Landing zones
Multi-account structures for AWS Organizations, Azure Tenants, GCP Folders. Guardrails baked in from day one.
Identity & access
IAM, IAM Identity Center, Entra, Workload Identity Federation. Least-privilege without slowing engineers down.
Networking
VPCs, Transit Gateways, ExpressRoute, Cloud Interconnect, ZTNA. Drawn, documented, monitored.
Compute & containers
EC2, ECS, EKS, AKS, GKE, Fargate, Lambda, Cloud Run. Right-sized, autoscaled, observable.
Data & storage
RDS, Aurora, DynamoDB, Cosmos, Cloud SQL, BigQuery, Snowflake, Databricks. Backups tested, encryption at rest.
M365 & Google Workspace
Tenant baseline, Conditional Access / Context-Aware Access, mailflow, MDM, eDiscovery. The boring stuff, done right.
Observability
Datadog, Grafana, Sentry, CloudWatch, Azure Monitor. SLOs, runbooks, on-call rotations.
FinOps
Cost allocation, anomaly detection, savings plans, RIs, commitment optimization. Monthly executive review.
Cloud security posture
CSPM, CIEM, IaC scanning, secrets management, encryption strategy, log retention.