Azure Infrastructure Architect
Platform Engineer
DevOps Architect
Security Architect
Site Reliability Engineer

Building the cloud,
the right way.

Platform engineer specialising in Azure infrastructure automation, identity & access management, and multi-tenant cloud governance at enterprise scale.

Current role
Platform Engineer
Olympus · Digital Unit · Platform Engineering
Certifications
AZ-900 AZ-104
Core stack
Azure Terraform PowerShell Azure DevOps Entra ID
CL
Colin Landers
Azure Infrastructure Architect · Platform Engineer · DevOps Architect · Security Architect
Cloud infrastructure,
done deliberately.

I'm a platform engineer on a Digital Unit team, where I design and build the Azure infrastructure foundations that product teams build on top of. That means Landing Zone patterns, hub-spoke networking, multi-tenant Entra ID governance, and everything in between.

My philosophy is simple: automate everything that can be automated, keep security posture tight with least-privilege by default, and treat infrastructure as code — always. I live in Azure, Terraform, PowerShell, and Azure DevOps pipelines day to day.

Outside of infrastructure, I'm expanding my roots in infrastructure and related services while keeping a close eye on how AI tooling is reshaping the cloud engineering workflow.

23+
Years in Technology
8+
Years in Azure
2
Azure certifications
What I bring to the table

From infrastructure design to security architecture and DevOps automation — here's what I do best.

Azure Infrastructure
Hub-spoke networking, Landing Zone architecture, private endpoints, Azure Monitor, Defender for Cloud, and multi-subscription governance.
AZ-104Hub-SpokeAPIMFront Door
Identity & Access (UIAM)
Entra ID governance, External ID/CIAM platform, Entra B2B, custom RBAC roles, ABAC conditions, app registrations, and least-privilege IAM patterns.
Entra IDExternal IDAZ-900SAML/OIDC
Infrastructure as Code
Terraform Cloud (azurerm, azuread, azapi, tfe), reusable modules, state management, Terraform Cloud workspace orchestration, and EPAC.
TerraformTerraform CloudazapiScalr
DevOps & Automation
Azure DevOps pipelines, PowerShell 7+ scripting, Graph SDK, REST API automation, and scheduled compliance tooling.
Azure DevOpsPowerShellGraph APIKQL
Microsoft Fabric & Analytics
Fabric capacity provisioning, Log Analytics workspace integration, Power BI Admin API, GraphQL APIs, lakehouses, and KQL query engineering.
Microsoft FabricLog AnalyticsKQLPower BI
Security & Compliance
ISO 27001 controls, Defender for Cloud, Microsoft Purview, Azure Policy, RBAC audit automation, and least-privilege service principal governance.
DefenderPurviewISO 27001Azure Policy
Microsoft Certified: Azure Fundamentals
AZ-900 · Microsoft
Microsoft Certified: Azure Administrator Associate
AZ-104 · Microsoft
Projects

A cross-section of platform engineering work spanning infrastructure, automation, security, identity, and observability.

Identity
UIAM Platform — Entra External ID

End-to-end External ID / CIAM platform build for a multi-tenant organisation. Terraform-managed app registrations, custom RBAC roles, Log Analytics bootstrapping, and cross-tenant user sync automation via Azure DevOps pipelines.

Infrastructure
Enterprise Production Landing Zone

Multi-subscription hub-spoke network deployment for enterprise production workloads. Private endpoints, Defender for Cloud integration, DNS hierarchy management, and Terraform Cloud workspace orchestration across environments.

Security
Azure RBAC Audit Automation

Scheduled weekly RBAC audit pipeline covering service principal security, managed identity permissions, and cross-subscription role assignments. PowerShell + Azure DevOps with CSV audit trail output and anomaly flagging.

DevOps
Microsoft Fabric Monitoring Pipeline

Bulk Log Analytics workspace integration across 24+ Microsoft Fabric workspaces via Power BI Admin API. Terraform-managed Fabric capacity, lakehouses, and GraphQL API health index with KQL-based monitoring dashboards.

Infrastructure
Azure APIM + Fabric GraphQL

APIM integration layer over Microsoft Fabric GraphQL APIs using User-Assigned Managed Identity. Policy XML templating, UAMI attachment via azapi_update_resource, and production 500 error incident resolution.

Security
Cross-Tenant User Sync

Automated cross-tenant Entra ID user synchronisation comparing ~1,000 workforce tenant users against ~200 non-prod users using UPN prefix matching, with ADO pipeline YAML orchestration and Terraform Cloud variable sourcing.

Infrastructure
Azure to Azure Infrastructure Migration

End-to-end migration of 6 release environments across Azure tenants, including pipeline standardisation across Azure DevOps, Terraform Cloud workspace automation improvements, and environment parity enforcement through modular IaC patterns.

Security
Microsoft Purview Enterprise Activation

Enterprise-scale Purview deployment to analyse and govern data across Azure and Microsoft Fabric sources. Configured scanning, classification, and lineage tracking to support data governance at scale across the organisation.

Infrastructure
Azure Front Door CDN & WAF Policy

Deployed Azure Front Door with WAF policy to enforce network traffic via X-Azure-FDID header validation on public-facing services, while routing internal Azure traffic through private endpoints and private link for a fully segmented network posture.

DevOps
IoT Operations Infrastructure Deployment

Partnered with application teams to deploy Azure IoT Operations services at scale. Built Terraform-managed infrastructure and automated deployment pipelines, enabling efficient provisioning and consistent environment management across the IoT platform.

Infrastructure
ClickOps to Terraform: ML/AI App Migration

Converted a portal-provisioned Function/ML/AI application to fully Terraform-managed infrastructure. Involved state imports, pipeline creation, and architectural refactoring to align with platform Landing Zone best practices and IaC standards.

Security
Platform Landing Zone Disaster Recovery

Analysed and designed a comprehensive disaster recovery strategy for the platform Landing Zone. Covered cost optimisation, feature verification across recovery scenarios, and deployment efficiency improvements to reduce RTO and operational overhead.

Let's work together

Whether you need an Azure architect for a greenfield platform build, fractional consulting on identity and governance, or someone to review your IaC foundations — I'm open to conversations.