Skip to content

Skills

What I know, and how well.

Years are the span since first professional use, which is the market convention. Where something has gone dormant I say so, because an unqualified number on a skill I have not touched in years is both misleading and easy to check. Where I have no confirmed start date, there is no number.

How to read the levels

Expert
Designed and owned it in production, across more than one engagement.
Strong
Built with it in production. Holds up under a deep technical interview.
Competent
Real production use — more often operated than designed.

Foundation

  • Linux

    18 yr

    Expert

  • System administration

    18 yr

    Expert

  • Networking

    18 yr

    Expert

  • Bash

    18 yr

    Expert

  • Incident response and RCA

    18 yr

    Expert

  • Bare metal and datacentredormant

    100+ servers across two datacentres. Ended 2019.

    8 yr

    Strong

Cloud

  • AWS

    10 yr

    Expert

  • Amazon EKS

    4 yr

    Strong

  • Amazon ECS and Fargate

    4 yr

    Strong

  • Amazon VPC and endpoints

    10 yr

    Strong

  • AWS IAM

    10 yr

    Strong

  • Amazon S3

    10 yr

    Strong

  • Amazon RDS and Aurora

    10 yr

    Strong

  • Azure and AKSdormant

    A 30-cluster AKS fleet across three continents, but only through 2025.

    2 yr

    Competent

  • Google Cloud and GKEdormant

    ETUS was the real depth. Dormant since 2023.

    2 yr

    Competent

  • AWS Transit Gatewaydormant

    Designed the hub-and-spoke, then handed it on.

    1 yr

    Competent

  • AWS Control Tower and Organizationsdormant

    1 yr

    Competent

  • Amazon SageMakerdormant

    1 yr

    Competent

  • AWS Gravitondormant

    1 yr

    Competent

  • AWS Secrets Manager and Credstashdormant

    1 yr

    Competent

  • Amazon CloudFrontdormant

    3 yr

    Competent

Containers and GitOps

  • Kubernetes

    Six years of span, four active. The 2023–2025 gap was all ECS.

    6 yr

    Strong

  • Docker

    6 yr

    Strong

  • GitOps

    Three mechanisms across three clouds — GKE, Flux on AKS, Argo CD on EKS.

    6 yr

    Strong

  • Helmdormant

    Wrote charts and built custom packages. Authorship, not consumption.

    1 yr

    Strong

  • Argo CDdormant

    Applications and ApplicationSets, with Helm and Kustomize integrated. Kojo only.

    1 yr

    Strong

  • Kustomizedormant

    1 yr

    Competent

  • Kargodormant

    Operated it as a platform user. Did not architect or deploy it.

    1 yr

    Competent

  • Fluxdormant

    Operated and debugged reconciliation. Did not design the setup.

    1 yr

    Competent

  • Karpenterdormant

    1 yr

    Competent

Infrastructure as code and CI/CD

  • Terraform

    Introduced it at Dock in 2016, during the move to AWS.

    10 yr

    Expert

  • CI/CD

    10 yr

    Expert

  • GitHub Actions

    4 yr

    Strong

  • Packerdormant

    Hardened PCI-DSS AMIs, calling Ansible and Bash. Immutable infrastructure on EC2.

    Strong

  • GitLab CIdormant

    4 yr

    Competent

  • Puppetdormant

    4 yr

    Competent

  • Ansibledormant

    Only at Dock, on the cloud migration. Dormant since 2019.

    3 yr

    Competent

  • Atlantisdormant

    1 yr

    Competent

  • CircleCIdormant

    1 yr

    Competent

  • Jenkinsdormant

    1 yr

    Competent

Reliability and observability

  • Site reliability engineering

    6 yr

    Strong

  • Observability and monitoring

    6 yr

    Strong

  • Datadog

    6 yr

    Strong

  • SLO and SLI

    99.99% at ETUS; 99% of API requests under two seconds at Kojo.

    6 yr

    Strong

  • Amazon CloudWatch

    10 yr

    Strong

  • OpenTelemetrydormant

    Org-wide rollout at Kojo, end to end.

    1 yr

    Strong

  • Prometheusdormant

    Essentially Sight Machine only.

    1 yr

    Competent

  • Grafana

    Four engagements. Start year not yet confirmed, so no figure is claimed.

    Competent

  • PagerDutydormant

    1 yr

    Competent

  • Sentrydormant

    2 yr

    Competent

  • Lokidormant

    Operated it. Never had to configure it.

    Competent

Data and performance

  • PostgreSQL

    4 yr

    Strong

  • Performance tuningdormant

    Tomcat and JVM at Dock (84% off the connection pool); Node heap and Postgres indexing at Kojo.

    5 yr

    Strong

  • FinOps and cost optimisationdormant

    87.5% at CoinList; CI at near-neutral cost at Kojo.

    1 yr

    Strong

  • Redisdormant

    4 yr

    Competent

  • MySQLdormant

    4 yr

    Competent

  • Elasticsearch and OpenSearchdormant

    Architected and implemented catalogue search at 4 Elements Music. Not a mastery claim.

    Competent

  • Apache Kafkadormant

    Part of the stack underneath me at Sight Machine. Operated, not mastered.

    1 yr

    Competent

Security and compliance

  • PCI-DSSdormant

    Provisioned the infrastructure that got the certification in three months.

    4 yr

    Strong

  • VPN and IPsecdormant

    4 yr

    Competent

  • Firewallsdormant

    4 yr

    Competent

  • OIDC federationdormant

    Removed long-lived AWS credentials from the delivery pipeline.

    1 yr

    Competent

Languages and AI

  • AI-assisted development (Claude)

    ddogctl was built end to end this way, as was the Kojo CI migration.

    2 yr

    Strong

  • Python

    In my stack since 2016. I read Python and I ship it with AI assistance — I designed and published ddogctl that way. I would not claim fluency writing it from scratch unassisted.

    10 yr

    Competent

  • Java and Springdormant

    Application server tuning, not development.

    4 yr

    Competent

  • Node.jsdormant

    1 yr

    Competent

  • Ruby on Railsdormant

    1 yr

    Competent

  • Djangodormant

    1 yr

    Competent

  • GraphQLdormant

    1 yr

    Competent

Practice

  • Technical documentation and runbooks

    18 yr

    Expert

  • Jira and Confluence

    13 yr

    Strong

  • Team leadership and mentoringdormant

    Founded and ran the SRE team at ETUS; mentored engineers at Caylent.

    2 yr

    Competent

Anything not on this list, I have not done enough of to answer questions about. That is deliberate — a keyword I cannot defend does not win a role, it loses an interview.