British Columbia, Canada · IT professional by trade · one engineer, start to finish

I run a company's IT for a living. The consulting brings that standard to yours.

My day job is administering Windows Server, SharePoint and Microsoft 365 estates — the accounts, the email, the file shares, the backups, the security. The habits that come with being responsible for someone else's production environment are the ones I bring to a small business that has never had that standard applied to it.

This started with a rack of secondhand hardware and a need to understand things properly: domains and forests, hypervisors, firewalls, a private cloud, eventually a whole security platform — built so I could get hands-on with what I couldn't touch at work. About four years on, that has become a consulting practice: one engineer who builds the thing, runs the thing, and stands behind it.

You work directly with the engineer who runs the cable, racks the server, writes the code, and answers the email. That's the whole company, and that's the point.

I'd rather hand you something that has been running in production for a year than something that only looks good on paper — and tell you plainly where it falls short. Every tool I recommend runs on my own infrastructure first. If it isn't good enough for mine, it doesn't go on yours.

Three commitments.

Good service. You reach the engineer, not a queue, and you hear back within a business day.

Resilient infrastructure. Built new or upgraded from what you have — designed on paper first, documented as I go, and tested by actually restoring the backup.

Solutions that pay for themselves. Open source where a subscription is the wrong answer; Sophos, Microsoft 365 or another enterprise platform where it is the right one. The recommendation is whichever fits, because I hold no reseller margin.

  1. 2022 One rack A rack of secondhand hardware, built to learn the full stack properly — domains and forests, hypervisors, firewalls — by running real systems and fixing what broke.
  2. 2023 · BCIS Degree, then full-time IT management A Computer Information Systems degree alongside a day job administering Windows Server, SharePoint, and M365 — theory turned into production ops.
  3. 2024–25 Built the platform A multi-tenant RMM + EDR security platform, a private LLM cloud, and an email-security gateway — engineered in-house to run my own fleet, and still running it.
  4. 2026 Consulting — and opening the source The consulting is the business: infrastructure, security and AI for small teams who want one accountable engineer rather than a vendor chain. The platform I founded and still maintain is now an open-source project rather than a product — I'd rather own the code in the open and compete on the work.

Everything above is verifiable, not a pitch — the security console, the private-AI chat, and the ops tooling all run on this same infrastructure. See what I run in production →

Focus Areas

End-to-end IT for small and mid-size organizations: physical infrastructure, identity, networking, storage, cloud, software, and AI.

  • Physical infrastructure I personally oversee or run: ethernet cabling, server-rack builds, structured cabling, UPS, and patch panels.
  • Networking from the ground up: L2/L3 switching, VLAN design, hardware firewalls, site-to-site VPNs, and wireless point-to-point bridges and backhauls (CPE710-class radios for distance links).
  • On-prem servers — Windows Server (AD DS, DNS/DHCP, GPO, IIS, Hyper-V) and Linux (Ubuntu, RHEL/Fedora) — alongside dedicated backup servers and snapshot-based recovery.
  • Cloud and hybrid: Azure (VMs, Entra ID, Intune, M365, Purview), AWS (EC2, S3, IAM, networking), and clustered VM workloads that span on-prem and cloud.
  • Software for hire: PHP/Linux web apps, custom internal tools, ticketing portals, dashboards, and SaaS-style products billed by retainer or fixed scope.
  • ERP and CRM integration: pulling enterprise data into custom workflows, automations, and AI assistants so the systems already in place actually talk to each other.
  • AI as part of the stack — not bolted on: on-prem private LLMs for sensitive data, agentic workflows (Claude Code, MCP, custom orchestrators), and AI-assisted ops.

Approach

Assess what’s actually there, stabilize what’s fragile, then modernize and automate — including AI where it pays for itself.

  • Start with a real assessment: walk the rack, read the firewall, audit AD/Entra, look at the backups — not just a questionnaire.
  • Stabilize the fundamentals first — identity, networking, storage, and backup — so the daily fire-fighting stops before any redesign work begins.
  • Modernize pragmatically: replace what genuinely needs replacing, virtualize what makes sense, move to cloud only where the math works.
  • Automate the repetitive: PowerShell and Bash for ops, Power Automate for business workflows, IaC-style configs for repeatable rebuilds.
  • Layer in security as a default — hardened baselines, MFA everywhere, least-privilege access, central logging — not as a separate "security project."
  • Bring AI in where the ROI is real: a private on-prem LLM on a single capable server can replace a paid AI subscription for every person on staff, and none of your data leaves the building.
  • Document as I go: diagrams, runbooks, and a maintenance plan an in-house team can actually pick up.

How I Work

Clear scope, small proofs, hands-on delivery, and documentation that outlives the engagement.

  • Define scope, success criteria, and constraints up front so everyone knows what "done" looks like — and what is explicitly out of scope.
  • Run small proof-of-concepts before rolling changes across an environment: stand up the new firewall in parallel, mirror the workload, validate, then cut over.
  • Engage hands-on: I run the cabling, rack the server, configure the firewall, build the AD/Entra design, write the script, ship the app — and supervise the trades I don’t do myself.
  • Use git, configuration-as-code, and versioned scripts so changes are reviewable instead of living in someone’s head.
  • Bring creative answers when the constraint is real — older systems, tight budgets, regulated data, or no internet at the destination.
  • Iterate: ship something useful, gather feedback, refine. Avoid month-long radio silence followed by a big-bang reveal.
  • Hand back diagrams, runbooks, and a maintenance schedule the in-house team can follow on a busy Monday morning.

That's who you'd be working with.

If you want that standard applied to your own setup, the first step is an hour of my time at no cost. I look at what you have, tell you plainly what's exposed and what to fix first, and the write-up is yours either way.

Book a free check-up →