← Back to profile

Selected work

Work that has to survive contact with operations.

A small set of anonymised examples showing how I take infrastructure, network, security and recovery change from an uncertain requirement to a working, supportable outcome.

Technical delivery Live operational environments Supportable handover

Project stories

The detail behind the profile.

These are deliberately high-level. The organisations and sensitive operational details stay private; the constraints, ownership and lessons are real.

01

Operational data platform · Systems integration

Replacing the operational platform behind a live environment.

A legacy platform sat at the centre of a wide operational information flow. Replacing it was an ecosystem change: interfaces, users and downstream services all depended on the transition working properly.

Requirements to handover Interfaces and dependencies Hyper-care and BAU transition

Context

The operation could not tolerate a gap between the old and new platforms, and the surrounding data flows were as important as the product being replaced.

My ownership

Technical requirements, target architecture, interface and dependency work, supplier coordination, migration planning, structured testing, cutover, hyper-care and transition into business-as-usual support.

The decision that mattered

Treat the work as an ecosystem replacement rather than a product swap. Every important data flow and operational dependency had to be understood, tested and owned through transition.

Result

A modern operational platform was integrated into the wider environment and brought into service through a controlled migration, with surrounding interfaces treated as first-class parts of the outcome.

Support lens

Hyper-care was part of delivery, not an afterthought. Issues found by real operational users were followed across application, database, interface and supplier boundaries before normal support took ownership.

02

Network and fibre transformation · Live operations

Rebuilding a live network without stopping operations.

A campus-wide network estate had growing resilience, capacity and support risk. Modernising it meant changing the infrastructure beneath a continuously operating environment without treating disruption as inevitable.

55 live switch replacements Fibre renewal Phased and reversible delivery

Context

The legacy core, access estate, cabinets and fibre had become a growing resilience and capacity concern. The work had to cover both the logical network and the physical conditions that made it dependable.

My ownership

Target core and access design, Layer 3 routing, cabinet layouts, resilient power and uplinks, fibre replacement specification, migration sequencing, contractor coordination, technical acceptance and handover.

The decision that mattered

Treat the active network migration and fibre renewal as one coordinated programme. Each phase needed to leave the estate working, testable and reversible even if the next phase moved by a week.

Result

A modernised core and access estate with renewed fibre, stronger capacity, clearer management and improved segmentation. Fifty-five switches were migrated live without unplanned operational disruption.

Support lens

Network records, consistent patterns and a handover the internal team could use were part of the technical outcome. The design had to remain diagnosable after the project ended.

03

Virtual infrastructure · Recovery

Refreshing the virtual estate from installation to recoverability.

Ageing virtual infrastructure supported services that could not simply be switched off and rebuilt elsewhere. The refresh had to cover the physical platform, migration path, failover capacity and backup as one service.

Two-host cluster Separate failover host Restore-aware design

Context

The existing estate needed a controlled refresh without losing service continuity or treating backup as a separate task from the platform itself.

My ownership

New two-host cluster and separate failover host, rack installation and cabling, platform configuration, workload migration, Veeam configuration, documentation and operational handover.

The decision that mattered

Separate availability from recoverability. Cluster resilience handled a local host failure; the failover host and backup design provided a different recovery path when the problem was larger than one node.

Result

Core workloads moved onto a refreshed, supportable virtual estate with dedicated failover capacity and recovery configuration aligned to how the environment would actually be restored.

Support lens

Recovery tooling is only useful when support teams understand what it protects, where it can recover to and which dependencies must return in what order.

04

Advanced Internal Security (AIS) · Segmentation

Replacing implied trust with granular control.

AIS replaced two Layer 3 core switches with new fibre switches across three core locations and introduced a redundant FortiGate pair, creating a clearer security boundary across a segmented network.

Three core locations Redundant FortiGate pair Granular segmented control

Context

The existing design relied too heavily on Layer 3 boundaries and gateway placement to determine what could reach what. AIS created an opportunity to make those trust decisions explicit without losing the connectivity the operation needed.

My ownership

Planned and delivered the change replacing two Layer 3 core switches with fibre switching across three core locations, integrating the redundant FortiGate pair, migrating gateways and routes, shaping policy, and supporting testing, cutover and handover.

The decision that mattered

Move trust decisions from implicit routing to explicit firewall policy. Redundancy at both the core and firewall boundary meant stronger control without introducing a single point of failure.

Result

A more resilient security boundary across the segmented network, with granular policy control and a platform for additional security measures such as traffic inspection and IPS.

Support lens

Clear zones, named policies and visible denials help distinguish security enforcement from application or routing faults, making the result easier to support after handover.

Back to profile

Complex systems. Clear ownership.

Return to the profile for the wider capability range, career timeline and contact details.