Hybrid Cloud Architecture
Production estates running across AWS and Azure together: landing zones, account and subscription structure, autoscaling and multi-AZ, sized right for cost and growth.
Eight years building and running DevOps platforms, fifteen in tech, and still hands-on across a hybrid AWS and Azure estate every day. I build platforms that are reproducible with code, observable when they move, and quick to recover when they don't.
Where I've worked
I'm a senior DevOps and platform engineer based in Dubai, and I still spend most of my day in the terminal. At Lumi I build and run our hybrid AWS and Azure estate myself, from Terraform and Bicep through to on-call.
Twice now I've stood up an entire cloud estate from scratch against a regulatory deadline: separating Lumi's AWS data platform and Okta identity from its former parent company after the public listing, and consolidating the Wellcome Sanger Institute's fragmented GCP and AWS workloads onto one automated AWS platform. Work like that is where architecture, security, networking and delivery stop being separate skills.
I'm relocating to New Zealand and will need work visa sponsorship. I hold a UK Master's in Computer Systems Security, delivered for the Wellcome Sanger Institute in Cambridge, and own a regulated, compliance-driven cloud estate day to day.
Engineering
Production estates running across AWS and Azure together: landing zones, account and subscription structure, autoscaling and multi-AZ, sized right for cost and growth.
Every environment reproducible in Terraform, Bicep and Ansible, reviewed and versioned, with PowerShell and Python automation for the operational work either side of it.
Least-privilege IAM, Entra ID and Okta, application SSO with SAML and OIDC, MFA, managed secrets, and tested backup and restore so recovery is a plan, not a scramble.
VPC and VNet design, subnets and peering, DNS, load balancing, network security groups, private endpoints and hybrid connectivity, debugged at packet level when it matters.
Build, test and deploy pipelines in Jenkins, Azure DevOps and GitHub Actions that turn manual, risky releases into fast, boring, repeatable ones.
Containerised workloads on managed Kubernetes across EKS and AKS, with sane defaults for scaling, rollouts and self-healing.
Prometheus, Grafana, Azure Monitor and Splunk wired into metrics, logs, traces and alerting that catch problems before users do, with runbooks teams can follow.
Agentic AI tooling used deliberately in the delivery loop for code review, infrastructure-as-code scaffolding, runbooks and incident triage, with human review kept firmly in front of production.
How I work
I follow a problem wherever it leads, through cloud, networking, Linux, containers and databases, not just the platform layer. Packet captures and kernel logs included.
Calm, structured incident response with runbooks and on-call practices that scale beyond one person. I carry the pager alongside the team.
I take work from design through code review, rollout and the operational reality afterwards. Whatever I build, I run.
Seven years setting technical direction while writing the code: design reviews, platform standards, and levelling up engineers around me.
Tools I work with
Saudi vehicle rental and mobility company, listed on the Saudi Exchange in 2024.
One of the Middle East’s largest online travel agencies, part of Seera Group.
UK genomics and biodata research institute, working on human and pathogen genome science.
Saudi Arabia’s largest travel and tourism group. Business units at the time included Almosafer, Almosafer Business and Lumi.
Global enterprise software and semiconductor company.
UK-listed online trading and financial derivatives provider.
Indian IT services and digital transformation consultancy.
Designed and built Lumi’s standalone technology estate after its public listing, carving it out of Seera Group over two years. I owned the architecture and did the hands-on work across cloud, identity/SSO, data and business-process automation. Delivered the regulatory, compliance-driven separation on schedule with no service disruption.
Rebuilt Lumi’s AWS data platform as an independent estate: Amazon EMR clusters, Apache Airflow orchestration, Tableau and production machine-learning workloads, cut over without breaking a single pipeline. Worked directly with the Data Engineering and Data Intelligence teams and avoided SAR 2 million (approximately NZD 910,000) in quoted professional-services costs.
Established Lumi’s independent Okta identity environment end to end: procurement, Active Directory integration, MFA and application SSO using SAML and OIDC. Designed and implemented the solution personally, avoiding SAR 1 million (approximately NZD 456,000) in quoted professional-services costs.
Implemented the end-to-end production platform for the Almosafer travel product single-handedly: Amazon EKS, CI/CD pipelines, Keycloak for identity, Istio service mesh, NGINX ingress and full monitoring and alerting. The platform scaled from zero to 4,000 bookings a day.
Almosafer Business ran an Apigee API gateway implemented by an external consultancy. I evaluated what the platform actually used, found none of the Apigee-specific capabilities were in play, and replaced it with Kong. Removed approximately USD 300,000 (about NZD 513,000) of licensing cost with no loss of capability.
A commercial robotic-process-automation rollout was proposed to automate a set of HR workflows. I analysed what those workflows actually required and built the integration myself in Python against the HR platform’s OData API instead. That avoided the RPA licences, the dedicated infrastructure to run them and two additional engineering hires, equivalent to SAR 645,150 (approximately NZD 294,000) in avoided annual operating cost.
Automated Almosafer’s data-platform infrastructure with Terraform, introduced scalable Amazon EMR capacity and implemented Prometheus and Grafana monitoring, improving ETL performance, reliability, recovery and environment consistency.
Consolidated fragmented GCP and AWS workloads onto a standardised AWS platform, automated infrastructure provisioning and introduced monitoring, security and compliance controls for sensitive healthcare and genomic data. Reduced operational complexity and helped research teams launch new DNA research processes faster.
University of South Wales, United Kingdom
Wellcome Sanger Institute, Cambridge · regulated healthcare and genomic data
Outside my day-to-day work I build small command-line tools and automation in Go and Python, for the fun of it, to keep learning, and to give a little back to the communities whose tools I rely on. It's where I try ideas before they're useful at work.
Read-only AWS technical readiness scanner for selected NZISM and PSR information-security controls. Single static binary, no mutating API calls, versioned control mappings, and terminal, JSON or HTML reports. Every finding states its evidence, its remediation and what an automated check cannot verify.
Small Go command-line tool to list and export all keys, or a prefix, from a Consul KV store. Built to make configuration backup and migration between Consul clusters a one-line operation.
Browser-based S3 bucket explorer built with Python, Flask and boto3, written because there was no simple local S3 browser for macOS at the time.
I'm always glad to talk about DevOps, cloud and platform engineering. The quickest ways to reach me are below.
I am relocating to New Zealand and would need work visa sponsorship. Happy to interview across New Zealand time zones and to start a conversation at any stage.