A home lab, a pile of secondhand hardware, and a habit of taking things apart to
understand them properly. I got into this because I couldn't leave the technology
alone — I wanted to be sharper at the day job running Windows servers and M365, so
I built the environments I couldn't get hands-on with at work: domains and forests,
hypervisors, firewalls, a private cloud, eventually a whole security platform.
About four years on, that obsession is a consulting practice. The same drive that
had me racking a server at 1 a.m. for fun is what clients hire today: someone
who builds the thing, runs the thing, and genuinely enjoys the parts most shops
outsource. I do the work — then I stand behind it.
No account managers. No ticket queue. No reselling a vendor's dashboard with a
markup on top. You work directly with the engineer who runs the cable, racks the
server, writes the code, and picks up the phone. That's the whole company, and
that's the point.
2022One rack, one obsessionA home lab built to learn the full stack properly — not from a course, from breaking and fixing real hardware.
2023 · BCISDegree, then full-time IT managementA Computer Information Systems degree alongside a day job administering Windows Server, SharePoint, and M365 — theory turned into production ops.
2024–25Built the platformA multi-tenant RMM + EDR security platform, a private LLM cloud, and an email-security gateway — all engineered in-house, all running today.
2026Taking on clients across BCThe passion project is the business now — serious security, AI, and infrastructure for small and mid-size teams who want one accountable engineer, not a vendor chain.
Everything above is verifiable, not a pitch — the security console, the private-AI
chat, and the ops tooling all run on this same infrastructure. See what
I run in production →
Focus Areas
End-to-end IT for small and mid-size organizations: physical
infrastructure, identity, networking, storage, cloud, software, and AI.
Physical infrastructure I personally oversee or run: ethernet cabling, server-rack builds, structured cabling, UPS, and patch panels.
Networking from the ground up: L2/L3 switching, VLAN design, hardware firewalls, site-to-site VPNs, and wireless point-to-point bridges and backhauls (CPE710-class radios for distance links).
On-prem servers — Windows Server (AD DS, DNS/DHCP, GPO, IIS, Hyper-V) and Linux (Ubuntu, RHEL/Fedora) — alongside dedicated backup servers and snapshot-based recovery.
Cloud and hybrid: Azure (VMs, Entra ID, Intune, M365, Purview), AWS (EC2, S3, IAM, networking), and clustered VM workloads that span on-prem and cloud.
Software for hire: PHP/Linux web apps, custom internal tools, ticketing portals, dashboards, and SaaS-style products billed by retainer or fixed scope.
ERP and CRM integration: pulling enterprise data into custom workflows, automations, and AI assistants so the systems already in place actually talk to each other.
AI as part of the stack — not bolted on: on-prem private LLMs for sensitive data, agentic workflows (Claude Code, MCP, custom orchestrators), and AI-assisted ops.
Approach
Assess what’s actually there, stabilize what’s fragile, then modernize and
automate — including AI where it pays for itself.
Start with a real assessment: walk the rack, read the firewall, audit AD/Entra, look at the backups — not just a questionnaire.
Stabilize the fundamentals first — identity, networking, storage, and backup — so the daily fire-fighting stops before any redesign work begins.
Modernize pragmatically: replace what genuinely needs replacing, virtualize what makes sense, move to cloud only where the math works.
Automate the repetitive: PowerShell and Bash for ops, Power Automate for business workflows, IaC-style configs for repeatable rebuilds.
Layer in security as a default — hardened baselines, MFA everywhere, least-privilege access, central logging — not as a separate "security project."
Bring AI in where the ROI is real: a private on-prem LLM running on a single capable server can replace dozens of $200/seat subscriptions for many orgs, with full data sovereignty.
Document as I go: diagrams, runbooks, and a maintenance plan an in-house team can actually pick up.
How I Work
Clear scope, small proofs, hands-on delivery, and documentation that
outlives the engagement.
Define scope, success criteria, and constraints up front so everyone knows what "done" looks like — and what is explicitly out of scope.
Run small proof-of-concepts before rolling changes across an environment: stand up the new firewall in parallel, mirror the workload, validate, then cut over.
Engage hands-on: I run the cabling, rack the server, configure the firewall, build the AD/Entra design, write the script, ship the app — and supervise the trades I don’t do myself.
Use git, configuration-as-code, and versioned scripts so changes are reviewable instead of living in someone’s head.
Bring creative answers when the constraint is real — older systems, tight budgets, regulated data, or no internet at the destination.
Iterate: ship something useful, gather feedback, refine. Avoid month-long radio silence followed by a big-bang reveal.
Hand back diagrams, runbooks, and a maintenance schedule the in-house team can follow on a busy Monday morning.