Azure architecture · security · governance

Azure architecture for teams without an architect.

Most companies running real workloads in Azure have capable engineers and nobody who owns the whole picture. I review your entire tenant and hand you a prioritized, costed remediation plan — read-only access, ten business days, under two hours of your team's time.

The flagship engagement

Azure Security & Governance Posture Assessment

You grant Reader access. I run the analysis, you carry on with your week, and ten business days later you get a findings register, an executive summary your board can read, and a remediation roadmap with hours attached to every item. Nothing is changed and nothing goes down.

10 business days
Kickoff to readout, on a fixed timeline
Under 2 hours
Total time required from your team
Read-only
Reader and Security Reader. No agents, no changes
Fixed fee
Quoted up front. No hourly billing, no overruns

What gets reviewed

  • Identity and access — Conditional Access, legacy auth, MFA coverage, PIM and standing privilege, guest and service principal hygiene
  • Network and segmentation — hub/spoke design, NSG rules, firewall policy, public IP exposure, WAF configuration, private DNS
  • Data protection — storage exposure, customer-managed keys, disk encryption sets, SQL TDE, Key Vault access and rotation
  • Private connectivity — private endpoint coverage across PaaS, DNS resolution, remaining public data-plane exposure
  • Governance — management groups, Azure Policy coverage, exemption sprawl, subscription topology, tagging, resource locks
  • Threat detection — Defender for Cloud coverage, Sentinel design and rule tuning, diagnostic settings, log retention against audit need
  • Automation and IaC — clickops versus code, Terraform structure and drift, pipeline security, service connection scope, secret handling
  • Resilience and cost — backup coverage and tested restores, DR design, orphaned resources, rightsizing, reservation gaps

What you receive

  • Executive summary written for non-technical leadership — risk in plain language, cost to fix, cost of doing nothing
  • Findings register with severity, affected resources, evidence, remediation steps and an effort estimate in hours
  • Prioritized roadmap grouped Now / Next / Later, with quick wins called out separately
  • Compliance mapping to HIPAA, PCI-DSS, SOC 2 or your cyber-insurance questionnaire
  • Cost findings with identified annual savings
  • Recorded readout and a summary deck

Commonly found

  • Storage accounts and databases still reachable from the public internet
  • Standing Owner and Contributor access that should be PIM-eligible
  • Policy assigned but never enforced, with exemptions nobody owns
  • 15–30% of monthly spend in idle, orphaned or oversized resources
From $6,500 · fixed fee

Priced by subscription count and whether a named compliance framework is in scope. An optional AI workload module covers Azure OpenAI and AI Foundry deployments — private networking, key management, data retention and residency.

Beyond the assessment

Engagements that follow

Most assessments end with a list of work worth doing. These are the pieces I take on directly — all scoped, scheduled and fixed-fee, with change windows agreed in advance.

Landing zone & governance build

Management groups, policy sets, subscription vending, RBAC model and naming standards — delivered as Terraform and a pipeline, not a diagram.

Infrastructure as code

Clickops converted to modules, state strategy, PR and approval gates, drift control, and Azure DevOps or GitHub pipelines that hold up under audit.

Secure AI deployment

Azure OpenAI and AI Foundry done properly — private endpoints, customer-managed keys, data residency and retention, RBAC, logging and cost guardrails.

Findings remediation

Private endpoints, CMK and disk encryption rollout, TDE, NSG rework, Defender and Sentinel tuning. Priced per finding, delivered in scheduled windows.

Migration design

VMware and Nutanix estates into Azure — target architecture, landing zone, wave planning, and cutovers run in weekend windows.

Resilience & DR

Backup coverage, DR design and an actual tested failover with a documented runbook — the artifact auditors ask for and most companies can't produce.

For managed service providers

An Azure architect, white-labeled

If you sell Azure but don't have an architect on staff — and can't justify hiring one for the utilization — I work behind your brand. Your logo on the report, your client relationship, your margin.

  • White-labeled deliverables. Your branding on every document. Your client never hears my name unless you want them to
  • You keep the relationship. I don't sell to your clients, and that's in the agreement, in writing, both directions
  • Fixed scope, fixed fee. You know your cost before you quote your price
  • A service line without a hire. Add Azure architecture and security assessments to what you sell, starting this quarter
  • It generates follow-on work. Every assessment ends in a remediation backlog you can sell and deliver
  • Certificate of insurance on request, along with a signed subcontractor agreement

Who you'd be working with

One architect, not a bench

Fifteen years in enterprise infrastructure, the last five doing architectural-level cloud engineering in Azure — landing zones, governance, security and infrastructure as code at scale, including roughly 120,000 lines of production Terraform. Northbound Cloud is a one-architect practice, deliberately. The person who scopes the work is the person who does it. No pitch team, no handoff to whoever was free.

Based in the Charlotte, North Carolina area, working with clients anywhere in the US.

Azure Landing Zones Terraform Entra ID Conditional Access Azure Policy Defender for Cloud Microsoft Sentinel Private Endpoints Azure Firewall Key Vault & CMK Azure DevOps PowerShell Python VMware & Nutanix Rubrik & Zerto

Get in touch

Tell me what you're running

A short email describing your environment and what's prompting the question is enough to get a straight answer about whether an assessment is the right starting point — and if it isn't, I'll say so.

Email
Based in
Charlotte, North Carolina

A note on scope. Northbound Cloud delivers scheduled, fixed-scope engagements. It is not a managed service provider — there is no help desk, no monitoring contract and no after-hours support line. If that's what you need, I'm happy to point you toward someone who does it well.