Fixed-price work packages with agreed acceptance criteria — implemented changes, repeatable tests, and evidence you can hand to an enterprise buyer. Not advisory decks.
Getting a working product fit for enterprise deployment: identity and least-privilege access, secrets and secure configuration, data-tenancy boundaries, retention and deletion controls, audit logging, monitoring, incident and recovery runbooks. Commissioning independent penetration tests and owning the remediation.
Reusable evidence packs that stand up to customer due diligence: implemented controls mapped to ISO 27001 and SOC 2 expectations, residual-risk registers, and operating procedures. Readiness work — certification and attestation stay with the auditors.
AWS serverless platforms, event and data pipelines, infrastructure as code, CI/CD. Design, review, or hands-on build — pragmatic, cost-aware, and operable by the team you already have.
Deployment-focused assurance for AI features: system and data boundaries, prompt-injection and hallucination risk, human-review and low-confidence controls, data minimisation. Plus making agentic development tools genuinely productive inside a real engineering org — with the guardrails that keep humans accountable for what ships.
More than twenty years of software architecture and engineering leadership. Progressed from senior engineer to software architect at a SaaS scale-up, where I led the migration from a monolith to AWS serverless microservices, introduced infrastructure as code, and built the product analytics pipeline. Contributed to the technical due diligence behind a $25m investment, an acquisition made, and the company's own acquisition. Currently lead supplier on an enterprise production-hardening and assurance programme for a privacy-first AI company.
Email: work@mousepilot.co.uk
Profile: LinkedIn
Terms: Sole trader · UK based · remote-first, on-site by arrangement