Download as PDF
DIPANKAR HALDAR
Principal Solution Architect · Cloud Platforms, IoT & Digital Twins
📞 +49 1522 8497851 ✉️ pophitu@gmail.com 🌐 blog.dipankar.de 💼 linkedin.com/in/dihaldar 🐙 github.com/pophitu
Microsoft Certified: Azure Solutions Architect Expert
Microsoft Certified
Azure Solutions Architect Expert
EXECUTIVE SUMMARY

Principal-caliber Solution Architect with 20+ years designing and delivering cloud-native, enterprise-scale platforms across Azure, DevOps, and integration ecosystems. Currently architecting and co-owning a shared, multi-tenant Azure platform (Front Door + WAF, API Management, a shared Container App Environment, Redis Enterprise, Service Bus, and Key Vault) that underpins six downstream business platforms, alongside the dedicated infrastructure for one of its flagship tenants — a project-management platform spanning networking, SQL, storage, messaging, and Dapr-based event-driven services. Deep expertise in IoT architecture, device management, and digital-twin–driven systems, enabling resilient, data-centric, and scalable connected-device ecosystems. Proven ability to set technical direction across teams, modernize infrastructure, enforce architectural governance through automated tooling (dependency boundaries, 99% test-coverage gates, security scanning), and build secure, high-performance platforms for financial, global, and mission-critical environments.

Specialized in: Azure Platform & Landing-Zone Architecture, Infrastructure as Code (Pulumi/TypeScript), Multi-Tenant Shared Platforms, IoT & Device Management, Digital Twins, Event-Driven & Dapr-Based Architecture, Python, Docker, Bash, PowerShell, CI/CD Pipeline Engineering, Integration Architecture, Enterprise Design Thinking, Zero-Trust Network Segmentation, DevSecOps Governance.

PROPRIETARY & ARCHITECTURAL PRACTICE
Design Thinking (Enterprise) — Expert

Certified practitioner of Enterprise Design Thinking, applying architectural-thinking techniques to translate business processes into integrated design frameworks, combining design-led approaches with analytics for intelligent solutioning.

Architectural Methods

Skilled in scenario modeling and modular decomposition of complex, multi-layered systems.

Architectural Patterns

In-depth exposure to reusable architecture patterns and enterprise design best practices.

10+ years of extensive experience applying Design Thinking, Enterprise Design Thinking and Architectural Thinking, coupled with data-science and big-data-analytics methodologies, across roles as Application Architect, Technical Lead, Data Modeler and Data Migration Solution Architect. Certifications and training achieved on the above proprietary tools, methodologies and practices.

PROFESSIONAL ROLES & RESPONSIBILITIES
Microsoft Azure Solution & Platform Architect

Proven ability to translate complex business requirements into secure, scalable Azure blueprints and end-to-end architectural roadmaps, including shared multi-tenant landing zones consumed by several downstream platforms. Deep, practical expertise across Azure IaaS, PaaS, networking, identity, and enterprise-grade governance. Strong command of modern authentication/authorization patterns — Entra ID, managed identities, OAuth2, OpenID Connect, RBAC/ABAC, and workload-identity federation — implemented programmatically and through native platform capabilities. Adept at designing IoT and device-management solutions, integrating Azure IoT Hub, DPS, and Azure Digital Twins to build secure, high-fidelity device ecosystems. Experienced in architecting resilient integration patterns leveraging event-driven architectures, API management, service buses, Dapr building blocks, and distributed systems to safeguard platforms against threats while ensuring operational continuity.

Microsoft Full-Stack Engineer

Extensive hands-on proficiency across the Microsoft ecosystem, including .NET Framework, .NET Core, ASP.NET, C#, and SQL Server. Strong engineering capability across cloud-native, API-driven, and microservices architectures. Highly effective in scripting, automation, and operations engineering using PowerShell, Bash, and modern DevOps toolchains. Skilled at building performant, maintainable, and secure applications spanning web, services, data, and device-interaction layers — supporting end-to-end scenarios from application tier to IoT edge workloads.

