Expertise

The areas I work in, in the order I came to them.

Choose an area

Software engineering

Frequent

TypeScript and Node.js, C#, Python, Bash, REST APIs. I was a developer before moving to architecture, and I never left the code behind: I still build small internal tools, bespoke integrations on request as a side job, and personal side projects.

Identity and access governance

Daily

Entra ID in multi-tenant and cross-tenant B2B scenarios: Conditional Access, Identity Governance, Azure Lighthouse. Automations run on Workload Identity Federation, with no standing secrets. For access we use RBAC and managed identities exclusively, in place of credentials; every legacy access has a migration already scheduled.

Azure cloud architecture

Daily

I design Azure solutions for complex multi-tenant, multi-customer environments: I size them at proposal stage, costs included, and follow them through to production. I manage the infrastructure as code, and in day-to-day operations I use Bash and PowerShell, with n8n backing flows and monitoring.

Infrastructure as Code and delivery

Daily

I write Terraform as a private library: reusable, versioned modules shared across repositories. Pipelines live on Azure DevOps and GitHub Actions, authenticated with OIDC and no standing credentials, and any potential drift is watched by a scheduled audit.

FinOps

Frequent

I map the spend and bring it back to the right size: recurring right-sizing of databases across tenants, root-cause analysis of cost anomalies, cleanup of resources nobody uses any more. Major migrations are validated with benchmarks on real workloads before production is touched, with a rollback plan ready.

Systems with AI components

Frequent

I stand up the infrastructure for solutions built on language models and agents, and I bring AI into workflows and day-to-day operations. The delicate part is governance: minimal permissions, traceability, and a clear boundary between what the model decides and what stays deterministic.

Compliance and hardening

Frequent

I work in regulated environments, where NIS2 enters the design from day one. The rules travel with me: least privilege, reversible changes, documented decisions.

© 2026 CRISTOPHER TURAZZA
ENIT