Jul 2023 – Jan 2026
Senior DevOps / Platform Engineer (Technical Lead)
Azure · HITRUST-Aligned SaaSThe Craneware Group
Senior technical lead for platform engineering and SRE across a HITRUST-aligned SaaS platform, setting the CI/CD, IaC and observability standards adopted by every engineering squad as an individual-contributor technical authority.
Azure Landing Zones & policy-as-code: Designed and delivered a reusable Azure Landing Zone architecture as a shared platform capability in Terraform/OpenTofu: hub-and-spoke networking, management group hierarchies and custom Azure Policy guardrails enforcing tagging, SKU restrictions and private endpoints. Cut policy non-compliance by 80% and produced continuous HITRUST audit evidence.
Containerised & serverless platforms: Operated 20+ Azure Container Apps in production: revision strategies, HTTP/event-driven scaling, Dapr integration and managed identity bindings with zero-downtime deployments. Led an AKS proof-of-concept deploying SonarQube as a Kubernetes-native workload with Helm; the resulting ADR was adopted as the platform’s forward migration path.
CI/CD security guardrails: Embedded SonarQube and Snyk SAST/SCA as mandatory, self-service quality gates in every Azure DevOps pipeline: coverage thresholds, code-smell limits and security hotspot policies enforced across all squads without slowing delivery.
Secrets management platform: Owned enterprise secrets management as a shared capability across every Azure environment: RBAC access policies, managed identity integration and automated rotation for credentials, connection strings and API keys, eliminating hardcoded secrets across 15+ microservices and all CI/CD pipelines.
HashiCorp Vault SME: PoC & architecture: Designed and delivered a Vault Enterprise proof-of-concept on Azure evaluating dynamic secret issuance, PKI certificate automation and AppRole/Managed Identity auth, producing a formal security architecture recommendation and migration roadmap adopted by security and platform leadership.
CA & SAML certificate lifecycle: Owned all CA and SAML signing/encryption certificates and OIDC client credentials across platform environments: rotation cycles, Auth0 SSO certificate updates and Key Vault-based automated renewal, reducing SSO certificate incidents by over 90% and manual renewal effort by ~60%.
SRE observability & reliability: Built SRE observability foundations (Azure Monitor, Log Analytics, KQL) as reusable dashboards and alerting frameworks contributing to a 30% MTTR reduction; automated RBAC provisioning for Azure SQL, cutting manual effort ~85% with audit-ready compliance reporting.
IaC modernisation: Led the full migration from ARM templates to Terraform/OpenTofu, standardising 15+ Azure DevOps pipelines around reusable modules, approval gates and integrated security checks, materially reducing onboarding time for new services.
Platform operations & FinOps: Ran a FinOps review cadence (Azure Cost Management, KQL dashboards) surfacing idle VMs, orphaned disks and over-provisioned resources; acted as de-facto DBA for Azure SQL and PostgreSQL (schema changes, indexing, failover testing) maintaining 99.9%+ availability on HITRUST-compliant workloads.
Cross-team leadership & mentoring: Represented platform engineering in architecture forums with Software Architects, Product Engineering Leads and the Head of Security; presented infrastructure risk plans and platform roadmaps to CTO/VP stakeholders; authored runbooks and architectural guidance while mentoring engineers through weekly coaching sessions and workshops.