
Hossam Abdelazim
Verified Expert in Engineering
Cloud Engineer and Developer
Cairo, Cairo Governorate, Egypt
Toptal member since July 29, 2025
Hossam is a Cloud and DevOps Architect specializing in AWS and Azure, with hands-on experience building scalable, secure, and automated cloud solutions. He designs multi-account architectures, implements IaC with Terraform, and builds CI/CD pipelines. Hossam works with Kubernetes, serverless, and integrates AI using Azure AI, with experience in observability and OpenSearch-based systems
Portfolio
Experience
- Terraform - 5 years
- Kubernetes - 5 years
- Amazon Web Services (AWS) - 5 years
- PowerCLI - 5 years
- Large Language Models (LLMs) - 4 years
- Microsoft Azure - 4 years
- Agentic AI - 3 years
- GitHub Copilot - 2 years
Preferred Environment
GitHub, Amazon Web Services (AWS), Microsoft Azure, Agentic AI, Microsoft Foundry, AWS Landing Zone, Azure Landing Zones, GitHub Copilot, Terraform, CI/CD Pipelines
The most amazing...
...thing I designed and deployed is an AI-powered cloud architecture combining low-latency 5G (AWS Wavelength) with applications for real-time processing.
Work Experience
Senior AI and Apps Solutions Engineer
Microsoft
- Designed and delivered end-to-end AI and app solutions leveraging Azure AI services (Azure OpenAI, Cognitive Services), improving customer solution adoption and time-to-value.
- Led technical pre-sales engagements, translating business requirements into scalable cloud architectures across AI, data, and application platforms.
- Built and demonstrated AI-powered use cases (e.g., copilots, automation workflows, intelligent search), enabling customers to accelerate digital transformation initiatives.
- Collaborated with enterprise customers to architect secure, scalable solutions aligned with Azure Well-Architected Framework and Zero Trust principles.
- Developed proof of concepts (PoCs) using Azure AI Foundry and modern app services, driving customer confidence and influencing technical decision-making.
- Advised customers on integrating AI into existing applications, enhancing developer productivity through tools like GitHub Copilot and automation frameworks.
- Optimized cloud architectures for cost, performance, and scalability, ensuring alignment with business KPIs and operational excellence.
Cloud Architect
The University of Colorado - Digital Collections AWS
- Designed and proposed a modern AWS-based architecture for CU Boulder’s Digital Library, replacing legacy LUNA systems with scalable, cloud-native services (EKS, S3, OpenSearch, and Aurora).
- Defined and implemented a bulk ingest workflow using S3, pre-signed URLs, SQS, and worker services, improving ingestion scalability and reliability for large digital assets.
- Architected a secure edge layer using CloudFront, WAF, and ALB to provide controlled, high-performance access to applications and APIs.
- Developed Terraform-based infrastructure aligned with strict governance (permission boundaries and PR approvals), enabling consistent and auditable deployments.
- Optimized a storage strategy using S3 lifecycle policies and object classification (master, derivative, and thumbnail), reducing long-term storage costs while maintaining accessibility.
- Integrated OpenSearch as a replacement for Solr, enabling faster and more scalable search capabilities across large metadata datasets.
- Designed identity integration using SAML federation and AWS services (Cognito and IAM Identity Center), ensuring secure access for both application users and administrators.
- Conducted MAP assessment and defined migration strategy, aligning business requirements with a scalable, cost-efficient AWS architecture.
- Identified and remediated security gaps (IAM over-permissions, logging, encryption, and backup strategies), improving overall platform security posture.
- Collaborated with cross-functional teams and stakeholders to validate architecture decisions and drive project progress through structured reviews and approvals.
AI and Cloud Infrastructure Architect
Vodafone Group
- Led Azure AI Translator integration with Copilot Studio, enabling multilingual chatbot support and reducing manual translation workload by over 60%.
- Designed and implemented a Redis hot-tier caching architecture that reduced Azure OpenAI and Translator API costs by 70-80% through response reuse and intelligent cache expiration.
