~70%
Reduction in standing privileged access through Entra ID, Conditional Access, MFA, PIM and just-in-time access.
Azure | Microsoft 365 | AWS
Cloud Architect & Senior Cloud Engineer
I combine cloud architecture, hands-on engineering and technical leadership, with 15+ years delivering secure Azure and Microsoft 365 environments. Through SpaceNet-IT, I help organisations assess, design and improve their cloud platforms, then deliver the work through to operations. AWS experience complements my Microsoft cloud focus.
Available for SpaceNet-IT consulting and selected Senior Cloud Engineer / Cloud Architect contracts.
UK remote and London / Surrey hybrid engagements; available to start ASAP.
Engineering delivery across enterprise and regulated environments, from identity and repeatable releases to infrastructure automation and global governance.
Reduction in standing privileged access through Entra ID, Conditional Access, MFA, PIM and just-in-time access.
Reduction in manual cloud deployment effort with Bicep and GitHub Actions.
Onboarded in five weeks through infrastructure automation; per-server QA reduced from ~60 to five minutes.
Covered by Azure Arc and Azure Policy governance in a global regulated environment.
Consolidated 5+ authentication paths and reduced standing privileged access by ~70% with Entra ID, Conditional Access and PIM. Introduced Bicep and GitHub Actions to cut manual deployment effort by ~80%, alongside Microsoft 365 Multi-Geo and Azure Arc governance across 10+ countries.
Designed and built substantial parts of a greenfield AWS multi-account environment: account foundations, identity, Terraform deployments, security monitoring and hub-and-spoke VPC routing.
Architecture and practical delivery across Azure, Microsoft 365, identity, security and hybrid infrastructure, with AWS experience, testing and operational handover built into the work.
Build and migrate cloud foundations: landing zones, multi-account environments, Azure Arc and Policy, connectivity, monitoring and recovery.
Implement and troubleshoot Entra ID, SSO, MFA, Conditional Access, PIM and least-privilege access, alongside Zscaler and network segmentation.
Hands-on Microsoft 365 E5, Intune, Autopilot, Defender and Purview delivery, including identity integration, endpoint services and Multi-Geo.
Implement cloud security controls, logging and monitoring with Defender, Microsoft Sentinel SIEM, AWS Security Hub and GuardDuty.
Build repeatable infrastructure deployments with Terraform, Bicep and PowerShell, using Azure DevOps and GitHub Actions for CI/CD, testing and controlled releases.
Deliver and troubleshoot Windows Server, VMware and hybrid connectivity, spanning BGP, ExpressRoute, VPN, DNS, firewalls and disaster recovery.
A career combining hands-on engineering, cloud architecture and technical leadership. Azure and Microsoft 365 delivery at Eutelsat and OneWeb sits alongside SpaceNet-IT consulting, AWS delivery and enterprise infrastructure work.
Cloud consulting, architecture and hands-on engineering, prioritising Azure and Microsoft 365 across cloud foundations, identity, security, hybrid networking and infrastructure modernisation. Assess existing environments, define practical improvements and deliver repeatable deployments with Terraform, Bicep, PowerShell, Azure DevOps and GitHub Actions. AWS client delivery includes substantial parts of a greenfield multi-account platform. Support organisations through consulting engagements and selected senior engineering and architecture contracts.
Worked directly with Azure, Microsoft 365, Entra ID and infrastructure engineering teams during the Eutelsat / OneWeb integration. Extended Azure Arc and Azure Policy governance across 10+ countries and supported migration, troubleshooting and transition into operations.
Engineered Azure and Entra ID services across identity, security and networking. Consolidated 5+ authentication paths, reducing standing privileged access by ~70%. Introduced Bicep and GitHub Actions, cutting manual deployment effort by ~80%. Implemented Microsoft Sentinel as a global SIEM and delivered Microsoft 365 Multi-Geo, segmentation and encryption controls supporting ITAR / EAR requirements.
Delivered hands-on Azure and Microsoft 365 engineering across identity, cloud connectivity and endpoint services. Designed and troubleshot BGP-based hybrid connectivity, SSO, MFA and Conditional Access, supporting global growth through automation, monitoring and platform standardisation.
Delivered infrastructure discovery, technical design, implementation, migration, testing, rollback and operational transition. Built automation that onboarded ~1,000 servers in five weeks and reduced per-server QA validation from ~60 to five minutes.
Implemented Azure disaster recovery using Azure Site Recovery, SQL replication and identity technologies, alongside Cisco UCS and SQL Server cluster consolidation.
Delivered VMware, Citrix and infrastructure services across Europe, North America and Asia-Pacific, including VPN access and complex Citrix migrations.
Earlier career (1992–2012): infrastructure engineering, consulting and technical roles across legal, financial-services and enterprise environments.
I combine technical direction with hands-on delivery, working with engineering teams from architecture and design through build, migration and troubleshooting to a secure, supportable operational handover.
Secure, repeatable cloud foundations, with the automation and operational controls needed to run them.
Principal Architect experience brings clear technical decisions, practical standards and effective collaboration with stakeholders and delivery teams.
Copilot Studio, AI agents and agentic workflows, with enterprise security, governance and human oversight built into the approach. Connect useful automation to business needs and the Microsoft cloud environment.
A practical approach for consulting engagements, cloud migrations and contract engineering: understand the business need and estate, agree the design, implement carefully and prepare the platform for operations.
Understand the current estate, dependencies, constraints and risk.
Implement technical designs with repeatable automation and controlled migration.
Test, troubleshoot and verify security, connectivity and recovery before handover.
Transfer knowledge and confirm monitoring, support and operational readiness.
For businesses in Kingston upon Thames and beyond, SpaceNet-IT provides cloud consulting, architecture and hands-on delivery across Azure and Microsoft 365, with AWS experience where needed. I also take selected Senior Cloud Engineer and Cloud Architect contracts across cloud, identity, automation and hybrid infrastructure.
Available for SpaceNet-IT consulting and selected Senior Cloud Engineer / Cloud Architect contracts.
UK remote and London / Surrey hybrid engagements; available to start ASAP.