Infrastructure that has to
survive the audit.
I have spent twenty years designing, migrating and securing infrastructure for federal agencies and regulated enterprises — the environments where the design review, the compliance boundary and the migration plan all have to hold at the same time.
Cloud architecture, security posture and the platform engineering that keeps a system maintainable after handover. Mostly large estates, long-lived data, and changes that cannot be rolled back by apologising.
Where the work concentrates.
Cloud architecture & migration
Datacenter-to-cloud programmes that land without a rewrite and without a surprise invoice. Landing-zone design, workload placement, right-sizing, and the sequencing that lets a migration run in stages while the business keeps operating.
Security posture & compliance
Control implementation and audit readiness for systems that answer to an authorising official. Translating a control catalogue into concrete architecture — and translating the resulting architecture back into language an auditor, a programme manager and an executive each accept.
Platform engineering & DevOps
Delivery pipelines, configuration management and the operational discipline that keeps a platform maintainable after handover. Infrastructure expressed as code, observability that answers real questions, and backups whose restores have actually been performed.
Systems engineering at scale
Enterprise Linux estates, database platform transitions, and high-performance computing for workloads that outgrow a single machine. Large-fleet upgrades planned so the rollback is as well understood as the rollout.
The kind of work, not the client list.
Enterprise database platform transition
Moved high-volume transactional systems off a commercial relational database onto PostgreSQL, spanning both on-premises and cloud estates, in an environment handling sensitive but unclassified data under continuous audit. Sequenced alongside an enterprise Linux major-version upgrade and a Unix-to-Linux transition across the same fleet, so the three programmes shared one rollback plan rather than three competing ones.
Eight-figure reduction in licensing and operating costRisk & capital-asset analytics platform
Delivered a major risk-management and capital-asset projection programme inside a hundred-consultant analytics advisory practice, alongside a dozen further data-processing engagements built on cloud object storage and elastic compute. Operated high-performance Linux clusters against shared storage, and stood up the firm's internal IT function from nothing while the programme ran.
1,200+ virtual machines under managementDefense systems architecture
Systems architecture on a Department of Defense programme — cloud and systems engineering, automation, design and implementation, with security posture treated as a design input rather than a review gate applied at the end.
Datacenter-to-cloud migration
Migrated a revenue-generating customer estate and its supporting server fleet out of an owned datacenter into public cloud, while acting as primary technical contact for the company's federal accounts and producing the SOC control documentation those accounts required. Ran a full productivity-suite conversion inside the first thirty days.
150+ customers and 100+ servers migratedResearch high-performance computing
Led the HPC effort behind a genomics research programme, building the cloud pipeline that processed genetic analyses against reference genome data — and acting as translator between the academics defining the questions and the engineers building the systems that answered them.
Re-platformed and relocated without data lossOn attribution. Engagements are described by shape, sector and scale rather than by client. Much of this work sits under non-disclosure agreements or federal sensitivity rules, and a public website is not the place to test their edges. Specifics can be discussed directly where an agreement permits it — and references are available on request.
How I actually work.
Diagnosis before repair
Understanding a system and changing it are separate passes. Collapsing them is how a plausible theory gets shipped as a fix while the real fault survives to surface later, usually at a worse moment.
Done means verified in production
A green pipeline is not a working system. Delivery ends when the real deployment path has run and the observable behaviour has been checked against the live environment — not when the change merges.
Fail closed, and say so
Safety controls default to refusing. Anything that cannot be confirmed is reported as unknown rather than assumed fine — an indicator that isn't measuring the thing it claims to measure is worse than no indicator at all.
Compliance is a design input
Controls considered at architecture time cost a design decision. The same controls discovered at assessment time cost a rebuild. The cheapest audit is the one the system was built to pass.
You keep the system
Runbooks, architecture decisions and the reasoning behind the trade-offs are deliverables, not afterthoughts. An engagement ends with your team able to operate and extend what was built, without me.
Direct engagement
You work with the person doing the build. No account layer, no handoff to a team you haven't met, no discovery phase that bills for reading your own documentation.
Certification, standards, sectors.
Certification
- CompTIA Security+ CE
- AWS Technical Professional
- CISSP — candidate
Regulatory depth
- FISMA
- FedRAMP
- NIST 800-53 & 800-171
- SOC reporting & audit support
Sectors served
- Federal civilian
- Department of Defense
- Commercial SaaS & analytics
- Research & non-profit
Affiliations
- IEEE — Institute of Electrical and Electronics Engineers
- ISOC — Internet Society
Start with the problem, not the spec.
The most useful first message describes what's failing or what's being planned, what it costs to get wrong, and what has already been ruled out. You'll get a direct answer on whether this is work worth taking on — including when the answer is no.
For consulting engagements through my practice, see bashsolutions.com.