- Architected enterprise-grade AI solutions using Azure AI Foundry, integrating private endpoints, secure networking, and role-based access controls aligned with Zero Trust principles.
- Built a RAG-based AI chatbot using Azure AI Search and Cosmos DB for vector storage, improving response relevance by 40% compared to baseline prompt-only models.
- Defined AI governance and responsible AI controls, including monitoring, prompt filtering, and access restrictions to ensure compliance with enterprise security standards.
- Collaborated with cross-functional teams to deliver AI PoCs from strategy to production, accelerating the AI adoption roadmap across internal stakeholders.
Senior Cloud Engineer
Orange Business Services
- Led the implementation and optimization of public cloud infrastructure on AWS, with a strong focus on infrastructure-as-code, automation, and secure service provisioning across multiple environments.
- Designed and managed Terraform-based deployments: modular architecture for reusable code, remote state management using an S3 back end with versioning and locking, and replacing GitLab storage to ensure better state integrity and collaboration.
- Implemented mutualized GitLab Runners using Kubernetes (self-hosted or managed).
- Configured and maintained GitLab CI/CD pipelines for infrastructure and application delivery.
Cloud Solution Architect
Orange Business Services
- Headed a mega project, Sonatel, for a big telecom provider in Senegal. Implemented their AWS Wavelength zone in the infrastructure to offer 5G mobile applications ultra-low latency, along with crafting a well-architected multi-account design.
- Enhanced our DevOps practices using GitLab runners on ephemeral Kubernetes pods instead of virtual machines for better customer isolation, performance, resource savings, and horizontal pod autoscaling.
- Managed and led a new project for a big medical entity, Alfa Scan, to host their website applications and API portals on Azure Kubernetes Service (AKS).
- Created runbooks for customer migrations to private or public cloud.
- Managed the private cloud utilizing VMware stack components such as VMware Cloud Director (VCD), NSX, vSphere, vSAN, VMware Cloud Foundation (VCF), and VMware Aria.
Infrastructure and DC Engineer
Network International for Payment Solutions
- Administered and optimized VMware infrastructure components, including vSphere, vSAN, vROPs, NSX, vSphere Replication, and Site Recovery Manager (SRM), to ensure high availability, performance, and disaster recovery capabilities.
- Ensured back-up policies, job automation, and successful recovery validation across environments.
- Implemented and supported hyper-converged infrastructure (HCI) using Nutanix AHV.
- Coordinated with platform, cloud, and DevOps teams to align virtualization and storage strategies with hybrid cloud architectures, especially AWS integration scenarios (e.g., storage gateway, backup to S3/Glacier).
- Applied infrastructure-as-code (IaC) principles, CI/CD readiness, and platform reliability practices, enabling future alignment with DevOps pipelines and cloud native operations.
Network and Security Engineer
Network International for Payment Solutions
- Administered and maintained enterprise-level network and security infrastructure, ensuring high availability, performance, and compliance across interconnected systems.
- Managed and resolved daily operational tickets involving network devices, including Cisco and Juniper routers/switches, ensuring rapid incident response and root cause analysis.
- Configured and troubleshooted Fortinet security solutions (FortiGate, FortiEMS, FortiAuthenticator), including the implementation of security policies and flows.
- Contributed to F5 LTM and GTM load balancers and configured and optimized L4/L7 load balancing for high-traffic web and application services.
Experience
Onboarding a Big Medical Entity to Azure (AKS)
AWS Wavelength Project in Dakar, Senegal
https://aws.amazon.com/about-aws/whats-new/2025/04/aws-wavelength-zone-dakar/Enterprise Multilingual AI Copilot with Azure AI Translator
To optimize cost and performance, I proposed and implemented a Redis-based hot-caching tier that stored translated responses and frequently used AI outputs, reducing repeated calls to the Azure OpenAI and Translator APIs. This approach resulted in a 70–80% reduction in AI operational costs while significantly improving response latency.
