Infrastructure as Code
Terraform · CloudFormation · encrypted remote state · multi-AZ VPC · isolated data tiers · least-privilege IAM
→ An environment you can destroy and rebuild with confidence
Remote Worldwide · Every Time Zone · Available Now
AWS DevOps Engineer / Cloud & Data Infrastructure
I build the path from commit to production and make it boring — infrastructure in Terraform, releases through CI/CD, systems watched by Grafana, and data pipelines that keep reporting honest. Then I hand you the code, the dashboards and the runbooks so your team owns it.
I'm an AWS DevOps Engineer built on two deep specialisations: AWS solutions architecture and data engineering. That combination is the point. Most teams can get code deployed, or get a dashboard built — the hard part is making the whole path reliable: commit → pipeline → infrastructure → data → decision.
Most businesses don't have an infrastructure problem. They have a repeatability problem. Servers configured by hand two years ago that nobody dares touch. Deploys that need a specific person online. Reports rebuilt manually every Monday. Outages discovered by customers. Every one of those is a system that was never finished — and finishing them is the work I do.
You get clear communication, organised documentation, and systems designed for real business use — not technical demonstrations. Send me your goal, your current stack, or the architecture problem that's been sitting in the backlog, and I'll tell you the most practical next step.
DevOps first, then the two specialisations that make it useful — AWS architecture and data engineering. Every line below is something I've shipped into production, not a technology I've read about.
Terraform · CloudFormation · encrypted remote state · multi-AZ VPC · isolated data tiers · least-privilege IAM
→ An environment you can destroy and rebuild with confidence
GitHub Actions · automated testing · container builds · gated deploys · fail-fast pipelines · fast rollback
→ Shipping becomes routine instead of an event
Grafana · Prometheus · Loki · Promtail · Alertmanager · CloudWatch · centralised logs · tested alert routing
→ You learn about incidents from a dashboard, not a customer
IAM policy design · ModSecurity WAF · CSF firewall · VPS hardening · CIDR blocking · TLS & certificate automation
→ A smaller blast radius when something does go wrong
EC2 · S3 · Lambda · API Gateway · DynamoDB · RDS · CloudFront · VPC · Well-Architected reviews
→ Architecture decisions you can defend in a review
S3 data lakes · AWS Glue · Athena · Redshift · BigQuery · schema drift handling · idempotent reruns
→ Loads that survive a rerun, and an answer when two reports disagree
Amazon Textract · Python OCR pipelines · S3 + Lambda · confidence thresholds with human review · structured export
→ Hours of manual data entry become a file drop
Power BI · DAX · Power Query · star-schema modelling · Tableau · Looker Studio · automated refresh
→ An executive KPI view that maintains itself
Live platforms, open-source infrastructure, and productised services — each one links to something you can actually inspect: a running dashboard, a public repository, or a written case study.
A managed Grafana stack I host for the client — API, website, cloud and server metrics with alerting and secure credential handover. The demo below is a real dashboard, not a screenshot.
The full Grafana + Prometheus + Loki stack installed on your own servers via Docker Compose, with centralised log search and tested alert routing. Full admin access handed over — no SaaS or per-host fees.
A secure-by-default AWS account baseline in Terraform: encrypted remote state, a multi-AZ VPC with an isolated database tier, and least-privilege IAM. Start compliant instead of retrofitting security later.
Event-driven document extraction on Textract and Lambda. Invoices, receipts and scans become clean CSV, Excel or database records — with low-confidence fields escalated to human review instead of silently corrupting your data.
A large affiliate travel platform: Viator API integration, custom PHP and WordPress workflows, MySQL ingestion, SEO infrastructure and automated content routing — deployed and monitored on cloud infrastructure.
A serverless ETL pipeline for NYC travel data, ending in a Tableau reporting layer. Ingest, transform, warehouse, visualise — the full data engineering path in one repository.
An end-to-end machine learning application: feature engineering, regression models, and a deployed Streamlit interface for interactive property price estimation. Training through deployment, not just a notebook.
A structured Well-Architected review of an existing account — security posture, cost leakage, reliability gaps and scaling limits — delivered as a prioritised remediation plan rather than a 60-page PDF nobody reads.
Scalable backends on Lambda, DynamoDB, API Gateway, S3 and IAM with event-driven workflows — defined in infrastructure as code, instrumented from day one, and documented for handover.
A cost-safe AWS lakehouse over live flight telemetry. The same dbt models run on DuckDB locally and Athena in the cloud, and CI proves the whole pipeline — 215 tests, 97% coverage — with zero AWS credentials.
I write up the problems I actually hit: the Terraform baseline, the pipeline that fails fast, the log label that wrecked a Loki install. Real debugging, with the trade-offs left in.
SageMaker Lakehouse vs Glue + Athena: Is Migration Worth It?
SageMaker Lakehouse is built on the Glue Data Catalog and Lake Formation, so a migration barely moves data. It moves enforcement…
Read article →
Your CRM Is Not a Database: Where GoHighLevel Should Stop
A CRM never pushes back when you add one more field, which is exactly why the schema drifts until someone asks a question that…
Read article →
Building a Hotel Data Lake on AWS That Agrees With the Night Audit
Hotel source data is mutable in the past, so an append-only pipeline drifts away from the PMS without anyone noticing until month…
Read article →
The Real Cost of CloudWatch: Logs, Metrics, Retention and Cardinality
CloudWatch rarely fails loudly, it accumulates. This is a breakdown of the four independent meters behind the bill: ingestion…
Read article →
Every credential below links to the issuer's own record. AWS issues its certification badges through Credly, so the badge page is the official proof — issue date, expiry and assessed skills included.
The things clients and hiring managers ask me first.
Available for DevOps engagements, cloud architecture consulting, data engineering projects — and open to full-time platform roles. Remote by default, working globally. Tell me the problem; I'll tell you the practical next step.