Projects & Things I’ve Built #
An anonymised collection of platform engineering, cloud infrastructure, and security work I’ve delivered across consulting, cloud migrations, and platform modernisation projects. Details have been generalised—and in some cases combined—to avoid identifying organisations or reproducing internal designs.
Platform Engineering
Accelerators, Kubernetes and developer workflows
Security & Identity
Authorization, guardrails and secure cloud foundations
Cloud Modernisation
Platform migrations, automation and cost reduction
Migration Case Study
Moving from web-managed tooling to declarative workflows
1. Platform Engineering & Accelerators #
Enterprise Microservice Platform Accelerator #
- Core Platform: Designed and built a Java and Kubernetes service accelerator that substantially reduced the effort required to bootstrap a new service. Included standard unit, component, and end-to-end test scaffolding.
- Automated Metric Tracking: Built a scheduled pipeline and reporting workflow to track platform adoption and migration progress.
- Vulnerability & Base Image Patching: Designed an automated system to push updated base images across all application teams upon new release or vulnerability detection, accounting for ADO pipeline timeouts and parallelization limits.
- Developer Enablement: Ran tabletop “gameday” onboarding sessions and chapter workshops to validate runbooks and support playbooks.
Reusable Kubernetes Platform Foundation #
- Automated Baseline: Architected a reusable Kubernetes accelerator using Terraform and CI/CD templates, standardising deployments across multiple engagements.
- Security & Compliance: Established hardened infrastructure baselines and automated security guardrails to reduce time-to-market for production workloads.
- Delivery Experience: Established consistent state-management and workspace-delivery patterns.
Container Workloads & Local Development #
- Container Architecture: Uplifted container workload patterns on AWS ECS, advising on secret management and Bitbucket CI/CD automated image promotion.
- Zero-Friction Local Testing: Built local testing workflows using ECS CLI and self-documenting Makefiles, allowing engineers to spin up and tear down ECS tasks locally with minimal Docker friction.
- Discovery: Led architecture discovery and aligned infrastructure recommendations with organisational requirements.
2. Security, Identity & Policy Architecture #
Fine-Grained Authorisation Platform #
- Fine-Grained Authorization: Designed and implemented the Open Policy Agent (OPA) architecture across domain teams, enabling granular team-specific policies proxyable via API Gateway and Lambda Custom Authorizers.
- Developer Environment Standardisation: Built a reusable VS Code Dev Container template adopted across multiple engineering teams.
- Pipeline Templating: Refactored multi-environment CI/CD pipelines to enforce consistent deployment standards.
- Mentoring: Led pair-programming sessions and workshops on AWS CDK, OPA, and core AWS patterns.
AWS Landing Zone & Security Uplift #
- Landing Zone Architecture: Designed enterprise AWS Landing Zone architectures for large-scale cloud migrations using AWS Control Tower, Organizations, and Terraform.
- Guardrails & Hardening: Implemented Service Control Policies (SCPs), unified multi-account networking, and automated container golden-image baking pipelines with vulnerability remediation.
Platform Migration & Security Remediation #
- Application Migration: Stepped in to lead AWS platform development efforts for a fast-moving insurance application migration into an isolated AWS organization.
- Security Remediation: Owned platform security compliance documentation, evidence collection, and stakeholder reporting.
- Network Security: Took operational ownership of AWS Network Firewall rule implementations and modular IaC releases.
Serverless Integration Platform #
- Sole DevOps Delivery: Architected and provisioned the entire AWS serverless infrastructure (CloudFront, API Gateway, DynamoDB, Lambda, S3) using Infrastructure as Code.
- Application Contribution: Contributed to the Serverless NestJS / GraphQL Lambda backend logic.
3. Cloud Modernisation & Tooling #
Cloud Tooling & Secret Architecture Optimisation #
- Platform Migration: Led a move from separate commercial state and secrets platforms to a cloud-native, configuration-driven workflow.
- Cost Reduction: Significantly reduced recurring licensing costs while retaining secure, self-service infrastructure and secret access.
- Reusable Workflows: Built shared CI/CD workflows for cloud authentication, state management, and secret migration and retrieval.
Read the full anonymised platform-migration case study.
Azure Virtual Desktop Automation #
- Automated Provisioning: Designed and automated Azure Virtual Desktop (AVD) infrastructure using Terraform, GitHub Actions, and PowerShell.
- Access Profiles: Configured several access profiles with tailored host-pool types and requirements.
- Lifecycle Management: Built PowerShell automation for user session draining, direct host assignment, and Terraform state cleanup.