Technical Architect | Cloud Platform & Site Reliability Engineering | AWS | Azure | Kubernetes | OpenShift | Terraform
I design, automate and operate secure cloud platforms for large, regulated environments. My work sits at the intersection of cloud architecture, Linux engineering, Kubernetes platform operations, observability, reliability and infrastructure automation.
I enjoy turning difficult operational problems into repeatable engineering systems: infrastructure as code, safe automation, useful telemetry, clear runbooks and architecture decisions that balance reliability, security and cost.
- Production Platform Architecture and Reliability — a sanitized walkthrough of a four-cluster primary/DR platform supporting 5,000+ microservices and 1M+ daily transactions. It covers my personal ownership, architecture decisions, alternatives and trade-offs, failure behaviour, deterministic validation, incident remediation and recovery engineering.
- Role-Aware Oracle Data Guard Failover for Azure Data Factory — a sanitized production-style design that replaced manual DNS/DNAT failover with fail-closed HAProxy routing driven by Oracle database role, managed identity, Key Vault, systemd automation and service-aware Azure Load Balancer health checks.
| Project | What it demonstrates |
|---|---|
| AWS Enterprise Platform | Secure VPC foundations, private connectivity, EKS patterns, tagging controls and Terraform design |
| Azure Enterprise Platform | Landing-zone patterns, VNets, Private Link, managed identities, RBAC and Log Analytics |
| Kubernetes & OpenShift Operations | Production readiness, workload resilience, platform health checks and incident runbooks |
| Enterprise Ansible Automation | Idempotent Linux lifecycle automation, patching, service recovery and observability-agent deployment |
| Observability & SRE Playbooks | OpenTelemetry, Prometheus, Grafana, Loki, Tempo, SLIs, SLOs and actionable alerting |
| Cloud FinOps Toolkit | AWS and Azure cost analysis, ingestion trends, anomaly investigation and engineering accountability |
| Cloud Network Troubleshooting Lab | DNS, TLS, routing, private endpoints, transit connectivity, Kubernetes network diagnostics and role-aware database failover patterns |
- Cloud platforms: AWS and Microsoft Azure architecture, networking, security, governance and operations
- Containers: Kubernetes, Red Hat OpenShift, EKS, Helm, Docker and Podman
- Infrastructure as code: Terraform, ARM concepts, reusable modules and policy-aware deployments
- Automation and validation: Ansible Automation Platform, Python, Bash, PowerShell, deployment checks and diagnostic tooling
- Observability: OpenTelemetry, Prometheus, Grafana, Loki, Tempo, Mimir and cloud-native monitoring
- Linux and infrastructure: Red Hat Enterprise Linux, SUSE Linux, VMware, OpenStack, high availability and enterprise backup platforms
- Reliability: incident response, operational readiness, capacity management, disaster recovery, SLIs, SLOs and error budgets
- FinOps: cost allocation, trend analysis, architecture-cost trade-offs and optimization governance
- Automate the repeatable, document the exceptional.
- Prefer private, least-privilege designs by default.
- Measure customer impact, not merely infrastructure activity.
- Make failure modes explicit before production.
- Treat cost as an engineering signal alongside reliability and security.
- Build platforms that enable teams rather than creating operational dependency.
- Red Hat Certified Architect, AWS Solutions Architect Professional, Google Professional Cloud Architect, CKA, CKAD and Terraform Associate
- Fortinet NSE 7, Cisco CCNA, PRINCE2 and ITIL
- MSc Electrical Engineering and first-class BSc engineering degree
- Mandela Rhodes Scholar and Erasmus mobility alumnus
My academic work includes cloud-native 5G network-slice optimization, orchestration and metaheuristic resource allocation. See 5GSLICEOPTIMIZATION and 5GMETAHEURISTIC.
Every technical repository includes a GitHub Actions validation workflow. From a clone of this profile repository, all checks can be dispatched and reviewed with:
chmod +x scripts/run-portfolio-ci.sh
./scripts/run-portfolio-ci.sh dispatch
./scripts/run-portfolio-ci.sh statusThe workflows validate Terraform, Ansible syntax, Kubernetes schemas, Prometheus rules, Python tests and Bash diagnostics without requiring access to private cloud environments.
The portfolio uses synthetic networks, placeholder identifiers and generated data. It contains no employer source code, credentials, customer information, production exports or confidential architecture.
I am particularly interested in international remote roles spanning technical architecture, platform engineering, cloud architecture, solutions engineering, DevOps and site reliability engineering.