JPButler Consulting Ltd Cloud & Security Architecture Get in touch

Independent cloud & security architecture · United Kingdom

Architecture for environments that can't afford to get it wrong.

I'm John Butler. Twenty years in Microsoft infrastructure, the last decade designing Azure platforms, identity models and security operations for defence, central government and regulated enterprise. I produce the architecture — and stay as design authority until it's built.

Enterprise-scale landing zone management groups
Tenant rootpolicy inherited downward
Platform
IdentityEntra ID · PIM · access reviews
ManagementLog Analytics · Sentinel
ConnectivityvWAN · Private DNS
Landing zones
CorpAzure Policy guardrails
OnlineDefender for Cloud
Sandboxno route to production
Decommissioneddeny by default
PrincipleGuardrails apply at scope. Delivery teams inherit them — they don't reimplement them.

Cloud Adoption Framework, as I build it

20+Years in Microsoft estates
SC-100Cybersecurity Architect Expert
MOD · HMRCDefence & central government
CAF & TOGAFFrameworks I design in

Services

Six things I'm brought in to do.

Usually as an interim architect inside an existing programme, sometimes as a fixed-scope piece of design work. Either way the output is architecture that survives peer review and the assurance process behind it.

Architecture

Cloud & security architecture

High and low level design, enterprise roadmaps and design authority through delivery. I work inside TOGAF and SIAM where they're already in use, and produce documents that hold up when they're challenged.

  • HLD / LLD
  • Strategic roadmaps
  • Design authority
  • TOGAF
Platform

Azure landing zones

Cloud Adoption Framework landing zones built to actually be used: management group hierarchy, Azure Policy guardrails applied at scope, private DNS integration throughout, and delivery by pipeline rather than by portal.

  • CAF
  • Enterprise-scale
  • Azure Policy
  • Terraform
  • Azure DevOps
Identity

Identity & access management

Entra ID maturity roadmaps and designs — privileged identity management, conditional access, access reviews, attribute-based access packages and Intune. Identity is where most cloud security programmes either hold together or come apart.

  • Entra ID
  • PIM
  • Conditional access
  • ABAC access packages
  • Intune
Operations

Security operations & SOC

Standing up a security operations capability from nothing, or fixing one that isn't producing signal. Sentinel and Defender for Cloud design, logging and monitoring architecture, and the operating model that has to exist around them.

  • Microsoft Sentinel
  • Defender for Cloud
  • Defender for Endpoint
  • Posture management
High assurance

Secure by Design patterns

Architecture for environments where the assurance case matters as much as the build: NCSC-aligned patterns for cross domain solutions, secure ingest and non-attribution connectivity, written to withstand formal security review.

  • NCSC guidance
  • Cross domain solutions
  • Secure ingest
  • Non-attribution
Governance

Compliance & FinOps

Policy as code, ISO 27001 and PCI DSS alignment, the NCSC Blueprint for Microsoft 365, and FinOps assessment with an evergreen procedure that keeps working once I've left.

  • ISO 27001
  • PCI DSS
  • NCSC Blueprint
  • Policy as code
  • FinOps

Selected engagements

Where the work has been.

2024 — Defence

Ministry of Defence

Cloud & Security Architect (interim)

Architecture and engineering for a cloud and on-premises data analytics platform. Leading identity and connectivity, an Entra ID maturity roadmap covering ABAC access packages, PIM and Intune, NCSC-aligned cross domain and secure ingest patterns, and a two-year strategic roadmap framed in TOGAF. Security guardrails automated across PaaS and DNS through Azure Policy and landing zone pipelines, with architectural oversight across several product teams and the SOC.

2023–24 Defence

Microsoft — MOD programme

Architect / Senior Security Consultant (interim)

Architecture and senior security consulting into Microsoft Consulting Services. Entra ID design covering PIM, access reviews, conditional access and risk-based sign-in; Defender for Cloud and Sentinel monitoring and logging delivery; secure Teams and Exchange Online design; and onboarding and leading the SOC setup. Evaluated, tested and configured the NCSC Blueprint for Microsoft 365.

2024–25 Nonprofit

The Big Life Group

Enterprise Security Architect

A two-year security strategy and roadmap, a Cloud Adoption Framework-aligned Azure platform design, Defender and Sentinel delivery, Azure Virtual Desktop design, and the policies and procedures underpinning ISO 27001 compliance.

