Open to Systems Administrator, Cloud & AI roles — Toronto

RohanDesai.

Systems Administrator & AI Engineer · Toronto

I run the infrastructure — and I build the AI that runs on top of it. Self-hosted, on hardware I own, with nothing leaving the network.

Scroll
Measured

Three years, one admin, real numbers.

Each figure below comes from a change I made and then measured — not an estimate.

−25%Infrastructure cost, after the Azure migration
−40%Manual admin workload, via PowerShell & Python
−30%Security incidents, six months after MFA & Conditional Access
50+Users supported as the only IT person
90%End-user satisfaction, sustained
The difference

Most people who run infrastructure don't build AI. Most people who build AI have never run infrastructure.

I do both, in the same building, on the same network. That's why the AI I ship actually survives contact with production — it runs on hardware I maintain, behind firewall rules I wrote, backed up by jobs I monitor.

Translation agent

Spec sheets and manuals into 15+ languages

Technical documentation is dense, illustrated and unforgiving — a mistranslated tolerance or a diagram that loses its caption becomes a support ticket at best.

  • Built an agent that translates full spec sheets and product manuals into more than fifteen languages
  • Preserves embedded images and their placement rather than flattening the document into raw text
  • Carries technical context across the translation so terminology stays consistent within and between documents
  • Runs entirely against the self-hosted model — no document ever reaches an external service
15+languages, images and layout intact
Operations agent

Log watch and backup verification

Backup jobs that report success and silently produce nothing are the classic way to discover a problem at exactly the wrong moment. So I stopped reading logs by hand.

  • Agent reads backup and system logs on a schedule and flags failures automatically
  • Surfaces anomalies — not just hard errors, but patterns that don't look like a normal run
  • Emails findings so problems arrive in my inbox instead of waiting to be discovered
  • Replaced a manual review that used to depend on someone remembering to do it
Dailyautomated verification, no manual review
Conversational

An internal chatbot

Built on the same self-hosted stack, so staff can ask questions of internal material without any of it reaching an outside provider.

  • Runs against the in-house Ollama deployment
  • Keeps internal knowledge inside the network by design
  • Built and iterated with Claude Code alongside hand-written Python
In-houseno third-party inference
Edge deployment

Agents small enough for a Pi — and a Jetson when they aren't

Not every workload deserves a server. Some of it belongs on the device, next to the thing it's watching.

  • Deployed lightweight agents onto Raspberry Pi devices at the edge
  • Worked with NVIDIA Jetson Orin Nano hardware where the workload needed local acceleration
  • Sits alongside the IoT environmental and equipment-monitoring sensors on segmented networks
  • Forced real discipline about model size, memory and what actually needs to run centrally
Edge-firstPi · Jetson Orin Nano · on-prem server
The environment I own

Four layers, no handoffs.

In an environment this size there is nobody to escalate to. This is the whole surface area I operate across — from a Conditional Access policy down to the VLAN the sensors sit on.

Identity & Endpoint

Who gets in, on what
Microsoft Entra IDIntuneAutopilot Conditional AccessMFACompliance policies Active DirectoryGroup PolicyIdentity lifecycle

Microsoft 365 & Cloud

Where the work happens
AzureExchange OnlineSharePoint TeamsOneDriveDefender Licensing & cost managementCopilot administration VMware vSphereHyper-V

Network & Voice

The building itself
Ubiquiti UniFiVLAN segmentationVoIP.ms Cisco MerakiFirewall rulesSite-to-site & client VPN DNS / DHCPSIP trunks & DIDsIVR & call routing

AI, Automation & Edge

The parts that run themselves
OllamaSelf-hosted LLMsAI agents Claude CodePowerShellPythonBash Jetson Orin NanoRaspberry Pi IoT sensor networksWindows ServerLinuxBackup & DR
Infrastructure work

The projects underneath it all.

Each started as a cost, a risk, or a task I was tired of doing by hand.

Cloud migration

On-prem workloads → Azure

Ageing on-premises servers carried real hardware risk and a maintenance bill nobody wanted to keep paying.

