05projects

Infrastructure I've shipped

Nine client engagements across healthcare, pharma, fintech, and IoT — filter by the part of the stack you care about.

Solutions architect and DevOps lead for an edge-compute AI surveillance platform sustaining 99.9% uptime across 21 live telemetry feeds over 90+ days, after GPU benchmarking and provisioning NVIDIA RTX 4000 servers and PtP/PtMP wireless networks. Runs YOLOv8/TensorRT inference engines with PostgreSQL and MediaMTX (RTSP/RTMP) containerized in Docker Compose, with Zero-Trust enforced through a split-tunnelled WireGuard VPN, strict egress, and Pi-hole DNS sinkholes.

Case study
Docker Compose
YOLOv8
TensorRT
PostgreSQL
MediaMTX
+4

Codified a zero-public-IP Azure landing zone in Bicep (4 zoned subnets, deny-all NSGs, Private Endpoints), eliminating 100% of standing credentials and reducing the attack surface to 0 reachable public assets, validated by Microsoft Defender. Operates an OIDC-federated GitOps pipeline promoting SHA-tagged containers across 30+ deployments a month. Migrated 2.8 TB of on-prem SharePoint data to M365 with 0 data loss using a throttling-aware, multi-threaded Python engine (MSAL, REST APIs) that recovers gracefully from 429/503 tenant responses, alongside MuleSoft API and Intune MDM integration.

Case study
Azure
Bicep
Private Endpoints
NSGs
GitOps
+6

Resolved 26 security-audit findings across 37 endpoints and servers by architecting a default-deny WireGuard VPN, deploying Wazuh SIEM, and automating UFW and Bash rules with Ansible for SSH GeoIP anomaly blocking. Cut release cycles 73% (45 to 12 minutes) across 6+ production apps by standardizing Jenkins and GitHub Actions pipelines with SonarQube quality gates, tuning Linux kernels via sysctl, and engineering Restic encrypted backups.

Case study
WireGuard
Wazuh SIEM
Ansible
UFW
Jenkins
+5

Led an ELT-over-ETL data platform scaling to 24.7M time-series records, designing a resilient 3-tier PostgreSQL warehouse with star-schema modelling across 10+ sources, building delta-load transformers, and managing a Next.js/Plotly monorepo. Reached 99.9% execution success on data-acquisition pipelines by orchestrating headless-browser automation (Selenium/Chromium) through multi-profile Docker Compose and running 19+ idempotent SQL migrations.

Case study
PostgreSQL
Python
Docker Compose
Selenium
Chromium
+3

Reduced commit-to-production lead time 80% for an AI algorithmic-trading platform by orchestrating a React/C#/Python microservices stack on Azure Kubernetes Service with Helm templates and Azure Pipelines. Engineered horizontal scalability with HPA autoscaling and namespace-scoped RBAC, configured Kubernetes CronJobs for Apache Arrow Flight workloads, and deployed cache-busted Docker builds via Azure Container Registry.

Case study
Azure Kubernetes Service
Helm
Azure Pipelines
Azure Container Registry
HPA Autoscaling
+5

Cut logging-infrastructure costs 80% and removed cluster overhead for 5 GB/day of logs by retiring Elasticsearch and building a lightweight full-text search and trace-correlation engine on SQLite FTS5 and FastAPI. Achieved a validated 24-hour RPO and 2-hour RTO for Supabase/PostgreSQL through a nightly automated dump-and-restore pipeline that strictly verifies schema, role, and sequence integrity.

Case study
SQLite FTS5
FastAPI
Python
Supabase
PostgreSQL
+2

Reduced p99 API latency 86% (850 to 120 ms) for a healthcare ecosystem by migrating .NET and SQL microservices into a single-tenant Azure App Service Environment (ASE v3) behind Front Door, WAF, and APIM, guided by KQL telemetry. Closed 100% of VAPT findings on the first re-test by mitigating LUCKY13 CBC timing attacks with TLS 1.3, enforcing HSTS, centralizing secrets in Key Vault, and provisioning Mirth Connect with Azure Data Factory SSIS.

Case study
Azure ASE v3
Azure Front Door
WAF
APIM
Key Vault
+6

Drove MTTR down 65% by engineering a proactive, self-healing observability pipeline that uses CloudWatch telemetry to trigger SNS alerts and event-driven Lambda functions for automated EC2 remediation. Achieved a sub-5-minute RPO in live recovery drills by architecting a highly available multi-tier AWS environment with parameterized CloudFormation, least-privilege IAM, and isolated RDS with point-in-time recovery.

Case study
AWS
CloudFormation
Lambda
CloudWatch
SNS
+4

Trimmed cloud observability spend 45% and drove MTTD down to 2 minutes by replacing Azure Application Insights with a self-hosted ELK, Prometheus, and Grafana stack, including custom C# Serilog middleware for the Elastic APM cutover. Accelerated BI releases from 2 hours to under 10 minutes with modular Jenkins declarative pipelines, Apache Superset provisioning, and a custom Python CLI that promotes dashboards with zero standing credentials.

Case study
ELK Stack
Prometheus
Grafana
Elastic APM
Serilog
+4