Azure architecture · security · governance
Azure architecture for teams without an architect.
Most companies running real workloads in Azure have capable engineers and nobody who owns the whole picture. I review your entire tenant and hand you a prioritized, costed remediation plan — read-only access, ten business days, under two hours of your team's time.
The flagship engagement
Azure Security & Governance Posture Assessment
You grant Reader access. I run the analysis, you carry on with your week, and ten business days later you get a findings register, an executive summary your board can read, and a remediation roadmap with hours attached to every item. Nothing is changed and nothing goes down.
What gets reviewed
- Identity and access — Conditional Access, legacy auth, MFA coverage, PIM and standing privilege, guest and service principal hygiene
- Network and segmentation — hub/spoke design, NSG rules, firewall policy, public IP exposure, WAF configuration, private DNS
- Data protection — storage exposure, customer-managed keys, disk encryption sets, SQL TDE, Key Vault access and rotation
- Private connectivity — private endpoint coverage across PaaS, DNS resolution, remaining public data-plane exposure
- Governance — management groups, Azure Policy coverage, exemption sprawl, subscription topology, tagging, resource locks
- Threat detection — Defender for Cloud coverage, Sentinel design and rule tuning, diagnostic settings, log retention against audit need
- Automation and IaC — clickops versus code, Terraform structure and drift, pipeline security, service connection scope, secret handling
- Resilience and cost — backup coverage and tested restores, DR design, orphaned resources, rightsizing, reservation gaps
What you receive
- Executive summary written for non-technical leadership — risk in plain language, cost to fix, cost of doing nothing
- Findings register with severity, affected resources, evidence, remediation steps and an effort estimate in hours
- Prioritized roadmap grouped Now / Next / Later, with quick wins called out separately
- Compliance mapping to HIPAA, PCI-DSS, SOC 2 or your cyber-insurance questionnaire
- Cost findings with identified annual savings
- Recorded readout and a summary deck
Commonly found
- Storage accounts and databases still reachable from the public internet
- Standing Owner and Contributor access that should be PIM-eligible
- Policy assigned but never enforced, with exemptions nobody owns
- 15–30% of monthly spend in idle, orphaned or oversized resources
Priced by subscription count and whether a named compliance framework is in scope. An optional AI workload module covers Azure OpenAI and AI Foundry deployments — private networking, key management, data retention and residency.
Beyond the assessment
Engagements that follow
Most assessments end with a list of work worth doing. These are the pieces I take on directly — all scoped, scheduled and fixed-fee, with change windows agreed in advance.
Landing zone & governance build
Management groups, policy sets, subscription vending, RBAC model and naming standards — delivered as Terraform and a pipeline, not a diagram.
Infrastructure as code
Clickops converted to modules, state strategy, PR and approval gates, drift control, and Azure DevOps or GitHub pipelines that hold up under audit.
Secure AI deployment
Azure OpenAI and AI Foundry done properly — private endpoints, customer-managed keys, data residency and retention, RBAC, logging and cost guardrails.
Findings remediation
Private endpoints, CMK and disk encryption rollout, TDE, NSG rework, Defender and Sentinel tuning. Priced per finding, delivered in scheduled windows.
Migration design
VMware and Nutanix estates into Azure — target architecture, landing zone, wave planning, and cutovers run in weekend windows.
Resilience & DR
Backup coverage, DR design and an actual tested failover with a documented runbook — the artifact auditors ask for and most companies can't produce.
For managed service providers
An Azure architect, white-labeled
If you sell Azure but don't have an architect on staff — and can't justify hiring one for the utilization — I work behind your brand. Your logo on the report, your client relationship, your margin.
- White-labeled deliverables. Your branding on every document. Your client never hears my name unless you want them to
- You keep the relationship. I don't sell to your clients, and that's in the agreement, in writing, both directions
- Fixed scope, fixed fee. You know your cost before you quote your price
- A service line without a hire. Add Azure architecture and security assessments to what you sell, starting this quarter
- It generates follow-on work. Every assessment ends in a remediation backlog you can sell and deliver
- Certificate of insurance on request, along with a signed subcontractor agreement
Who you'd be working with
One architect, not a bench
Fifteen years in enterprise infrastructure, the last five doing architectural-level cloud engineering in Azure — landing zones, governance, security and infrastructure as code at scale, including roughly 120,000 lines of production Terraform. Northbound Cloud is a one-architect practice, deliberately. The person who scopes the work is the person who does it. No pitch team, no handoff to whoever was free.
Based in the Charlotte, North Carolina area, working with clients anywhere in the US.
Get in touch
Tell me what you're running
A short email describing your environment and what's prompting the question is enough to get a straight answer about whether an assessment is the right starting point — and if it isn't, I'll say so.
A note on scope. Northbound Cloud delivers scheduled, fixed-scope engagements. It is not a managed service provider — there is no help desk, no monitoring contract and no after-hours support line. If that's what you need, I'm happy to point you toward someone who does it well.