Every discipline, rated by what was actually delivered.

Not a keyword list. Each row below is a technical discipline scored by delivery depth, not years held, backed by the specific thing built or owned. Filter by domain or read the whole set.

  • Azure landing zones & governance

    Architected & owns

    CAF landing zones, management groups, Azure Policy, RBAC, Entra ID, Key Vault, Bastion

    Built the standard from scratch to the Microsoft Cloud Adoption Framework - every build since, across a dozen-plus regulated customers, has followed it.

  • Azure networking

    Architected & owns

    Virtual WAN, Azure Firewall, hub-and-spoke, UDRs, NSGs, ExpressRoute, VPN gateways, Front Door, FortiGate NVAs

    Owns the routing design end to end, including inspection paths and firewall ruleset rationalisation across customer boundaries.

  • Azure Virtual Desktop

    Delivered at scale

    AVD at several-hundred host scale, FSLogix, proximity placement groups, scaling plans

    Held latency down for legacy case-management applications on Progress-based databases at production scale.

  • Azure data & DevOps

    Working depth

    Azure SQL, SQL Managed Instance, Data Factory, Microsoft Fabric, DevOps pipelines on VM Scale Sets

    Built the data platform work and an Azure DevOps pipeline to standardise deployment.

  • Cost & FinOps

    Delivered at scale

    Reservations, 95th-percentile rightsizing, storage tiering, AVD density tuning, Logic Apps power scheduling

    Cut spend on a major account by around 25%, beating the customer's target, without moving net profit.

  • Security & compliance

    Architected & owns

    Microsoft Sentinel, Defender for Endpoint & Cloud, ISO 27001:2022, Cyber Essentials Plus

    Named accountable owner for 44 of 92 ISO 27001:2022 controls - zero major or minor non-conformities across two recertifications.

  • Service provider routing

    Architected & owns

    BGP, MPLS/LDP, L3VPN with per-customer VRFs, route reflectors, OSPF, IP transit, LINX peering, RPKI/IRR at RIPE NCC

    Sole architect and delivery owner for a live ISP core carrying full internet routing tables.

  • Cisco platform

    Delivered at scale

    IOS-XR on NCS-5500, NX-OS on Nexus 9000 with vPC, Catalyst, HSRP, IP SLA

    Personally responsible for gateway, distribution and access design migrating four legacy sites into two Equinix availability zones.

  • Data centre

    Delivered at scale

    Equinix availability-zone consolidation, dual-AZ design, dark fibre and wavelength services, physical build

    Leading the live migration out of four legacy sites into two Equinix AZs in Manchester and London.

  • Fortinet & SD-WAN

    Delivered at scale

    FortiGate HA/VDOM, Secure SD-WAN, FortiManager, FortiAnalyzer, IPsec, ADVPN

    Authored a 15-site SD-WAN design and rebuilt a FortiGate estate onto new HA clusters with per-customer VDOM segmentation.

  • Virtualisation

    Architected & owns

    VMware NSX-T (Tier-0/Tier-1, BGP, distributed east-west firewalling, Autonomous Edge), vSAN stretch clusters, Hyper-V

    Built NSX-T from scratch, peering BGP into the self-built MPLS core; ran a Manchester-Leeds vSAN stretch cluster under 5ms RTT.

  • Monitoring & automation

    Working depth

    LogicMonitor, IP SLA, SNMPv3, Terraform, PowerShell, Python, Git

    Built estate-wide IP SLA monitoring into LogicMonitor so carrier circuits alert on loss and latency, not just hard failure.

Architected & owns - designed it, built it, remains accountable for it.Delivered at scale - hands-on production delivery across multiple sites or clients.Working depth - confident, regular hands-on use, not the primary specialism.

Got a piece of work that touches two or three of these at once?

Bring the problem, environment and timing. I can work out whether there is a useful fit.