About
Enterprise IT experience,
moving deeper into infrastructure.
I have spent more than ten years in enterprise IT across global organisations. The work has progressed from support and migration projects into identity, endpoint and platform administration, and now into infrastructure I own end to end. The next step is a role built around Azure, infrastructure and platform engineering.
Progression
Three stages, one direction
- 01
Enterprise IT, administration and operations
2008 — today
Large-scale Windows migrations at PwC, global service desk and second-line work at CEB and Gartner including Okta SSO administration, then a regional lead role in Dubai covering six EMEA sites. Today at Lockton that means administering Entra ID, Intune and Microsoft 365 for a 2,000–2,500-user estate, with ownership of the sFTP platform and the endpoint refresh alongside.
- 02
Deeper infrastructure ownership
Homelab, ongoing
Running my own platform end to end: Proxmox with ZFS, OpenMediaVault with mdadm RAID1 and SMB, Docker services for DNS, reverse proxy and monitoring, an RTX A2000 passed through to the VM for Ollama, and Tailscale for remote access. Owning it means dealing with what breaks, from a validated disk migration to recovering GPU passthrough after a kernel upgrade broke the NVIDIA DKMS build.
- 03
Azure, infrastructure and cloud direction
Now
Building the subscription-level Azure skills that a service-delivery role does not cover: CLI provisioning, budgets and Action Groups, private storage and RBAC in a DevTest lab, with AZ-104 study ongoing. The aim is a role where infrastructure, identity and cloud platforms are the job rather than the escalation.
Approach
How I work
Understand the system
Identity, networking, DNS, storage, operating systems, containers and monitoring all interact. Most problems I have fixed lived at the boundary between two of them.
Diagnose at the right layer
An endpoint complaint is often an identity or policy problem upstream. A GPU failure was a kernel and driver problem. Establishing which layer failed before changing anything saves repeat work.
Validate before declaring done
Storage is mounted read-only before read-write. Services are checked individually after a recovery. A budget alert exists before the first resource. The check is part of the change.
Be accurate about depth
Terraform is introductory and the k3s cluster was never completed. I would rather say so than turn exposure into expertise I do not have.
Where I am now
What is established and what is still developing
Established: enterprise Microsoft administration and troubleshooting across Entra ID, Intune, Microsoft 365 and Active Directory, identity and endpoint operations, PowerShell, and the stakeholder side of running IT in international organisations.
Substantial and hands-on: Linux, Proxmox, Docker, storage, DNS, reverse proxying and Prometheus/Grafana monitoring, all built and operated in my own environment and documented on this site.
Developing: subscription-level Azure administration through structured lab work and AZ-104 study. Introductory: Terraform. Incomplete: Kubernetes, where my k3s work never reached a working cluster. I document all three because they are part of the progression, not because I present them as expertise.
Explore
See the work behind the direction.
The Projects and Architecture pages document what I have built, what has broken, and how it was recovered. The CV has the technology list and career history in one place.