Cloud & Network Engineering Intern
Occident (Grupo Catalana Occidente) · Cloud & Networks Team
Worked within the team responsible for hybrid connectivity and network security policies of a regulated insurance company (on-prem CPDs + Azure, ~50 networks across dev/pre/prod and 2 tenants).
- Migrated manually-managed cloud networking (VNets, peerings, routes, firewall rules, DNS) to reproducible Terraform modules with remote state and locking.
- Implemented SDN governance with Azure Virtual Network Manager: network groups, centralized connectivity, routing and security admin rules, IPAM.
- Operated hybrid perimeter security: Check Point firewalls on-premises (SmartConsole) alongside Azure Firewall Premium for centralized traffic inspection.
- Managed enterprise DNS end to end: Windows Server DNS on-premises integrated with Azure Private DNS zones and conditional forwarding for hybrid name resolution.
- Built GitOps workflows for network changes: plan review, controlled apply, drift detection and post-change verification.
- Contributed to the Zero Trust access architecture (identity- and context-based access, private endpoints, private DNS, Global Secure Access).
- Designed and validated Hub & Spoke topologies per environment, hybrid connectivity (VPN/ExpressRoute), app publishing with Front Door, AKS private networking and observability.