Engineering · by the day

Senior security & cloud engineering, by the day.

I spent over two decades building and securing digital infrastructure for some of Europe's most complex organisations. I am good at it. I take on hands-on work to unblock production and ship securely, for B2B SaaS teams of roughly 20-150 with no in-house GRC, a stalled enterprise deal, or an AI feature heading to production.

What I do

Where senior engineering actually moves the needle.

This is a small, deliberate set of things I do every day. It is not a menu of everything. Each one is hands-on build and review. I do not advise from the sidelines.

01

Secure cloud-native platforms

Production platforms designed and built with security-by-design from the first commit, not bolted on before an audit.

02

Kubernetes

Cluster architecture, workload hardening and the operational guardrails that keep a platform safe to run and safe to change.

03

Identity & access

OAuth2 / OpenID Connect, API gateways and access models that hold up when an enterprise buyer's security team starts asking.

04

Auditable CI/CD

Controlled, auditable delivery pipelines, who shipped what, when, and the evidence trail to prove it.

05

Security-by-design

Threat-aware decisions baked into architecture and code review, so the secure path is the default path.

Track record

Twenty years, hands on the keyboard.

I have worked across public sector, banking, transport, aviation, retail, energy and publishing. These are engineering and architecture roles, named as they appear on my CV.

  1. 2019-present
    CJIB
    Dutch Ministry of Justice, central judicial collection agency
    Cloud engineer / architect & DevOps · security-by-design
  2. 2019
    Nederlandse Spoorwegen (NS)
    National rail operator
    DevOps · CI/CD
  3. 2013-2019
    Ahold Delhaize
    Retail group
    Architect / DevOps
  4. 2013
    ING
    Banking
    Software developer
  5. 2010-2013
    KLM
    Aviation
    DevOps / architect · lead Java
  6. 2007-2010
    Essent, Enexis, SDU and others
    Energy, utilities and publishing
    Solution architect / senior Java developer, freelance
How I work

Clear terms, no open-ended retainer.

I work one way, and I state it up front. The terms are the same on day one as on day thirty.

Day rate
€1,000/ day
ex VAT
  • One engagement at a time

    You get my full attention. I do not split it across three other clients.

  • Fixed-scope day blocks

    We agree the scope and the number of days up front, so you know the cost before I start.

  • No open-ended retainer

    I do not leave a meter running in the background. When the agreed block is done, it is done.

Where I hand off

What I am not, and who to bring in.

I am an engineer. I will get you ready, and I am honest about where my work stops. For the sign-off that needs an accredited specialist, I tell you who to call.

I am not an auditor
I get you audit-ready and assemble the evidence; an accredited certification body runs the ISO 27001 / SOC 2 audit and issues the certificate.
I am not a lawyer
I implement the technical controls; a qualified lawyer or DPO gives the legal sign-off on GDPR, NIS2 and the EU AI Act.
I am not a pentester
I harden the platform and fix what gets found; an independent firm runs the penetration test and writes the report.

Need a senior pair of hands on production?

Start with a short call. If I am not the right person, I will say so, and point you to someone who is. I would like to talk.

Contact

Book a call

Tell me what you are working on. I will tell you plainly whether I can help, and how.

Calendar not loading? Email contact@sirrapa.com