Work

Systems in production, written down honestly

Client names are withheld — most of this work sits under agreement. What is described is what was built, measured and operated, and the numbers are the measured ones. Detail available under NDA on request.

Prior engagements

Where the patterns were proven

Nearly four decades of engineering, the last ten-plus specialising in AWS cloud infrastructure. These are the engagements the service lines were built out of.

Case 03 · 2022 – 2025Developer-experience platform · 500+ engineers

Cloud provisioning as a product, for five hundred engineers

A multi-year engagement embedded with a fintech’s developer-experience platform team, spanning its transition to a public company. The mandate was to stop product teams from having to become infrastructure engineers: cloud resources declared in a simplified YAML schema, processed during CI/CD by a distributed internal-developer-platform backend, and surfaced through a React portal exposing every pipeline, status, metric, log and best-practice guide for each system provisioned through it.

Architected and shipped the abstractions engineers actually consumed — S3 with bucket policy grants, object eventing to SNS, SQS and Lambda, and lifecycle rules; ElastiCache Redis and Memcached with flexible cache types, master/replica topologies, IAM users and controlled version upgrades; and managed OpenSearch with domain security, index specification and master/replica configuration, which turned the company’s help-desk search from a bespoke backend into a highly available multi-index platform with a step change in performance for customers and support staff.

Also led the distributed architecture design and cross-team engagement that let SME platform teams — machine learning, networking, security — own provisioning of their own resources against published specifications while remaining components inside the core platform.

Engineers served500+
ScopeGo, AWS CDK v2, Kubernetes
LineDeveloper experience & platform
Case 04 · 2019 – 2021National streaming platform · launch scale

A single-instance monolith made ready for a national launch

Consulting principal across the build of a major streaming service: catalog portal, scheduling for live events and video on demand, metadata export to network partners, real-time ad cutting and breaks, and worldwide manifest delivery to television, mobile and desktop clients — then the same platform again for an Olympic summer games.

The webapp at the centre of it had historically run on one manually provisioned instance. We decomposed it for horizontal scale, extracted functionality into microservices to isolate concerns and improve testability, reprovisioned every piece of infrastructure as Terraform and Terragrunt with shared remote state so all changes went through pull-request review and automated apply, and built the CI/CD platform from scratch for the .NET application, the serverless functions and the Kubernetes services alike.

Also designed an abstraction over the global streaming platform’s resource APIs that atomically allocated resource pools per environment, ran the load-testing programme ahead of a worldwide sporting event, tightened the exposed surface with security policy and allow-listing, and treated monthly cloud spend as an engineering target.

Cloud spend−72% in 11 months
ArchitectureMonolith → horizontal + services
LineRelease reliability & decomposition
Case 05 · 2016 – 2019Ed-tech marketplace · later public

Cloud foundation from zero, then fifty services and a marketing platform

Three roles over three years — senior engineer, then engineering manager, then director — across infrastructure, IT and special operations. The company’s legacy systems ran on a third-party layer over AWS, which meant no control of its own resources, little control of spend, no access to critical logs and alarms, and a dependency on someone else’s support desk to diagnose its own outages.

We built a secure cloud presence from scratch: twelve accounts, private networks fronted by minimal-surface load balancers, provisioning and CI/CD automation, and shared modular tooling designed so engineering teams would actually adopt it. White-hat penetration testers hired in the following year found no infrastructure vectors. We then migrated all five legacy systems into it without customer impact, including the real-time tutoring platform used around the clock worldwide, and led the transition from monolith to more than fifty services and a hundred serverless functions, with cross-cutting authentication, log shipping, account, SSO tenancy and role-based cloud access services underneath.

The final year was spent as principal architect on a paid-marketing platform built because the ad networks could not segment audiences the way the business needed: a multi-tier distributed system enforcing ad and keyword integrity across millions of ads and roughly 4.2 billion keywords, with an event-driven ELT pipeline landing performance data in Redshift for analytics — against an ad budget of about a fifth of the company’s annual spend.

Decomposition50+ services · 100+ functions
Pen test0 infrastructure vectors
Ad platform~4.2B keywords
Case 06 · 2014 – 2016National retailer · digital office

An ETL orchestration platform over terabyte on-premise data

Architected, built and operated an orchestration platform that aggregated data from terabyte-scale on-premise databases into a cloud Postgres cluster and presented it to the interface tier as a horizontally scalable REST API behind a load balancer and autoscaling group, with a Redis cache layer for read performance and the whole stack provisioned by CloudFormation.

The pipeline itself was built as pluggable abstractions: tasks loaded dynamically so acquisition, transformation, business logic, mapping and storage could each be extended for a new scenario without touching the orchestrator.

PatternPluggable pipeline tasks
ScopeNode · Python · Postgres · Redis
LineArchitecture & data platform
Case 07 · 2008 – 2014Global software company · enterprise platforms

Enterprise platforms at a scale where milliseconds are policy

Six years on enterprise platforms inside one of the largest software companies in the world. On the display advertising platform: a decoupled interface, headless API and aggregation tier over five backend stores representing billions of advertising campaigns, led as engineering lead — and, after taking ownership, re-engineered with lazy loading, data paging and cache pre-fetching that took interface load time for the largest accounts from over ten minutes to under two seconds.

Before that, as global design lead and technical architect in the OEM organisation: the long-deferred migration of worldwide operating-system and software license management from paper to digital, a generalised notification platform decoupled from its data sources with pluggable off-the-wire acquisition and a real high-availability story, and a declarative user-interface rules engine with runtime assembly generation that let business partners change logic without an engineering release — work that won the company’s IT Pro Innovate award. Also served on its global unit-testing team, setting the quality maturity model other teams adopted.

Performance10+ min → <2s
RecognitionIT Pro Innovate award
LineArchitecture & performance

This is the level of detail you would get on your own systems — written down, measured and handed over.

Start a project