Skip to main content
Chris Chalmers - professional headshot

Chris Chalmers

Cloud Solutions Architect

United Kingdom

Helping enterprises build, migrate, secure, and optimise their cloud infrastructure - with hands-on delivery across Microsoft Azure, Microsoft 365, and hybrid environments.

Background

About

A bit about my background, focus, and how I work.

I'm a Cloud Solutions Architect with over 16 years in IT, the last several focused on designing and delivering enterprise-scale solutions across Microsoft Azure and Microsoft 365. I work with clients across finance, insurance, and retail to architect cloud environments, migrate complex workloads, and build secure, well-governed platforms that organisations can operate and scale with confidence.

I specialise in turning business requirements into practical cloud solutions - handling everything from tenant migrations and identity to infrastructure-as-code and automated delivery pipelines, so teams ship faster on a secure, consistent foundation.

I bring breadth across the Microsoft ecosystem - from Azure infrastructure and cloud-native services through to Microsoft 365, security, and device management. That cross-domain perspective lets me assess client needs quickly, lead teams of engineers through delivery, and design integrated solutions that are performant, stable, and deliver a strong end-user experience.

I'm driven by finding opportunities to streamline operations, reduce cost, and improve efficiency - whether that's consolidating services, automating repetitive processes, or modernising legacy infrastructure to take advantage of cloud-native capabilities - work that has eliminated recurring outages, retired duplicate infrastructure, and taken recurring cost and manual effort out of clients' day-to-day operations.

Key Skills

Cloud Solutions Architecture
Cloud Security, Identity & Zero Trust
Cloud Migration & Consolidation
Infrastructure as Code - Terraform
DevOps & CI/CD
Cost Optimisation & FinOps
Disaster Recovery & Business Continuity
Governance & Well-Architected Framework
C-Level Stakeholder & Commercial Management
People Management and Team Leadership
Service Delivery - ITIL Standards

Technology Skills

Artificial Intelligence

ChatGPT
Claude
Microsoft Copilot
Microsoft Foundry
Model Context Protocol (MCP)
Prompt Engineering

Azure IaaS

Azure Backup
Azure Firewall
Azure Site Recovery
Azure Virtual WAN
Virtual Machine Scale Sets
Virtual Machines

Azure PaaS/SaaS

App Services
Azure Container Apps
Azure DNS
Azure Front Door
Azure Functions
Key Vaults
Load Balancers
Storage Accounts
Traffic Manager

Identity & Access

Conditional Access
Global Secure Access
Microsoft Entra Connect
Microsoft Entra ID
Multi-Factor Authentication
Zero Trust

Security & SIEM

Defender for Cloud
Defender for Endpoint
Defender for Identity
Defender for Office 365
Microsoft Purview
Microsoft Sentinel

CI/CD

Azure Container Registry
Azure DevOps
Azure Managed DevOps Pools
Azure Pipelines
GitHub

Scripting & IaC

Ansible
Checkov
Packer
PowerShell
Terraform
TFLint

End-User Computing

Action1
Azure Virtual Desktop
Microsoft Intune MAM/MDM
Windows 365 Cloud PC
Windows Autopilot

Collaboration

Exchange Server
Microsoft 365
Microsoft Teams
Mimecast
OneDrive for Business
SharePoint Online

Database

Azure Database for MySQL
Azure Database for PostgreSQL
Azure SQL Database
Azure SQL Managed Instance
SQL Server

Observability

Application Insights
Azure Monitor
Grafana
Graylog
Log Analytics
Nagios
Netbox
Zabbix

On-Premises Infrastructure

Active Directory
Cisco
DFS
DHCP
DNS
Draytek
Fortinet
Group Policy
Meraki
NLB
NPS
Palo Alto
RRAS
Server 2008-2025
VMware
WSUS

Career

Experience

Architecture and delivery roles with finance, insurance, and retail clients, and Microsoft partners.

