12+ years architecting the systems that let organisations run reliably and scale sensibly — from server topologies and Zero-Trust networks to Copilot-driven automation and bespoke platforms built for design, finance and operations teams. I sell solutions ready: tell me the requirement, I’ll show you the working answer.
Position, location, notice period, target roles, and how to reach me — without scrolling the whole page.
Hands-on technology leadership across the layers most organisations only buy. Equally comfortable architecting a Hyper-V cluster, hardening a FortiGate edge, deploying Copilot Studio agents, leading a phishing incident in real time, or assembling a workstation from parts when the deadline demands it.
I lead enterprise technology operations end-to-end — server-side topologies, networks, voice platforms, cybersecurity, cloud and the AI/automation layer that ties them together. Most engagements span infrastructure design, project delivery, vendor and MSP management, ISO-aligned governance and team leadership.
Over the last decade I have delivered hybrid Azure environments, multi-emirate office rollouts, Zero-Trust and Business Premium / E5 migrations, IP-PABX modernisation, Xerox XWC cloud-print topologies, and an AI orchestration layer combining Copilot Studio, Claude, Gemini, Grok, Vertex AI and MCP services — applied across Finance, HR, Architecture, Facilities, Fleet, Guest Management and Task Operations.
"Tell me the requirement. I'll show you the working answer."
Currently leading infrastructure and digital transformation at Archcorp Creative Technologies — active M365 E5 migration, completed Business Premium migration, Hexnode MDM rollout, Zero-Trust framework purpose-built for the GPU rendering teams, a 360°-protected endpoint estate, custom DLP and productivity-monitoring, and bespoke platforms supporting Autodesk Forma and Construction Cloud for the design teams' custom requirements. Open to Technology Lead, Head of IT and Transformation Lead roles across the UAE and EU.
Concrete deliveries from the last few years — the platforms, programmes and incidents that make up the working portfolio behind the title.
Twelve domains I architect, deploy, harden, monitor and replace when they stop earning their keep — grouped roughly in the order I tend to address them on a transformation engagement.
Redundant on-prem and hybrid topologies — domain controllers, file/app servers, clustered Hyper-V and VMware estates, NAS and MSA SAN storage, with high-availability auth and print services.
Enterprise LAN/WAN, multi-site VPN, segmented VLAN topologies, structured cabling and controller-based wireless — designed, documented, and administered as a working day-job, not a project deliverable.
IP telephony rollouts and unified communications across Zycoo, 3CX and Microsoft Teams Voice — SIP trunking, call routing, conferencing rooms, IP speaker systems and digital reception platforms.
Perimeter, endpoint and email security with live incident response. ISO 27001 ISMS preparation, third-party VAPT cycles and phishing-campaign containment with post-incident hardening.
Hybrid cloud on Azure and AWS — IaaS workloads, M365 tenancy operations, identity governance, Conditional Access, and licensing migrations from Business Premium through to E5.
Unified management across corporate, BYOD and mobile estates — provisioning, app delivery, compliance, signature solutions and secure WFH onboarding. Plus hands-on custom PC assembly for visualisation teams.
Data Loss Prevention, data activity monitoring and productivity capture — wired into the EDR, identity and mail layers for a single, end-to-end protection posture.
3-2-1-1-0 backup designs, immutable repositories, replicated DR sites and tested failover runbooks — built around meaningful RPO and RTO targets, not theatre.
Effective use of Copilot and Copilot Studio rather than scripted automations — combined with deployed MCP services and external models from Claude, Gemini, Grok and Vertex AI behind a single flow-maker interface.
IT lead for design teams running Autodesk Forma and Construction Cloud — identity, access, custom integrations and bespoke supporting platforms shaped to the studio’s actual workflow, plus Xerox XWC cloud-print topology for the wider organisation.
Hands-on with extra-low-voltage infrastructure — structured cabling, fibre runs, CCTV cabling, access-control topologies, intercom, paging and barcode/document scanner integrations.
ITIL-aligned service operations and a custom-built ITSM platform designed at MSP service-level — ticketing, asset register, knowledge base and SLA reporting integrated with Azure AD and Teams.
From trading-floor support in India and field engineering in Kuwait, to logistics IT for IKEA in Dubai, and now leading enterprise technology at a UAE design consultancy with overseas operations.
Each card is a working solution, ready to discuss in detail — the customer scenario, the approach, the stack and the measurable outcomes. Click through for the full case-study.
I don’t pitch in the abstract. Each problem below has a built and tested answer — Finance, HR, Design Tech, Facilities, Fleet, ITSM, Voice, Print and Secure WFH. Tell me which one you’re trying to solve, and I’ll show you what I’ve already shipped.
Selected delivery photos from current and recent projects. Some content is sensitive; access is restricted to invited reviewers only.
Enter the access code shared with you to view the project library.
archcorp
Replaced an unstructured legacy fabric — tangled patching, mixed vendors, inconsistent labelling — with a clean, segmented topology. New patch panels, structured cable management, FortiGate edge, Cisco core, QNAP NAS, HPE servers, and a properly documented rack elevation.
The right-hand image is the as-built. The left-hand is the starting point.
The current Archcorp wireless design — FortiGate 200F → service switch → four ceiling APs (Idea Hub, Reception, Workplace, Lounge), monitored via Cisco Business Dashboard.
Policy-segregated SSIDs: AC_Enterprise and AC_Conference get authenticated access to internal resources; AC_Guest and AC_Mobile are constrained to internet-only with a captive portal — all enforced at the firewall, not the AP.
This is what was running the office voice estate when I arrived — Panasonic TDA200 hybrid PBX with a TVM200 voice processor and a Mediatrix C7 gateway, sitting on top of a wall-mounted Krone block. Functional, but fragile and impossible to extend.
Replaced with a unified voice platform across Zycoo IP-PABX, 3CX and Microsoft Teams Voice, with SIP trunking, meeting-room conferencing and IP speaker integration.
Formal credentials underpinning the operational stack — Microsoft Azure and M365 administration, Cisco networking, AWS cloud foundations and Apple ecosystem certification.
Open to Technology Lead, Head of IT and Transformation Lead positions across the UAE and EU, and to advisory engagements where the brief is sound infrastructure and considered automation.