About

I turn security, compliance and governance constraints into architecture that ships.

Download CV (PDF)

Scale
AWS foundations from a first landing zone to 1,000+ accounts
Domain
Energy, insurance, luxury, media and health — CAC 40 to scale-up
Seat
Architect and tech lead for 10+ years — and CTO of an AI product

I’m Jeremy — a cloud architect with 10+ years across AWS, and more recently Google Cloud, spanning platform design, security, governance and FinOps. I hold the design authority on cloud foundations that whole organisations build on: secure by default, easy to reason about, and cheap to run — then I make them a place AI agents can safely operate, with the security toolchain and governance that make that defensible at enterprise scale.

Most of that work is infrastructure as code: organisational policy expressed as Terraform, identity wired to least privilege, and the fast path made the safe path. Where the tooling falls short I fix it upstream — eleven merged pull requests to the Terraform AWS provider — and I write up what I learn on my blog.

Community

Recognition

Where I've had impact

Experience

Mar 2025 – Present

TotalEnergies

Platform Engineer / Quality Lead

Design authority and quality lead for the group-wide AWS platform — the cloud foundation every entity in the group builds on.

  • Steward a 1,000+ account AWS organisation, shaping the guardrails, landing-zone patterns and governance that thousands of engineers inherit.
  • Reset how RUN is delivered — re-engineering the operating model and embedding AI agents to remove 50% of operational load, redirecting a team’s worth of capacity from toil to platform capabilities.
  • Reporting to the Head of Engineering, I built the skeleton of the AI harness the teams build on — skills, agents and plugins — while designing and delivering the AI security toolchain, non-regression workflow and the governance around them.
  • Python
  • Terraform
  • Custom Terraform provider
  • AWS
  • Azure (Entra ID)
  • GitHub Copilot
  • Claude Code

Sep 2024 – Apr 2026

MyUniqSkin

CTO

Founding technical leader for an AI product putting dermatological-grade skin analysis in the hands of pharmacists.

  • Owned the full technical vision as CTO — architecture, cloud strategy, model selection, security and roadmap — carrying the AI skin-scan product from concept to live deployment across pharmacies.
  • Architected a GCP-native platform (Vertex AI, Firebase, PostgreSQL) orchestrating Gemini and OpenAI models behind a single pharmacist-facing recommendation engine.
  • Python
  • Node.js
  • Vue.js
  • Google Cloud
  • Vertex AI
  • Firebase
  • PostgreSQL
  • Gemini
  • OpenAI
  • Claude Code

Jan 2024 – Dec 2024

Allianz Trade

SRE / AWS Architect — System Team

Recruited to raise an engineering organisation’s delivery, industrialisation and quality bar as a transverse System Team.

  • 500+ instances moved onto a tested AMI supply chain — an EC2 Image Builder “AMI Factory” replacing manual, drift-prone provisioning, so a patch became a pipeline run instead of a project.
  • A 50+ engineer SRE community rallied around one Terraform module estate (RDS, DynamoDB, Lambda, AWS Backup) — as lead maintainer I introduced Terratest and semantic versioning, making the shared modules the default rather than a fork per team.
  • Conceived and delivered a Visual Management platform that put real-time security, compliance and code-quality KPIs in front of leadership — turning governance from periodic audit into a continuous signal.
  • Owned the HashiCorp Vault platform end to end, onboarding teams onto brokered, least-privilege database access.
  • Python
  • Terraform
  • Terratest
  • AWS Lambda
  • Step Functions
  • AWS Config
  • EC2 Image Builder
  • S3
  • AWS Backup
  • ECR
  • Vault
  • PostgreSQL
  • GitLab CI

Jun 2022 – Dec 2023

Allianz Trade

Tech Lead / AWS Architect — Datahub

Technical authority for a strategic private-cloud-to-AWS migration, owning the target architecture and its industrialisation.

  • Defined the multi-region, multi-account target architecture and re-platformed the Terraform estate into reusable modules that became the team’s paved road.
  • Twice-a-year live failover to a secondary region: I engineered fully automated disaster recovery and the exercise that proves it, turning DR from a documented intention into a rehearsed capability the business can audit.
  • Drove resilience and toil reduction with Step Functions / Lambda state machines that self-diagnose and remediate common production failures.
  • AWS
  • Terraform
  • Step Functions
  • Lambda
  • DMS
  • RDS
  • S3
  • GitLab CI

Jun 2021 – Jun 2022

Jellysmack

SRE / AWS Architect

Owned the cloud architecture steering a data-centric scale-up from single-account start-up to enterprise-grade foundations.

  • 400+ TB of unencrypted, unbacked-up, mis-tiered S3 data brought into compliance — I defined the encryption, cross-account backup and lifecycle strategy that closed the audit gap and put the largest line of the storage bill under a tiering policy.
  • Led the move to a multi-account AWS architecture and the EC2-to-EKS migration, cutting blast radius and service-quota risk as the company scaled.
  • Architected an on-demand GPU platform (EKS, Karpenter, ArgoCD) giving data scientists elastic compute without standing cost.
  • AWS
  • EKS
  • Karpenter
  • ArgoCD
  • Fargate
  • Control Tower
  • SageMaker
  • Lambda
  • S3
  • EC2 Image Builder
  • Kaniko
  • Terraform
  • Checkov
  • Google Cloud

May 2018 – Mar 2021

Hermès

DevOps / AWS Architect

Technical lead of the 10-person System Team on a 150-person international programme, owning delivery from architecture through to production.

  • Set the release-engineering standards for the programme and led the migration of integration environments from Azure to AWS.
  • Architected a serverless configuration-diff platform (Lambda, DynamoDB, SQS, API Gateway) that gave the programme visibility into config drift across every environment.
  • Re-architected a single-node, freestyle Jenkins into a versioned, master-node delivery platform with shared libraries — the backbone for the programme’s deployments.
  • AWS
  • Jenkins
  • Docker
  • Terraform
  • Lambda
  • DynamoDB
  • SQS
  • API Gateway
  • EC2
  • GuardDuty
  • CloudTrail
  • Symfony
  • Vue.js
  • Node.js

Where I started

Early career

  • 2018PeugeotOps

    Containerised the developer environment and built the Jenkins/Ansible pipelines deploying a Symfony app to production on an Azure Swarm cluster.

  • 2015 – 2017Air LiquideDeveloper

    Built an international B2B portal on Drupal 7 (PHP), adding Gatling load testing and CI pipelines that ran PHP unit tests on every pull request.

Credentials

Certifications

Want to work together or compare notes? Get in touch →