Cloud Solutions Architect

Soteria365

Mar 2024 - Present · Edinburgh, United Kingdom

Hands-on senior architecture role at a security-focused Microsoft partner, designing and deploying complex, large-scale enterprise cloud solutions for clients across the insurance sector.

  • Raised the average Microsoft Secure Score across managed clients from 40% to 90%, advancing them towards CIS and ISO 27001 and standardising security onboarding for new clients
  • Built an internal expiry-monitoring platform tracking 1,100 secrets, certificates, and accounts across client environments, eliminating a recurring cause of outages
  • Automated Let's Encrypt certificate issuance and renewal to replace paid certificates, removing around $1,500 per year in licence costs alongside 1-2 hours of manual effort per certificate each cycle
  • Deployed Azure Landing Zones across 8 client tenants using Terraform and Azure Verified Modules, establishing a governed, compliant foundation aligned with the Cloud Adoption Framework
  • Design and architect enterprise cloud solutions on Azure, applying Well-Architected Framework principles and aligning with client security, compliance, and operational requirements
  • Engage directly with clients and stakeholders to understand business objectives and translate them into scalable, cost-effective cloud architectures
  • Mentor and unblock engineering teams across infrastructure, networking, security, automation, and DevOps, raising delivery consistency across client engagements
  • Develop and maintain cloud architecture documentation including high-level and low-level designs, reference architectures, and organisational standards
  • Evaluate emerging cloud technologies and services to inform solution design and strengthen client recommendations
  • Establish shared best-practice and reference standards with fellow architects, reducing rework and driving consistency across engagements
  • Contribute hands-on to cloud engineering delivery including infrastructure as code with Terraform, CI/CD pipeline configuration, and platform automation

Global Lead of Cloud Solutions

Portfolio BI

Jun 2021 - Mar 2024 · London, United Kingdom

Led cloud infrastructure strategy and a team of infrastructure professionals for an investment management software provider.

  • Led an initiative to reduce ongoing infrastructure and application costs - conducted regular audits, consolidated services, analysed licensing, and migrated to modern technologies, resulting in a saving of $250k per year
  • Led and mentored a team of infrastructure professionals, fostering a culture of collaboration, innovation, and continuous improvement
  • Developed and executed an infrastructure strategy aligned with organisational goals, providing vision and direction for design standards, implementation, and ongoing maintenance across internal and client environments
  • Led the implementation of infrastructure projects, ensuring on-time and within-budget delivery
  • Created baseline standards for Conditional Access Policies through Terraform, meeting best practices and regulatory standards - deployed to internal and client environments, significantly improving security while minimising maintenance overhead through a centralised IaC approach
  • Transitioned internal and external VDI environments from Azure Virtual Desktop to Windows 365 Cloud PC, reducing ongoing support overhead, monthly costs, and initial provisioning time while providing a scalable modern desktop experience
  • Established and enforced security policies and procedures to safeguard data and infrastructure, ensuring compliance with relevant regulatory and industry standards
  • Developed and maintained robust disaster recovery and business continuity plans internally and within clients' environments
  • Managed relationships with infrastructure vendors, negotiating contracts, and maintaining service levels
  • Increased revenue opportunities by collaborating with partners and vendors to expand package service offerings - defined add-on technical services and worked with client account teams to strategically implement across clients

Director and Cloud Solutions Consultant

CC IT Consulting Ltd

Sep 2020 - Jun 2021 · London, United Kingdom

Independent consultancy providing cloud architecture expertise, Azure migration, and DevOps solutions on a contract basis.