2020–23 Central government

Microsoft — HMRC programme

Architect / Senior Security Consultant (interim)

Led the Cloud Adoption Framework and enterprise landing zone workstreams, including an automated vending model delivered with a full working proof of concept, and the Defender for Cloud and Qualys workstreams across a large Azure estate. Workshops, design, documentation and operational handover for Azure VMware Services, backup and recovery, and agile governance run through Azure DevOps.

2019–20 Legal

DLA Piper

Cloud Security Architect

Subject matter expert for Azure, Office 365 and cloud security. Defined the Azure scaffold and CAF governance against internal policy and NCSC guidance, introduced policy as code using Azure Policy with Terraform and JSON, and produced the detailed design for a secure SIEM platform including Key Vault, peered networks, Azure Firewall and DDoS Standard.

2019 Healthcare

NHS England

Azure & Lead IDAM Architect

Architecture and delivery of a scalable multi-tenant Azure identity solution in a greenfield estate — PIM, conditional access, identity protection, access reviews and MFA — with a DevOps strategy built on infrastructure as code and CI/CD, and SAML single sign-on integration with ServiceNow.

2023 Energy

newcleo

Lead / Enterprise Architect

End-to-end cloud transformation strategy and roadmap for a nuclear energy business, including vision statement, defining principles, critical path scoping and pre-sales statements of work, alongside proofs of concept for Defender for Cloud, Azure Arc and Azure OpenAI.

Earlier: Vodafone (Azure CSP resell architecture, PCI DSS and GDPR aligned) · Parole Board, MOJ (hybrid Azure architecture and delivery) · Legal Ombudsman (Azure migration technical lead) · Daisy Group · Jet2 (PCI DSS resilient estate) · KCOM Group.

How I work

Opinionated, and quick about it.

01 / ENGAGEMENT

Design authority, not drive-by

I stay with a design through delivery, take the escalations it generates, and hand over an operating model rather than a document and a wave goodbye.

02 / FRAMEWORKS

Frameworks where they earn it

CAF, TOGAF, SIAM and NCSC guidance are worth their weight when they shape a decision and expensive when they become ceremony. I use the parts that change the outcome.

03 / OUTPUT

Two readers per document

Every design carries something the board can act on, and enough detail that the engineer building it doesn't have to guess what was meant.

Credentials

Certified across the Microsoft cloud stack.

SC-100Cybersecurity Architect Expert
AZ-303 / AZ-304Azure Solutions Architect Expert
AZ-400DevOps Engineer Expert
AZ-500Azure Security Engineer Associate
AZ-700Azure Network Engineer Associate
MS-500Microsoft 365 Security Administrator
AZ-100 / AZ-101Azure Administrator Associate
MCSECloud Platform & Infrastructure
MCSEProductivity
VCP-DCVVMware Certified Professional
HNCBusiness Information Technology

Alongside legacy Microsoft certification going back to Windows 2000 — MCSE 2012, MCITP Enterprise and Server Administrator, MCTS, MCSA and MCP — plus SAP NetWeaver.

Verify on Microsoft Learn

About

John Butler

Twenty years in Microsoft infrastructure, and the last decade of it designing cloud and security platforms for organisations where a bad architecture has real consequences.

Defence, HMRC, NHS England, the Ministry of Justice, a nuclear energy business, an international airline's PCI DSS estate. Different sectors, same shape of problem: there's a strategy at one end and a delivery team at the other, and someone has to turn the first into work the second can pick up — then stay to defend the decisions when they meet the assurance process.

That middle part is the work I'm interested in. I'm comfortable in a customer workshop and comfortable in the pipeline, which is usually why I get called.

I also look after IT for Band of Rescuers, a charity, on a voluntary basis — Microsoft nonprofit grants and licensing, tenant administration, and Secure Score remediation. Considerably smaller estate. Same principles.

  • SpecialismsAzure architecture, Entra ID, Defender & Sentinel, Cloud Adoption Framework
  • SectorsDefence, central government, legal, telecoms, energy, nonprofit
  • EngagementsInterim architect, design authority, fixed-scope design and assessment
  • BasedYork — working UK-wide, remote with on-site where it's warranted

Get in touch

Tell me what's stuck.

Whether that's a landing zone nobody trusts, an identity model that's grown past its design, a SOC producing noise instead of signal, or a roadmap that needs to survive contact with an assurance process. A short call is usually enough to work out whether I'm the right person.

Email an enquiry