  • Planned and executed the move of VMs, storage and backup into Azure with minimal downtime
  • Rebuilt backup and disaster recovery around the new topology
  • Put ongoing cost management in place so spend stayed visible after cutover
−25%infrastructure cost
Identity hardening

MFA and Conditional Access, company-wide

A 50-user tenant with legacy sign-in habits is a phishing incident waiting to happen.

  • Rolled out MFA and Conditional Access across all users without stalling the business
  • Tightened identity lifecycle so accounts are created, changed and disabled on time
  • Paired it with Defender and hardened backup controls
−30%security incidents in six months
Endpoint management

Intune and Autopilot from scratch

Devices were being built by hand, which meant every laptop was a little different from the last.

  • Deployed Intune with compliance and configuration profiles across the fleet
  • Introduced Autopilot so new machines provision themselves
  • Moved application deployment off manual installs
−25%endpoint risk
Network & telephony

The office floor: UniFi, VoIP and IoT

Networking, telephony and shop-floor sensors are three problems most organisations this size outsource to three different vendors. I run all three.

  • Own the full UniFi estate — gateways, switches, APs, VLAN segmentation, firewall rules, VPN and Wi-Fi coverage
  • Run VoIP.ms end to end: SIP endpoint provisioning, DID management, IVR and call routing for office and remote staff
  • Deployed environmental and equipment-monitoring sensors on segmented networks
1person on call for all of it
Automation

Scripting the repetitive half of the job

Provisioning, patching and reporting were eating days that should have gone to real projects.

  • Automated user provisioning and offboarding with PowerShell
  • Scripted patching cycles and recurring reporting in PowerShell and Python
  • Automated backup verification so failures surface before they matter
−40%manual administration workload
Web platform

Corporate site replatforming

A public site on ageing WordPress is a maintenance and patching liability well before it is a design problem.

  • Led the migration off WordPress, including content and structure
  • Improved page performance and integration with the tooling the business actually runs on
  • Removed a self-managed CMS from the estate I had to keep patched
Retiredone self-hosted CMS and its patch surface
Independent practice

Four areas I take on independently.

Engagements are scoped end to end — assessment, build, documentation, handover — so the environment is maintainable by whoever inherits it rather than dependent on me.

Practice area

Microsoft 365 & identity architecture

Tenants are commonly deployed on defaults and left there. Defaults are a starting configuration, not a security posture.

  • Tenant design and migration, Entra ID, identity lifecycle and group strategy
  • Conditional Access and MFA baselines built in at the outset rather than retrofitted after an incident
  • Licence position reviewed against actual consumption
  • Intune and Autopilot for provisioning that doesn't depend on someone building each machine by hand
Delivered asdocumented baseline · policy set · handover
Practice area

Private AI deployment

Most organisations have material worth processing with a model and no appetite for sending it to a third party. That constraint is solvable rather than disqualifying.

  • Self-hosted inference on client hardware — specified, deployed and benchmarked before anything depends on it
  • Document processing agents: translation, extraction, summarisation over internal material
  • Operational agents that read logs and surface anomalies instead of waiting to be asked
  • Edge inference where latency or isolation makes central processing the wrong answer
Delivered asrunning stack · no external inference
Practice area

Network design & deployment

Segmentation is the control most often deferred and most expensive to add later.

  • Gateway, switching and wireless design on Ubiquiti UniFi or Cisco Meraki
  • VLAN architecture that accommodates growth rather than being redrawn at the next headcount
  • Firewall policy and remote-access VPN; guest and IoT traffic isolated from corporate
  • Wireless laid out against the actual floor plan and coverage requirement
Delivered astopology · config · as-built documentation
Practice area

Automation & operational tooling

Administrative work that recurs on a schedule should not consume a person on that schedule.

  • Joiner-mover-leaver automation that completes the full checklist, not the memorable parts of it
  • Licensing, mailbox and compliance reporting produced on a schedule rather than on request
  • Backup verification and patch reporting, written once and repointed per environment
  • PowerShell and Python against the Microsoft Graph API
Delivered asscripts · scheduled jobs · runbook
Experience

Where I've done it.

