirements, and prepared Azure-side resources and configuration documentation. Planning covered gateway peers, IPsec/IKE compatibility, and connectivity dependencies.

Project status

Azure-side preparation and documentation were recorded. Remote configuration, validation, and final cutover were still to be coordinated.

06 / CLOUD OBSERVABILITYInvestigation & recommendations

AKS logging & ingestion analysis

Tracing log volume from the workspace down to application containers to identify noise, cost drivers, and logging-governance concerns.

Telemetry & investigation flow
AKS application logs flow to Azure Log Analytics, where KQL analysis examines volume, severity, and dependencies to inform logging recommendations.
Logical analysis view · No savings claimed
Azure Kubernetes ServiceLog AnalyticsKQL
Read case study +
ENGINEERING EFFORTMedium–highBUSINESS VALUELogging governance & targeted optimization

Evidence-led workload analysis provides actionable insight without unverified savings.

Challenge

Determine which workloads were driving ingestion and where collection could be improved without losing useful operational data.

My work

Investigated query exports across tables, clusters, namespaces, containers, and severity levels. Identified concentrated ingestion and raised logging-governance concerns for application-team review.

Project status

Produced targeted optimization recommendations. The project record supports analysis and potential improvements, not verified post-change savings.

07 / RESOURCE LIFECYCLEPlanning & tracked cleanup

Backup planning & resource cleanup

Connecting resource inventory, database export planning, and ownership review to make legacy-resource cleanup more deliberate.

Planned data-preservation workflow
Database services are mapped to an appropriate export or logical dump method, with files destined for Azure Blob Storage. Resource ownership and preservation review inform cleanup decisions.
Planning view · Backup and restore completion not verified
Azure SQLMySQL / PostgreSQLBlob Storage
Read case study +
ENGINEERING EFFORTMedium–highBUSINESS VALUEData preservation & controlled cleanup

Tracked cleanup progress and ownership review provide stronger delivery evidence than a topology proposal alone.

Challenge

Understand legacy resources and plan data preservation before continuing cleanup.

My work

Reviewed a resource-analysis tracker, mapped database categories to export approaches, and tracked cleanup progress. Resources with unclear identity or ownership remained pending clarification.

Project status

Cleanup progress was documented alongside unresolved items. Export, backup verification, and restore testing are not presented as completed deployments.

08 / HYBRID ARCHITECTUREArchitecture proposal

Dual-path hybrid VPN design

Mapping independent on-premises and Azure connectivity paths so stakeholders can understand how remote sites connect to both environments.

Proposed hybrid topology
An on-premises FortiGate connects to Azure VPN Gateway. Each of three remote sites has a path to the FortiGate and a separate path to Azure, making seven proposed logical connections.
Proposed design · Logical connections, not confirmed failover
Azure VPN GatewayFortiGateSite-to-site VPN
Read case study +
ENGINEERING EFFORTHighBUSINESS VALUEResilient network design

A technically broad dual-path proposal; ranked below more directly evidenced implementation work.

Challenge

Communicate a hybrid network proposal without confusing independent paths with duplicate tunnels.

My work

Iterated on a topology diagram showing an on-premises firewall, Azure VPN Gateway, and remote sites. Corrected connection origins and used distinct line styles to separate Azure paths from on-premises paths.

Project status

Documented a proposed topology with seven logical site-to-site connections. The diagram does not assert completed deployment, automatic failover, or measured availability.

09 / CLOUD OPTIMIZATIONOptimization planning

Application Gateway capacity review

Balancing capacity and cost through staged changes, traffic analysis, and operational checks rather than sizing from backend count alone.

Traffic path & capacity feedback
Client requests pass through Azure Application Gateway to a backend pool. Monitoring of gateway capacity, errors, and latency informs staged autoscaling decisions.
Simplified review model · Validation still required
Application GatewayAzure MonitorAutoscaling
Read case study +
ENGINEERING EFFORTMediumBUSINESS VALUECapacity efficiency & service stability

A focused capacity-review scope with benefits dependent on monitoring and validation.

Challenge

Evaluate gateway capacity while retaining headroom for variable traffic and business peaks.

My work

Reviewed autoscaling limits, reserved capacity, and the difference between a scale-out ceiling and the minimum capacity baseline. Developed a staged monitoring and rollback approach.

Project status

Prepared a capacity-review approach. Further reductions were conditional on observed health and demand; no quantified savings or performance improvement is claimed.

THE ENGINEER

Practical engineering.
Security at the core.

I’m Nicholas Fernando, a Cloud Security Engineer working primarily with Microsoft Azure. My work brings together secure connectivity, operational visibility, and practical cloud engineering.

These case studies summarize engineering work developed with ChatGPT assistance. Customer identities, credentials, and infrastructure identifiers are omitted.

Download diagram ↓