The solution followed Zero Trust and Responsible AI principles, leveraging private endpoints, managed identities, RBAC, and monitoring. This project accelerated AI adoption internally and served as a reference architecture for future AI initiatives.
Azure AI Foundry-based RAG Platform for Enterprise Knowledge Access
The solution was secured using private endpoints, identity-based access, and network isolation, ensuring compliance with enterprise security standards. I also introduced governance controls, including prompt filtering, monitoring, and usage tracking, aligned with Responsible AI guidelines.
This platform improved answer accuracy by over 40% compared to prompt-only approaches and established a reusable AI foundation for future copilots and intelligent applications across the organization.
Cloud Architect – AWS Digital Library Modernization (CU Boulder)
• Defined a bulk ingest pipeline using S3 pre-signed URLs, SQS, and worker services to improve scalability and reliability for large digital assets. Implemented a secure edge layer with CloudFront, WAF, and ALB for controlled, high-performance access.
• Developed Terraform-based infrastructure aligned with strict governance (permission boundaries, PR approvals), ensuring consistent and auditable deployments. Optimized storage using S3 lifecycle policies and object classification, reducing long-term costs.
• Integrated OpenSearch to replace Solr, improving search performance and scalability. Designed secure identity integration using SAML, Cognito, and IAM Identity Center.
• Led assessment and migration planning, while identifying and remediating security gaps across IAM, logging, encryption, and backups. Collaborated closely with stakeholders to drive architecture decisions and delivery.
Education
Bachelor's Degree in Communications and Computer Engineering
Helwan University - Cairo, Egypt
Certifications
GitHub Copilot GH-300
Microsoft
Oracle Cloud Infrastructure Certified Architect Associate
Oracle
Microsoft Certified: Azure Administrator Associate (AZ-104)
Microsoft
Certified Kubernetes Administrator
CNCF
AWS Certified Solutions Architect – Associate
Amazon Web Services Training and Certification
VMware Certified Professional - Network Virtualization 2022
Broadcom
VMware Certified Professional - Data Center Virtualization 2022
Broadcom
Fortinet Network Security Expert Level 4: Certified Professional
Fortinet
CCNA
Cisco
Skills
Libraries/APIs
Azure API Management, REST APIs, GitHub API
Tools
VMware, VMware vSphere, Terraform, Ansible, VPN, Azure Kubernetes Service (AKS), Azure Application Gateway, Amazon EKS, VMware vSphere HA, Amazon CloudWatch, Amazon Simple Queue Service (SQS), Amazon Simple Notification Service (SNS), AWS Step Functions, AWS CloudFormation, Amazon Virtual Private Cloud (VPC), Bitbucket, Azure Logic Apps, Observability Tools, AWS Batch, Helm, Logging, Amazon OpenSearch, GitHub Copilot, GitLab, PowerCLI, AWS Command Line Interface (CLI), GitLab CI/CD, GitHub, AWS CodeBuild, AWS CodeDeploy, Grafana, Amazon Elastic Container Service (ECS), Jenkins, AWS Cloud Development Kit (CDK), Claude Code, AWS IAM, Azure Key Vault, Kubernetes HorizontalPodAutoscaler (HPA), AWS Fargate, Distributed Resource Scheduler (DRS), Amazon Elastic Block Store (EBS), ELK (Elastic Stack), AWS CloudTrail, Azure App Service, Azure Monitor, Git, Microsoft AI, Kubectl, Azure Cache for Redis, Oracle Cloud Infrastructure (OCI) Generative AI, GitHub CLI
Languages
SAML, Python 3, Python, Bash, Bicep, Java
Frameworks
AWS HA, Pods.io, AWS Well-Architected Framework, Agentic Frameworks
