Things I've designed, built, and shipped.
Complete Azure Landing Zone (CAF Hub & Spoke)
A full Cloud Adoption Framework Azure Landing Zone in Terraform and Azure Verified Modules, covering the management-group hierarchy, an enforced policy baseline, dual-region hub-and-spoke with Azure Firewall Premium, four platform subscriptions, and corp/online landing zones, all shipped through OIDC GitHub Actions with policy-as-code PR gates.
Read case studyAzure Virtual Desktop Landing Zone (Terraform + AVM)
A reference-grade AVD application landing zone built entirely from Azure Verified Modules in Terraform and shipped through OIDC GitHub Actions with no stored secrets. It is CAF-aligned, Entra ID-joined, private-only, and mapped against every Microsoft AVD design area.
Read case studySecure CI/CD for Federal Workloads
Built and hardened CI/CD pipelines for multiple federal agencies, from application delivery to a multi-environment Azure data platform, folding code analysis and supply-chain scanning into the path to production, administering the GitHub organization (80+ repositories across ~10 applications), and holding the line on NIST and FedRAMP controls.
Read case studyGovernance & Secure Landing Zones
Operationalized the security pillar of the Well-Architected Framework into repeatable landing-zone guardrails, turning one-off security reviews into automated, baseline-enforced governance across Azure deployments.
Read case studyTwo-Site Stretched Azure Local Cluster
Designed and built a two-site stretched Azure Local (Azure Stack HCI) reference environment with storage-replica site-to-site replication and Azure Arc management, demonstrating edge infrastructure that survives the loss of a full site.
Read case study