Skip to content

About

Enterprise IT experience, moving deeper into infrastructure.

I have spent more than ten years in enterprise IT across global organisations. The work has progressed from support and migration projects into identity, endpoint and platform administration, and now into infrastructure I own end to end. The next step is a role built around Azure, infrastructure and platform engineering.

Progression

Three stages, one direction

  1. 01

    Enterprise IT, administration and operations

    2008 — today

    Large-scale Windows migrations at PwC, global service desk and second-line work at CEB and Gartner including Okta SSO administration, then a regional lead role in Dubai covering six EMEA sites. Today at Lockton that means administering Entra ID, Intune and Microsoft 365 for a 2,000–2,500-user estate, with ownership of the sFTP platform and the endpoint refresh alongside.

  2. 02

    Deeper infrastructure ownership

    Homelab, ongoing

    Running my own platform end to end: Proxmox with ZFS, OpenMediaVault with mdadm RAID1 and SMB, Docker services for DNS, reverse proxy and monitoring, an RTX A2000 passed through to the VM for Ollama, and Tailscale for remote access. Owning it means dealing with what breaks, from a validated disk migration to recovering GPU passthrough after a kernel upgrade broke the NVIDIA DKMS build.

  3. 03

    Azure, infrastructure and cloud direction

    Now

    Building the subscription-level Azure skills that a service-delivery role does not cover: CLI provisioning, budgets and Action Groups, private storage and RBAC in a DevTest lab, with AZ-104 study ongoing. The aim is a role where infrastructure, identity and cloud platforms are the job rather than the escalation.

Approach

How I work

01

Understand the system

Identity, networking, DNS, storage, operating systems, containers and monitoring all interact. Most problems I have fixed lived at the boundary between two of them.

02

Diagnose at the right layer

An endpoint complaint is often an identity or policy problem upstream. A GPU failure was a kernel and driver problem. Establishing which layer failed before changing anything saves repeat work.

03

Validate before declaring done

Storage is mounted read-only before read-write. Services are checked individually after a recovery. A budget alert exists before the first resource. The check is part of the change.

04

Be accurate about depth

Terraform is introductory and the k3s cluster was never completed. I would rather say so than turn exposure into expertise I do not have.

Where I am now

What is established and what is still developing

Established: enterprise Microsoft administration and troubleshooting across Entra ID, Intune, Microsoft 365 and Active Directory, identity and endpoint operations, PowerShell, and the stakeholder side of running IT in international organisations.

Substantial and hands-on: Linux, Proxmox, Docker, storage, DNS, reverse proxying and Prometheus/Grafana monitoring, all built and operated in my own environment and documented on this site.

Developing: subscription-level Azure administration through structured lab work and AZ-104 study. Introductory: Terraform. Incomplete: Kubernetes, where my k3s work never reached a working cluster. I document all three because they are part of the progression, not because I present them as expertise.

Explore

See the work behind the direction.

The Projects and Architecture pages document what I have built, what has broken, and how it was recovered. The CV has the technology list and career history in one place.