AWS Certified Solutions Architect – Professional

Cloud infrastructure that works — designed, built, and kept running.

Networking and landing zones, compute and containers, CI/CD, observability, security, and cost control — end to end, mostly on AWS, with hands-on GCP and Azure for teams that aren't. You work directly with the person doing the work.

Read-only, always Fixed-fee engagements GCP & Azure capable

Read how engagements actually work →

Reference architectures

Patterns I actually build.

Five common builds, cycling on their own — click a tab to stop it and dig in, or click any box for what it actually does.

microservices.svg
SHIP A CHANGEGitHubCIBuild & testSecurity scanTrivy · SonarQubeECRArgoCD syncEDGE & IDENTITYRoute 53CloudFront+ Shield AdvancedCognitoAPI GatewayAmazon EKS — App Mesh sidecarsOrdersInventoryPaymentsEventBridgePer-service data storesOBSERVABILITY & GOVERNANCEX-RayCloudWatchPrometheus + GrafanaGuardDuty + Security HubAlerting EDGE & SECURITYRoute 53CloudFront+ Shield AdvancedAWS WAFALBmulti-AZS3static assetsAPPLICATION TIERSecrets ManagerApp TierEC2 / ECS · Auto ScalingParameter StoreDATA TIERElastiCacheRedisRDS PrimaryMulti-AZRDS ReadReplicaS3(AWS Backup)GOVERNANCE & OBSERVABILITYCloudWatchAWS ConfigCloudTrailAWS Backup INGEST & GOVERNKinesisS3Data lakeGlueETL + CatalogLake FormationML PIPELINE — SAGEMAKER PIPELINES (CI/CD/CT)SageMakerFeature StoreSageMakerTrainingSageMakerProcessing (Eval)ModelRegistryDEPLOYCodePipelineSageMakerEndpoint (prod)BatchTransformMONITOR & GOVERNModel MonitorCloudWatchEventBridgeCloudTrail + IAM DISCOVER & PLANApplicationDiscovery ServiceMigration HubMigrationEvaluatorCONNECTOn-PremData CenterDirect ConnectSite-to-Site VPN(backup path)Transit GatewayMIGRATEAWS MGNApp migrationAWS DMS + SCTDatabase migrationLanding Zone /Control TowerTARGET AWS ENVIRONMENTEC2(migrated, multi-AZ)RDS(migrated, multi-AZ)Route 53ResolverCloudWatch SOURCE ENVIRONMENTSource Cloud VMs(Azure / GCP)SourceManaged DBSource IdP(Entra ID / Cloud IAM)CONNECT & REPLICATECross-cloud linkInterconnect + VPN backupReplicationPipelineTransit GatewayTARGET AWS — PARALLEL RUNLanding Zone /OrganizationsTarget WorkloadEC2 + RDS, multi-AZIAM IdentityCenterCUT OVER & VALIDATERoute 53Weighted routingCloudWatchValidationCost ExplorerDecommissionsource

Capability

End-to-end, not just one layer.

Eight layers, one point of contact. Everything here is a system I've built, not a slide I've presented.

Foundations & Networking

VPC design, multi-account landing zones, and IAM boundaries that contain the blast radius.

Compute & Containers

EC2, EKS/Kubernetes, ECS/Fargate, and Lambda — sized for the actual workload, not a guess.

CI/CD & Infrastructure as Code

Terraform, GitOps via ArgoCD, Jenkins, GitHub Actions — changes ship safely, not by hand at midnight.

Observability & Monitoring

Prometheus, Grafana, CloudWatch, and alerting scoped to page the person who can fix it.

AI/ML & LLM Infrastructure

SageMaker pipelines, Bedrock, and retrieval-augmented tools for internal use.

Multi-Cloud (GCP & Azure)

AWS-deep, hands-on elsewhere — for teams not fully on one cloud.

Ways to work together

Engagement models.

Assessment

A prioritised review of what's risky, wasteful, or fragile right now.

Implementation

Design and build it — empty account to production-ready.

Managed Operations

Once it's live, I keep it running: monitoring, incidents, iteration.

Enablement

Your team takes over — you're not locked into needing me forever.

Why not an agency

You hire the person doing the work.

No account manager, no bench of juniors learning on your bill, no multi-week procurement process.

Direct access

You talk to the person writing the Terraform, not a relay.

Transparent pricing

Quoted upfront — proven on the live audit service.

Documented approach

Written down, not tribal knowledge you take on faith.

Fast start

A scoping call, then a start date — no procurement maze.

Approach

How I'd approach common engagements.

One is a pattern description. Two are real and live right now.

Approach pattern

Landing zone from zero

One unstructured AWS account. A multi-account foundation — segmentation, centralized logging and IAM — so every new workload starts on solid ground.

Get in touch

Let's talk about what you're building.

AWS Certified Solutions Architect – Professional, verified on Credly — with hands-on GCP and Azure experience too.