PROJECT PROFILE
1. Germany — B4C Shared Platform & PDPM (Digital Project Management)
01/2024 – Till Date · Role: Solution / Platform Architect

Own the architecture of two closely related Pulumi (TypeScript) programs: B4C, a shared multi-tenant Azure platform consumed by PDPM and five other downstream business platforms (UCC, VRIDS, NTPDG, DoIT, AquaScan), and PDPM, the Digital Project Management platform used by all project participants — client, contractor and sovereign functions — to plan, test, implement and monitor infrastructure projects. B4C provisions the shared Front Door + WAF, API Management, Container App Environment, Container Registry, Redis Enterprise cache, Service Bus namespace, Key Vault, Storage and Log Analytics workspace that every tenant platform builds on. PDPM is split into two independently deployed Pulumi stacks — pdpm-core (SQL Server with an elastic pool across seven databases, TDE encryption and private endpoints, storage accounts, networking, Service Bus, Key Vault with RBAC authorization) and pdpm-component (Function Apps, Container Apps, a Static Web App admin portal, Logic Apps and Dapr pub/sub, state-store and cron-binding components) — with the architectural boundary between the two mechanically enforced at build time via dependency-cruiser so platform and application concerns cannot leak into one another.

Tools & Technology: Azure (Front Door/WAF, API Management, Container Apps, Function Apps, Static Web Apps, SQL Elastic Pool, Service Bus, Key Vault, Redis Enterprise, Log Analytics), Pulumi (TypeScript), Dapr, Docker, Bash, PowerShell, Azure DevOps, GitHub Advanced Security, Renovate, Vitest.
  • Serve as solution, integration and infrastructure architect for both the shared B4C platform and the PDPM tenant, across six environments (AU, AU1, EU1, EU2, PU1, TU1).
  • Designed the two-stack (core/component) split for PDPM and the accompanying StackReference-based cross-stack output contract, so platform/data infrastructure and business-domain application hosting evolve and deploy independently.
  • Architected the shared B4C platform's multi-tenant network topology — Front Door + WAF, API Management, and a shared Container App Environment — serving as the common ingress and compute fabric for six downstream business platforms.
  • Designed secured, segmented network architectures with private endpoints, NSGs, firewall rules and zero-trust-aligned controls across subnets for API Management, private endpoints and the delegated Container App Environment.
  • Implemented identity and access management with OAuth2, Entra ID and workload-identity/federated authentication patterns, and RBAC-authorized Key Vault access consumed via managed identities.
  • Designed event-driven integration using Service Bus topics/queues and Dapr pub/sub, state-store and cron-binding components, decoupling business-domain services (workflow, project, email, model management, SharePoint permissions, Teams, transfer jobs) from one another.
  • Maintained enterprise-grade security posture: encryption at rest and in transit, TDE on SQL, secure configuration baselines, GitHub Advanced Security scanning, and automated dependency updates via Renovate.
  • Planned and implemented disaster-recovery strategy, high-availability configuration and scheduled backup/restore pipelines for critical SQL and storage resources.
  • Enforced engineering governance: TypeScript across both repositories, ESLint + Prettier, a 99% line/branch/function test-coverage gate on all infrastructure code via Vitest with Pulumi runtime mocks, and JSON-Schema-validated (Ajv) per-environment configuration as the single source of truth.
  • Redesigned and optimized Azure DevOps CI/CD pipelines (validate → preview → deploy), including plan-based pulumi up --plan deployments, scheduled drift detection, and manual maintenance-mode toggles for API Management and Front Door WAF.
  • Authored architecture, pipeline and pub/sub documentation (Mermaid diagrams) consumed by every team building on the shared platform, and repo-level agent skills that let engineering teams and AI coding agents navigate the platform boundary safely.
  • Delivered Proofs of Concept to validate architecture decisions and gave engineering teams a clear source of truth; provided ongoing architectural guidance to management and development teams, shaping long-term roadmap and technology strategy.
  • Wrote automation scripts in Bash and PowerShell for operational efficiency, compliance enforcement and lifecycle management; used Docker for secure development, testing and deployment workflows.
  • Troubleshot and resolved complex multi-layer issues spanning networking, infrastructure, identity and application domains across both platforms.
2. Germany — Single Supervisory Mechanism
11/2021 – 12/2023 · Role: Senior Software Developer / IT Architect

The Single Supervisory Mechanism is the legislative and institutional framework under which the European Central Bank directly supervises larger banks and indirectly supervises smaller ones.

