Cloud architecture, security, and platform engineering.
I have spent twenty years designing, migrating and securing infrastructure for federal agencies and regulated enterprises.
Most of the work is large Linux estates, database platform transitions, and datacenter-to-cloud migrations — systems where the compliance boundary matters as much as the deadline.
What I work on
Cloud architecture and migration
Datacenter-to-cloud programmes: landing-zone design, workload placement, right-sizing, and sequencing a migration in stages so the business keeps operating while it runs.
Security and compliance
Control implementation and audit readiness for systems that answer to an authorising official — turning a control catalogue into architecture, and explaining the result to auditors, programme managers and executives.
Platform engineering
Delivery pipelines, configuration management, infrastructure as code, and monitoring. Backups whose restores have actually been tested.
Systems engineering at scale
Enterprise Linux estates, database platform transitions, and high-performance computing for workloads that outgrow a single machine. Fleet upgrades planned so the rollback is as well understood as the rollout.
Selected work
Enterprise database platform transition
Moved high-volume transactional systems off a commercial relational database onto PostgreSQL, across both on-premises and cloud estates, in an environment handling sensitive but unclassified data under continuous audit. Ran alongside an enterprise Linux major-version upgrade and a Unix-to-Linux transition on the same fleet, so the three programmes shared a single rollback plan.
Eight-figure reduction in licensing and operating costRisk and capital-asset analytics platform
Delivered a risk-management and capital-asset projection programme inside a hundred-consultant analytics practice, alongside a dozen further data-processing engagements on cloud object storage and elastic compute. Operated high-performance Linux clusters against shared storage, and built the firm's internal IT function from nothing while the programme ran.
1,200+ virtual machines under managementDefense systems architecture
Cloud and systems engineering on a Department of Defense programme — automation, design and implementation, with security posture handled during design rather than as a review gate at the end.
Datacenter-to-cloud migration
Migrated a revenue-generating customer estate and its supporting servers out of an owned datacenter into public cloud, while acting as primary technical contact for the company's federal accounts and producing the SOC control documentation those accounts required. Completed a full productivity-suite conversion in the first thirty days.
150+ customers and 100+ servers migratedResearch high-performance computing
Led the HPC work behind a genomics research programme, building the cloud pipeline that processed genetic analyses against reference genome data, and translating between the academics defining the questions and the engineers building the systems.
Re-platformed and relocated without data lossEngagements are described by shape, sector and scale rather than by client. Much of this work sits under non-disclosure agreements or federal sensitivity rules. Specifics can be discussed directly where an agreement permits it, and references are available on request.
How I work
Diagnosis before repair
Understanding a system and changing it are separate passes. Combining them is how a plausible theory gets shipped as a fix while the real fault survives.
Verified in production
A green pipeline is not a working system. I check the deployed behaviour against the live environment before calling something done.
Fail closed
Safety controls default to refusing, and anything that cannot be confirmed is reported as unknown rather than assumed fine.
Compliance during design
Controls considered at architecture time cost a design decision. The same controls discovered at assessment time cost a rebuild.
Documented handover
Runbooks, architecture decisions and the reasoning behind the trade-offs are part of the delivery, so the team can operate and extend the system without me.
Credentials
Certification
- CompTIA Security+ CE
- AWS Technical Professional
- CISSP — candidate
Standards
- FISMA
- FedRAMP
- NIST 800-53 & 800-171
- SOC reporting & audit support
Sectors
- Federal civilian
- Department of Defense
- Commercial SaaS & analytics
- Research & non-profit
Affiliations
- IEEE — Institute of Electrical and Electronics Engineers
- ISOC — Internet Society
Contact
Email is the best way to reach me. A short description of what is failing, or what is being planned, is enough to start.
Consulting engagements run through my practice at bashsolutions.com.