TEHUTI EKEMA
Azure Solutions Architect

I design secure cloud solutions and hybrid infrastructure.

Certified Azure Solutions Architect with a Secret clearance, building secure, survivable systems for federal agencies and global enterprises, from stretched on-prem clusters to compliant delivery pipelines.

Clearance
Secret
Focus
Secure cloud / hybrid
Certs
5× Azure
Base
Texas
Selected work

Problem → architecture → outcome.

01 Cloud Architecture · Landing Zones

Complete Azure Landing Zone (CAF Hub & Spoke)

A full Cloud Adoption Framework Azure Landing Zone in Terraform and Azure Verified Modules, covering the management-group hierarchy, an enforced policy baseline, dual-region hub-and-spoke with Azure Firewall Premium, four platform subscriptions, and corp/online landing zones, all shipped through OIDC GitHub Actions with policy-as-code PR gates.

Personal build · 2026
Azure Landing ZoneCAFTerraformAzure Verified Modules
Read case study
02 End-User Compute · Landing Zones

Azure Virtual Desktop Landing Zone (Terraform + AVM)

A reference-grade AVD application landing zone built entirely from Azure Verified Modules in Terraform and shipped through OIDC GitHub Actions with no stored secrets. It is CAF-aligned, Entra ID-joined, private-only, and mapped against every Microsoft AVD design area.

Personal build · 2026
Azure Virtual DesktopTerraformAzure Verified ModulesGitHub Actions
Read case study
03 DevSecOps · Compliance

Secure CI/CD for Federal Workloads

Built and hardened CI/CD pipelines for multiple federal agencies, from application delivery to a multi-environment Azure data platform, folding code analysis and supply-chain scanning into the path to production, administering the GitHub organization (80+ repositories across ~10 applications), and holding the line on NIST and FedRAMP controls.

Procentrix · 2022–Present
GitHub ActionsAzure DevOpsSonarQubeGitHub Advanced Security
Read case study
04 Cloud Governance · Security

Governance & Secure Landing Zones

Operationalized the security pillar of the Well-Architected Framework into repeatable landing-zone guardrails, turning one-off security reviews into automated, baseline-enforced governance across Azure deployments.

Insight Global // IBM (Kyndryl) · 2019–2021
Landing ZonesEntra IDMicrosoft DefenderPurview
Read case study
05 Hybrid Cloud · Azure Local

Two-Site Stretched Azure Local Cluster

Designed and built a two-site stretched Azure Local (Azure Stack HCI) reference environment with storage-replica site-to-site replication and Azure Arc management, demonstrating edge infrastructure that survives the loss of a full site.

Dell Technologies · 2021–2022
Azure LocalAzure ArcStorage Spaces DirectStorage Replica
Read case study
What I do

Depth across the stack.

Architecture & Hybrid

  • Landing zones & governance
  • Azure Local / Stack HCI
  • Disaster recovery & BCDR
  • Network & identity design

DevSecOps & IaC

  • GitHub Actions / Azure DevOps
  • Terraform · Bicep · ARM
  • SonarQube / GH Advanced Security
  • Docker / Kubernetes security

Security & Observability

  • Sentinel · Defender · Purview
  • Entra ID & RBAC
  • Azure Monitor · Log Analytics · KQL
  • NIST · FedRAMP alignment
Open to senior architect & engineer roles contact@tehutiekema.com