  • Provided architecture expertise and implementation for migration of on-premises Microsoft IIS websites and SQL databases into Microsoft Azure, leveraging IaaS for IIS servers and PaaS for SQL databases
  • Created PowerShell scripts to remove repetitive tasks and provide a baseline of application configuration following automated infrastructure deployment
  • Utilised Azure DevOps and GitHub for code repository, and Azure Pipelines for CI/CD of deployments
  • Created deployment pipelines to include branching and code review approval processes
  • Developed re-usable Terraform environments and value add services for Microsoft Azure

Senior Cloud Solutions Architect (Contract)

Hentsu

Apr 2017 - Sep 2020 · London, United Kingdom

Managed and coordinated the migration of hedge funds from private to public cloud, working from both the UK and USA.

  • Managed and coordinated the migration of existing hedge funds from private to public cloud, ensuring successful delivery in line with aggressive timelines
  • Provisioned public cloud resources with a DevOps approach - Infrastructure as Code with Terraform, BitBucket as Git repository, deployed through Bamboo CI pipelines
  • Provided leadership and direction to a growing team (from 1 to 5) responsible for managing escalations, delivering solutions, overseeing presales, and handling client engagement
  • Oversaw the end-to-end project lifecycle including planning sessions, Sprint stand-ups, Confluence documentation, resource management, and client onboarding
  • Conducted pre-sales reviews of corporate cloud engagements whilst managing client onboarding through proposals valued up to GBP 250k

Showing 4 of 9 roles

Selected work

Projects

Enterprise migrations, identity architecture, and infrastructure-as-code delivery. Select a project to expand.

Raised the average Microsoft Secure Score across Soteria365's insurance-sector managed clients from 40% to 90%, advancing them towards CIS and ISO 27001 and standardising onboarding for new clients. Delivered as a security hardening programme: reviewed recommendations and implemented standardised device policies through Microsoft Intune using Endpoint Security Baselines, Device Configuration Profiles, and Proactive Remediations - in practice, hardening every managed device to one consistent standard and automatically correcting drift - alongside changes in Microsoft Entra and Microsoft Defender for Office 365. Worked with stakeholders to pilot and roll out changes with minimal disruption, and deployed configurations centrally through Inforcer, a platform for managing settings consistently across many client tenants, to prevent drift.

Eliminated a recurring cause of outages for Soteria365 by monitoring 1,100 secrets, certificates, and accounts approaching expiry across managed client environments, giving advance warning before lapsed credentials could cause downtime. Built an internal web application with one dashboard covering identities and devices across Microsoft Entra and Microsoft Intune, integrated with ServiceNow ITSM to raise incidents through escalating 30, 14, 7, and 1-day notifications alongside email alerts, and produced branded reports for executives and account managers. Hosted on Azure Container Apps, scaling to zero outside the daily scan and notification window to keep hosting below $10 per month, and developed with Claude Code.

Eliminated around $1,500 per year in DigiCert licence costs (roughly $300 per certificate) and removed expiry-related outages by automating the issuance and renewal of Let's Encrypt certificates for Soteria365's external-facing hosted services. Built an internal web application that verifies domains via DNS challenges against an Azure Public DNS Zone delegated from Cloudflare, then stores the issued certificates in Azure Key Vaults for the services to consume. Ran the solution on Azure Container Apps, scaling on a schedule to keep hosting below $10 per month, and developed it with Claude Code as a self-initiated project. Initially managing 5 certificates, it also cut 1-2 hours of manual renewal effort per certificate each cycle.

Gave an 80-user insurance client at Soteria365 always-on, per-application secure remote access - staff reach only the internal systems they are entitled to, with no broad network access - by replacing their existing Azure VPN with Global Secure Access - Private Access. Gained leadership sign-off for the proposed solution, worked with the client's security and infrastructure teams to define the access required by each group, and designed the Enterprise Applications and network segments scoped to Microsoft Entra security groups. Deployed 2 Global Secure Access Connector virtual machines for redundancy and migrated all 80 users to the new solution. Improved the user experience and strengthened the security posture through explicit per-application access rather than broad network-level control.

Showing 4 of 14 projects

Continuous learning

Training

Courses and structured training that keep my Azure and DevOps practice current.