Paradigms
DevOps, HIPAA Compliance, Continuous Integration (CI), Continuous Delivery (CD), DevSecOps, Azure DevOps, REST
Platforms
Ubuntu, Azure, AWS IoT, AWS ALB, Kubernetes, Amazon Web Services (AWS), Amazon EC2, AWS Lambda, Windows Server, Azure Functions, Microsoft Copilot Studio, SharePoint 365, Google Cloud Platform (GCP), Docker, Azure PaaS, VMware Tanzu, Linux, Unix, OpenStack, Azure AI Search, Azure AI Studio, Oracle, Oracle Cloud Infrastructure (OCI)
Storage
VMware vSAN, Amazon S3 (AWS S3), Microsoft Entra ID, Amazon DynamoDB, Microsoft SQL Server, Database Management, Elasticsearch, Azure SQL, Ingres, Amazon EFS, Azure Cloud Services, Redis Cache, Azure Cosmos DB
Other
IT Networking, Cloud, Virtualization, AWS Cloud Security, Microsoft Azure, Architecture, Design, VMware vCenter, VMware NSX, vCloud Director, VMware Aria Operations for Logs, Border Gateway Protocol (BGP), Routing, IPsec, SSL, AWS CodePipeline, Azure Virtual Machines, Containers, Virtual Private Cloud (VPC), Amazon GuardDuty, Identity & Access Management (IAM), AWS Config, VMware VMotion, VMware ESXi, Networking, Load Balancers, Web Application Firewall (WAF), Firewalls, Terraform Cloud, CI/CD Pipelines, Infrastructure as Code (IaC), AWS Cloud Architecture, GitHub Actions, Active Directory (AD), DHCP, Site-to-site VPN, Palo Alto Networks, API Gateways, Microsoft Entra, Cloud Architecture, AWS DevOps, AWS ECS Fargate, Network Engineering, Solution Architecture, Azure Virtual Networks, Azure sentinel, Microsoft defender for cloud, AWS Certified Solution Architect, Amazon EventBridge, System Administration, Linux System Administration, Networks, Windows System Administration, Enterprise Architecture, Active Directory Federation Services (AD FS), PKI, ECS, GitOps, Infrastructure Architecture, Infrastructure, Version Control Systems, Monitoring, AWS Monitoring, AWS Cloud Map, AI Tools, AI-assisted Development, GitHub Copilot Chat, HIPAA, SDKs, Microsoft 365, Migration, Compliance, System Architecture, Data Governance, Azure Administrator, Cloud Infrastructure, Agentic Coding, Data Labeling, High-level Design (HLD), VXLAN, GitHub Runners, Prometheus, APIs, Software Development Lifecycle (SDLC), AI Enablement, Large Language Models (LLMs), Microsoft Purview, Data Loss Prevention (DLP), Fintech, Retrieval-augmented Generation (RAG), Machine Learning, Full-stack, 5G, Azure VDI, Azure SSO, Azure land, Azure CLI, Azure Virtual WAN, Kubernetes Security, Amazon Inspector, Storage, Security, Cisco Switches, Open Shortest Path First (OSPF), Network Security, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Sandbox to Production, VMware vCloud, Tanzu Kubernetes Grid, vCF, Servers, Nutanix, AWS Organizations, AWS Landing Zone, AWS Control Tower, AWS Security Hub, RHEL, HP Enterprise (HPE), Amazon Bedrock, AWS Transit Gateway, Azure Virtual Network (VNet), Azure Blob Storage, Azure Stack HCI, Amazon RDS, Microsoft Foundry, Agentic AI, Agentic RAG Systems, Azure Cognitive Search, Responsible AI, AI Modeling, AI Model Integration, Presales, Azure Landing Zones, AI Landing zone, Containerization, Azure AI Custom Vision, Computer Vision, Natural Language Processing (NLP), Generative Artificial Intelligence (GenAI), RAG Architecture, Azure AI Translator, Azure foundry, Vector Search, OpenAI, Splunk Enterprise Security, Open-source LLMs, Azure Database for PostgreSQL, AI Copilots, Graphics Processing Unit (GPU), Amazon MemoryDB for Redis, GitHub Codespaces
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring