Systems, security, and software · Since 2008
Someone has to understand the whole system.
The problems that actually matter rarely live inside one layer. They live in the seams — between the application and the database, the pipeline and the platform, the policy and the person who has to work around it. I’ve spent 26 years working in those seams, and I’m at home in every layer above.
26 years · Harwinton, Connecticut · Remote worldwide
Breadth
Not a specialist in one thing. A generalist who goes deep.
Specialists are easy to find and often exactly the right call. What’s harder to find is someone who can tell you which specialist you need — and who has the range to just handle it when the answer turns out to be “this one isn’t that complicated.”
Cloud
- Azure
- AWS
- GCP
- Oracle Cloud
Platform & delivery
- Terraform
- Bicep
- Kubernetes / AKS / EKS
- Docker
- Helm
- Ansible
- GitHub Actions
- Jenkins
- Octopus Deploy
- JFrog Artifactory
Identity & access
- SailPoint
- Okta
- Entra ID
- Active Directory
- Group Policy
- CyberArk
- OIDC / OAuth2
- SAML
- LDAPS
Security
- Zero Trust
- Zscaler
- Network segmentation
- Secret scanning
- Firewall policy
- Key management
Data
- SQL Server / T-SQL
- PostgreSQL
- Cosmos DB
- Snowflake
- DynamoDB
- SSIS
- JSON Schema
Observability
- Azure Monitor
- Grafana
- Datadog
- Splunk
- New Relic
- Power BI
- SolarWinds N-central
Languages
- Python
- PowerShell
- C# / .NET
- Bash
- SQL
- Java
- Groovy
- JavaScript
Systems
- Linux
- Windows Server
- macOS
- VMware ESXi
- IIS
Legacy & integration
- IBM 3270 / CICS
- Attachmate VHI
- z/VSE
- WMI
- ServiceNow
- LeanIX
- ArcGIS
Compliance
- NIST CSF 2.0
- HIPAA
- SOX
- SOC 2
- GDPR
- PCI
Also, when a project needs it
- HTML / CSS
- JavaScript
- Responsive front end
- CMS platforms
- Web hosting
Earlier — through 2015
- PHP
- MySQL
- jQuery
- ASP.NET
- WatchGuard
- SonicWall
- Android
- iOS
What I do
The work, in six parts
Most jobs start in one of these and quietly end up touching the others. The boundaries are clear on the diagram; they are less so in a system that has been in production for a few years, and closing that gap is most of the work.
Cloud & Platform Engineering
Infrastructure that is written down, version controlled, and reproducible — instead of assembled by hand and remembered by one person.
- Azure
- AWS
- Terraform
- Bicep
- Kubernetes / AKS / EKS
- +7
Security, DevSecOps & IAM
Identity, access, and hardening built into the delivery pipeline — not bolted on the week before an audit.
- SailPoint
- Okta
- Entra ID
- Active Directory
- CyberArk
- +7
Software & Data Delivery
Web applications, APIs, integrations, and the database designs underneath them — built to be maintained by someone other than me.
- Python
- PowerShell
- C# / .NET
- ASP.NET
- SQL Server / T-SQL
- +6
Legacy Systems & Integration
The system that still runs the business, that nobody wants to touch, and whose author left in 2014.
- IBM 3270 / CICS
- Attachmate VHI
- z/VSE
- WMI
- SOAP / XML
- +4
AI & Local LLM Engineering
Language models running on hardware you control, where the data never leaves the building.
- Ollama
- Llama 3.2 Vision
- Gemma 3
- Whisper
- PostgreSQL
- +4
Architecture Review & Due Diligence
A second opinion from someone who has built the thing you’re about to commit to — while it’s still cheap to change your mind.
- Architecture review
- Technical due diligence
- Platform design
- Integration design
- Migration planning
- +2
How it goes
You should know what happens next at every step
- 01
Conversation
You describe the situation, and I ask the questions that usually turn out to matter. If I don’t think I’m the right person for it, I’d rather say so early than take it on — and I’ll point you somewhere better if I can.
- 02
Assessment
A short, bounded look at what is actually there. It ends in a written findings document and a prioritized list of recommendations — yours to keep and act on, with or without me.
- 03
Execution
I’d rather settle scope and sequence before work starts than discover them along the way. Work happens in visible increments, so you can see where things are and change direction without losing what is already done.
- 04
Handoff
Documentation, runbooks, and as many screen-share calls as your team needs — over Teams, Slack or Zoom, whichever you already live in. I lean harder on the written material than the meetings, because notes survive and a session on a Tuesday afternoon mostly doesn’t. The measure of a good engagement is that you don’t need me afterward — and call me anyway, because you want to.
Shapes
What the work usually looks like
Most of what I have done falls into one of these three, whether it arrived as a job, a contract, or someone asking whether a thing was a good idea.
Reviews and assessments
Looking hard at one thing — an environment, a security posture, an application, an architecture decision that has not been made yet — and writing down what is actually true about it. These end in a document someone can act on without me.
Builds and migrations
Infrastructure written down and version controlled, pipelines that deploy without ceremony, systems moved from where they were to where they need to be. Scoped up front, delivered in increments you can see.
Untangling what is already there
The system that still runs the business, that nobody wants to touch, whose author left years ago. Working out what it does, writing that down, and making it safe to change — which is usually more valuable than replacing it.
If any of this is useful to you.
Whether that is a role, a problem you are staring at, or just wanting to know how I would approach something — write and say so. I answer properly.