Aug 2023 — Present
Laserglow Technologies

Systems Administrator

Photonics manufacturer, North York, ON — sole administrator for a 50+ user hybrid environment

  • Administer Microsoft 365 and Entra ID for 50+ users — identity lifecycle, Exchange Online, SharePoint, Teams and licensing; enforced MFA and Conditional Access that cut security incidents 30% within six months.
  • Deployed Intune and Autopilot for device compliance, configuration profiles and application deployment, standardising endpoint management and reducing endpoint risk 25%.
  • Led migration of on-premises workloads to Azure (VMs, storage, backup) with minimal downtime, reducing infrastructure costs 25%.
  • Automated user provisioning, patching and reporting with PowerShell and Python, cutting manual administration workload 40%.
  • Deployed a self-hosted LLM server on Ollama to process internal data without third-party exposure, and built AI agents for document translation, automated backup verification and IT workflow automation — including lightweight agents on Raspberry Pi and Jetson Orin Nano edge hardware.
  • Own the entire office network on Ubiquiti UniFi — gateways, switches and access points — including VLAN segmentation, firewall rules, VPN and Wi-Fi coverage; hands-on with Cisco Meraki as well.
  • Administer the VoIP.ms phone system end to end: SIP endpoint provisioning, DID management, and IVR and call-routing design for office and remote staff.
  • Deployed IoT environmental and equipment-monitoring sensors on segmented networks, and supported device provisioning for company IoT product lines.
  • Maintain a 90% end-user satisfaction rate; led the company website migration from WordPress to Wix.
Ongoing
Independent

Independent IT & AI Consultant

Toronto, ON — independent engagements alongside full-time practice

  • Advise and deliver across Microsoft 365 and identity architecture, network infrastructure, private AI deployment, and operational automation.
  • Engagements are scoped and delivered end to end — assessment, implementation, documentation and handover — rather than staffed as a single phase.
Toolkit

What I work with.

AI & Automation
OllamaSelf-hosted LLMsAI agentsClaude CodePythonPowerShellBash
Edge & Hardware
NVIDIA Jetson Orin NanoRaspberry PiOn-prem GPU/serverIoT sensor networks
Identity & Endpoint
Entra IDIntuneAutopilotConditional AccessMFAActive DirectoryGroup Policy
Microsoft 365
Exchange OnlineSharePointTeamsOneDriveDefenderLicensingCopilot admin
Cloud & Virtualisation
Azure VMsAzure networkingAzure storageAzure BackupCost managementVMware vSphereHyper-V
Networking & VoIP
Ubiquiti UniFiCisco MerakiVLANsFirewallsVPNDNSDHCPVoIP.msSIPIVR
Education & certifications

How I got here.

2022 — 2023

Postgraduate Certificate, Financial Technology

Seneca Polytechnic, Toronto · 3.8/4.0 · Cybersecurity, Privacy Management, Data Analytics

President's Honour List
2021 — 2022

Postgraduate Certificate, Business Analytics

Seneca Polytechnic, Toronto · 3.8/4.0 · Programming for Analytics, Predictive Analysis, Security & Privacy

President's Honour List
2016 — 2020

B.Tech, Computer Science & Engineering

Navrachana University, India · Operating Systems, Network Administration, Cybersecurity, Cloud Computing, Databases

Professional development
2024Career Essentials in System Administration — Microsoft & LinkedIn
2024Microsoft 365: Administration — LinkedIn Learning
2024PowerShell: Automating IT Administration — LinkedIn Learning
2024Cloud Security and Audit Fundamentals: AWS, Azure & Google Cloud — LinkedIn Learning
2024Linux: System Maintenance — LinkedIn Learning
Get in touch

Hiring for infrastructure, cloud, or applied AI?

I'm in Toronto and open to Systems Administrator, Cloud Administrator, IT Infrastructure and applied-AI roles — on-site or hybrid. Email is the fastest way to reach me.