04 // systems & network engineering
Twenty years of keeping things running.
Cloud and on-premises servers, enterprise storage, and the networks that tie
them together — sized for anything from a two-rack office to a business spread across the
country. Below are the kinds of problems I get brought in for, and what came out of them.
01 Finding petabytes of data nobody was using
A large organisation was buying ever more expensive high-speed storage while most of what
sat on it hadn't been opened in years. I profiled multi-petabyte file estates spread
across several different storage systems to work out what was genuinely still in use, then
moved the cold data to far cheaper cloud storage.
The important part was that nothing changed for the people using it — the files
appeared in exactly the same place, opened the same way, and nobody needed to be retrained.
The result was less expensive storage to buy, backups that finished in a fraction of the time,
and a smaller cloud bill.
Storage tieringMulti-petabyteCloud archiveZero user disruption
02 Communications that had to work in hostile conditions
Secure, mission-critical systems for defence work, carried from concept through to
deployment. This meant designing communication networks with military-grade encryption and
building them to keep running in remote and hostile environments where nobody is coming to
fix them.
The infrastructure I deployed roughly halved data transmission times and improved
reliability by around 30%, through redundancy and automatic failover — so that a
failure somewhere in the chain doesn't become a failure of the whole thing.
Secure networksEncryptionHigh availabilityFailover design
03 Healthcare systems where privacy is the floor, not the goal
Architecture for high-traffic clinical applications, where patient privacy law is the
starting requirement rather than the finish line. That meant designing for genuine scale
across both AWS and Azure, and hardening throughout — multi-factor authentication, encrypted
storage, and protection of data end to end.
Alongside the security work, redesigning how those systems were hosted took around
10% out of the client's running costs.
AWSAzureHIPAACost reduction
04 Moving a global operation to hybrid cloud
An organisation running investigations worldwide needed to move off ageing on-premises
systems without stopping work. Migrating to a hybrid cloud setup — some things staying local,
some moving out — cut operational costs by roughly 15%, and redesigning how data moved
through the system improved performance by about 20%.
Hybrid cloudMigrationData pipelines
05 Connecting sites across the country
A business with offices in different states and a data center somewhere else again needs
all of it to behave like one network. I build the encrypted tunnels that link offices, data
centers and remote workers, and increasingly I use SD-WAN — currently in production for
cross-country connectivity.
SD-WAN treats several separate internet connections as one intelligent link: it sends
traffic down whichever path is healthiest at that moment, switches away instantly when one
degrades, and applies the same rules everywhere. A branch in one state and a data center on
the other side of the country behave as though they're in the same building.
SD-WANSite-to-site VPNMulti-circuit failover
06 The everyday work underneath all of it
Most of what I know came from managed service providers, where you're handed dozens of
environments you didn't build — each to a different standard — and expected to be useful
inside an hour. Reading somebody else's cabling, somebody else's network design, somebody
else's firewall rules, and finding the actual fault rather than the one that's easiest
to blame.
Day to day that covers Windows and Linux servers, VMware and Hyper-V virtualisation,
enterprise storage from Dell EMC and Pure Storage, switching and routing on Cisco and Aruba,
firewalls from SonicWall, Cisco and Fortinet, and cloud-managed networking with Ubiquiti and
Meraki for smaller businesses that want enterprise behaviour without enterprise overhead.
It's also where I learned the part that isn't technical: telling an owner honestly what
something will cost, what it will fix, and what it won't.
VMwareHyper-VDell EMCPure StorageCiscoFortinetMerakiUbiquiti
07 Where it started
I served in the U.S. Army from 2005 to 2013 as an Information Technology Specialist,
including two tours in Iraq — installing and maintaining the networks, servers and
communications equipment a unit depends on, in conditions nothing like a climate-controlled
server room.
Eight years and two deployments is where the standard got set. In an office, an outage is
an inconvenience; downrange, communications are how people stay safe. That's where I learned
to fix what's in front of me with what I have, document so the next person isn't guessing, and
stay level when everything is failing at once.
U.S. Army veteran2005–20132× IraqAWS Certified