Tools & Technology: Azure Kubernetes Service, Redis, GitLab, Docker, Azure KeyVault, App Configuration, Azure Service Bus, Azure Functions, Bash, PowerShell, Linux, Datadog, HashiCorp Vault, React 16 (Redux/Flux), TypeScript, Sass/Less, Cypress, Selenium, C#, ASP.NET Core 6, SQL Server 2019, SSRS, SSIS, TFS, Elasticsearch/Kibana, SonarQube.
  • Migrated an on-premises application and its components into Azure Kubernetes Service; prepared Dockerfiles and published images to a jFrog Artifactory Docker registry.
  • Configured Docker Compose to pull and run images, and set up environment variables, certificates, port routing and secrets synchronized from HashiCorp Vault into Azure Key Vault.
  • Set up CI/CD pipeline jobs in GitLab YAML, and wrote Bash/PowerShell scripts to support the GitLab runner during build and deployment.
  • Redesigned and re-architected existing applications for cross-platform operation (Windows and Linux).
  • Migrated RabbitMQ messaging into Azure Service Bus, and redesigned console-app components into Azure Functions for serverless execution.
  • Developed and maintained the software as a member of a scrum team, engaging with multiple scrum teams to orchestrate activity, take ownership, and drive solutioning and improvements.
  • Provided day-to-day technical support on issue triage and resolution.
3. CIBC, Canada — Cheque Day 1
10/2019 – 06/2021 · Role: Application Architect, Integration Architect, Azure Solution Architect

A Remote Deposit Capture application that publishes scanned cheques to Cheque Day 1, which decides whether internal or external processing applies via rigorous validation before publishing to Cheque Day 2 or external services.

Tools & Technology: MS Visio, MS Office, MS TFS, XML.
  • Designed the Azure infrastructure for migrating the Cheque application.
  • Designed interfaces for integrations across Windows, Mainframe and Linux systems on the cloud platform.
  • Engaged with multiple teams to orchestrate activity, take ownership, and drive solutioning.
  • Managed architecture and design of the application's various components, and coordinated architecture deliverables across teams.
  • Provided day-to-day technical support on issue triage and resolution.
4. Shop Direct, UK — NCE
01/2016 – 08/2019 · Role: Application Architect, Integration Architect, Data Migration Solution Architect

Shop Direct Group is a multi-brand online retailer in the UK and Ireland, based in Liverpool. The project implemented a new credit platform to support business modernization, process automation, and faster, more flexible credit-offering delivery.

Tools & Technology: Visual Studio 2015, Uniface 9, SQL+, MS Visio, Mindmap, MS Office, SoapUI, .NET, C#, WCF, Uniface, Oracle, MS TFS, XML.
  • Architected a new finance platform, a key component of the client's drive to deliver more personalized customer journeys and a broader range of credit offerings.
  • Delivered quality design documents to help the client understand business behavior and align stakeholders around a single requirements timeline.
  • Engaged with multiple teams to orchestrate activity, take ownership and drive solutioning.
  • Drove successful completion of data migration through proactive collaboration, exchanging technical expertise and business-process knowledge with the team.
  • Guided technical staff working across geographically distributed and offshore teams.
5. UBS Group AG, Switzerland — Dragon
02/2013 – 12/2015 · Role: Senior System Analyst

UBS is one of the largest banks in Switzerland. Internal bank operations are performed through various in-house applications across segments such as tax, risk, branding, data protection, legal and compliance.

Tools & Technology: Visual Studio 2015, SQL Server Management Studio, MS Visio, MS Office, ServiceNow, Tortoise SVN, .NET, C#, SQL Server 2008, MVC, Web Services, Web API, XML, JavaScript.
  • Performed requirement analysis, feasibility analysis and technical evaluation.
  • Wrote use cases, technical design documents and functional test cases.
  • Contributed to development, including system/architecture design tweaks, and helped the team understand requirements through functional and technical discussion.
  • Managed the deployment process and schedule.
6. PMI, Switzerland — ISMS
08/2010 – 01/2013 · Role: System Analyst

PMI is a global cigarette and tobacco company with products sold in over 200 countries. ISMS was the client's main sales and merchandising tool, customized per country to reflect local government rules and regulations; assigned to Russia, Hong Kong and Taiwan.

