Every discipline, rated by what was actually delivered.
Not a keyword list. Each row below is a technical discipline scored by delivery depth, not years held, backed by the specific thing built or owned. Filter by domain or read the whole set.
Azure landing zones & governance
Architected & ownsCAF landing zones, management groups, Azure Policy, RBAC, Entra ID, Key Vault, Bastion
Built the standard from scratch to the Microsoft Cloud Adoption Framework - every build since, across a dozen-plus regulated customers, has followed it.
Azure networking
Architected & ownsVirtual WAN, Azure Firewall, hub-and-spoke, UDRs, NSGs, ExpressRoute, VPN gateways, Front Door, FortiGate NVAs
Owns the routing design end to end, including inspection paths and firewall ruleset rationalisation across customer boundaries.
Azure Virtual Desktop
Delivered at scaleAVD at several-hundred host scale, FSLogix, proximity placement groups, scaling plans
Held latency down for legacy case-management applications on Progress-based databases at production scale.
Azure data & DevOps
Working depthAzure SQL, SQL Managed Instance, Data Factory, Microsoft Fabric, DevOps pipelines on VM Scale Sets
Built the data platform work and an Azure DevOps pipeline to standardise deployment.
Cost & FinOps
Delivered at scaleReservations, 95th-percentile rightsizing, storage tiering, AVD density tuning, Logic Apps power scheduling
Cut spend on a major account by around 25%, beating the customer's target, without moving net profit.
Security & compliance
Architected & ownsMicrosoft Sentinel, Defender for Endpoint & Cloud, ISO 27001:2022, Cyber Essentials Plus
Named accountable owner for 44 of 92 ISO 27001:2022 controls - zero major or minor non-conformities across two recertifications.
Service provider routing
Architected & ownsBGP, MPLS/LDP, L3VPN with per-customer VRFs, route reflectors, OSPF, IP transit, LINX peering, RPKI/IRR at RIPE NCC
Sole architect and delivery owner for a live ISP core carrying full internet routing tables.
Cisco platform
Delivered at scaleIOS-XR on NCS-5500, NX-OS on Nexus 9000 with vPC, Catalyst, HSRP, IP SLA
Personally responsible for gateway, distribution and access design migrating four legacy sites into two Equinix availability zones.
Data centre
Delivered at scaleEquinix availability-zone consolidation, dual-AZ design, dark fibre and wavelength services, physical build
Leading the live migration out of four legacy sites into two Equinix AZs in Manchester and London.
Fortinet & SD-WAN
Delivered at scaleFortiGate HA/VDOM, Secure SD-WAN, FortiManager, FortiAnalyzer, IPsec, ADVPN
Authored a 15-site SD-WAN design and rebuilt a FortiGate estate onto new HA clusters with per-customer VDOM segmentation.
Virtualisation
Architected & ownsVMware NSX-T (Tier-0/Tier-1, BGP, distributed east-west firewalling, Autonomous Edge), vSAN stretch clusters, Hyper-V
Built NSX-T from scratch, peering BGP into the self-built MPLS core; ran a Manchester-Leeds vSAN stretch cluster under 5ms RTT.
Monitoring & automation
Working depthLogicMonitor, IP SLA, SNMPv3, Terraform, PowerShell, Python, Git
Built estate-wide IP SLA monitoring into LogicMonitor so carrier circuits alert on loss and latency, not just hard failure.
Architected & owns - designed it, built it, remains accountable for it.Delivered at scale - hands-on production delivery across multiple sites or clients.Working depth - confident, regular hands-on use, not the primary specialism.
Got a piece of work that touches two or three of these at once?
Bring the problem, environment and timing. I can work out whether there is a useful fit.