Tools & Technology: Visual Studio 2010, SQL Server Management Studio, MS Visio, MS Office, ServiceNow, IBM ClearCase, HP Service Desk, .NET, C#, SQL Server 2005, Web Services, XML.
  • Presented ideas for system improvements and worked closely with analysts, designers and staff.
  • Produced detailed specifications and wrote the code.
  • Tested the product in controlled, real-world scenarios prior to go-live.
  • Prepared training manuals for users and maintained the systems once operational.
7. Wyndham Hotel Group, USA — HMS
11/2009 – 07/2010 · Role: Programmer Analyst

Wyndham Worldwide Corporation is the holding company for Wyndham Hotels & Resorts, Group RCI and other lodging brands. HMS, the main Hotel Management System, maintained room and rate data for global publication alongside reservations and interfacing with legacy systems.

Tools & Technology: Visual Studio 2005, SQL Server Management Studio, MS Office, .NET, C#, SQL Server 2005, MS TFS, MS CAB Framework, Web Services, XML.
  • Presented ideas for system improvements and worked closely with analysts, designers and staff.
  • Produced detailed specifications and wrote the code.
  • Tested the product in controlled, real-world scenarios prior to go-live.
  • Prepared training manuals for users and maintained the systems once operational.
8. Lilisoft Medical LLC, USA — LILISOFT
04/2007 – 10/2009 · Role: Application Programmer

Lilisoft is an American medical company. The Lilisoft application functioned as a complete Clinical Information System managing medical records, reports and documents per patient, and processing claims to a standardized format, achieving compliance across six HIPAA modules relevant to Lilisoft Medical's line of business.

Tools & Technology: Visual Studio 2003, SQL Server Management Studio, MS Office, .NET, C#, SQL Server 2003, MS VSF, Web Services, XML, JavaScript.
  • Presented ideas for system improvements and worked closely with analysts, designers and staff.
  • Produced detailed specifications and wrote the code.
  • Tested the product in controlled, real-world scenarios prior to go-live.
  • Prepared training manuals for users and maintained the systems once operational.
TECHNICAL SKILLS
LanguagesC#, Python, JavaScript/TypeScript, React, Bash, PowerShell
CloudMicrosoft Azure (IaaS/PaaS, networking, identity, governance)
IaCPulumi (TypeScript)
ContainersDocker, Kubernetes, Azure Container Apps
Frameworks.NET, .NET Core, MVC, WCF, Web API, Dapr
DatabasesSQL Server, Oracle
MessagingAzure Service Bus, RabbitMQ, Event Grid
DevOpsAzure DevOps, GitLab CI/CD, YAML pipelines, GitHub Advanced Security, Renovate
TestingVitest, Cypress, Selenium, SonarQube
ToolsGit, VS Code, Visual Studio, Microsoft Visio
IdentityEntra ID, OAuth2, OpenID Connect, RBAC/ABAC, Managed Identities
OSWindows, Linux, Mainframe
Azure Landing Zones Multi-Tenant Platforms IoT Hub & DPS Azure Digital Twins Front Door & WAF API Management Zero-Trust Networking Event-Driven Architecture Disaster Recovery & HA DevSecOps Governance
CERTIFICATIONS
Microsoft Certified: Azure Solutions Architect Expert
Microsoft Certified: Azure Solutions Architect Expert
View credential — learn.microsoft.com/.../credentials/e6cd40e0ec78d3c
ACADEMIC PROFILE
Degree Year Board / University Percentage Class
Bachelor of Engineering (Computer Science & Engineering) 2004 Burdwan University 60% I
XII (Science) 2000 West Bengal Council of Higher Secondary Education 64% I
X 1998 West Bengal Board of Secondary Education 80% I
DECLARATION

I hereby declare that the details provided above are true to the best of my knowledge.

(DIPANKAR HALDAR)