Platform engineering · AI infrastructure · FinOps

Cloud platforms that stay reliable, secure and affordable, including the AI running on them.

I'm Abdihakim Said, a platform engineer with 6 years in production infrastructure on AWS and Azure, most of it in regulated healthcare. Through HumanLayer AI Ltd I run fixed-price reviews for UK engineering teams: 2 weeks, read-only access, and a written report you keep.

63%
AWS cost cut at Moorfields Private Eye Hospital
99.95%
uptime for patient-facing systems
6 yrs
production infrastructure, AWS and Azure
CKA · AWS
Kubernetes Administrator, Solutions Architect
Experience from Moorfields Private Eye Hospital Chelsea & Westminster Hospital NHS Foundation Trust Luul Solutions

Open source

Inspect how I work before we speak

Two tools that back the two reviews. Both are tested in CI, and each has a demo you can run offline.

Terminal demo: the scan finds waste and writes a plan, the plan is approved, and apply skips two actions because the resources changed after the scan

AWS FinOps: plan, approve, apply

Finds AWS waste and writes a plan. Nothing changes until a named person approves it, and every action is re-checked against live AWS first. gp2→gp3 with IOPS parity, safe snapshot clean-up, Compute Optimizer rightsizing.

PythonTerraformAWS Lambda33 tests
Terminal demo: a team budget blocks a runaway loop, a forbidden tool is denied, a refund waits for human approval, and the audit log verifies

LLM guardrails gateway

Per-team LLM budgets enforced before each call, cost per call, redaction of personal data, tool allow-lists, human approval for risky agent actions, and a tamper-evident audit log.

PythonClaude / Anthropic SDKOpenTelemetry21 tests

Selected platform work

Platforms I have designed and delivered. The code is published in anonymised form, with employer and client details removed.

Architecture: golden-AMI pipeline, infrastructure pipeline, disposable runtime and operations

Golden-image CI/CD platform on AWS

Packer golden AMIs with Trivy and Amazon Inspector scanning, Terraform (11 modules), a disposable EFS-backed Jenkins controller, and a security-gated pipeline with approval before production.

Architecture & code →
Architecture: CI scanning, ACR, ArgoCD GitOps, Key Vault secrets and SLO alerting on AKS

GitOps & DevSecOps on Azure AKS

Layered Terraform, build-once images promoted by Git commit, ArgoCD, Key Vault secrets via CSI, a Trivy image gate with SBOMs, and SLO alerting.

Architecture & code →
Architecture: the LLM drafts an IAM policy, a gate validates it, and permission boundaries cap it

AI-assisted IAM with guardrails

Amazon Bedrock drafts least-privilege IAM policies from plain-English requests; permission boundaries cap what any generated policy can grant, with MFA enforced.

Architecture & code →
AWS serverless architecture with Azure, OpenAI and Google AI integrations

Serverless multi-cloud AI integration

AWS Lambda services orchestrating Azure AI Speech, OpenAI and Google Vision, with Cognito JWT authentication on the API and Terraform-managed infrastructure.

Architecture & code →

Work with HumanLayer AI

Start with a fixed-price review

Clear scope, a written report you keep, and read-only access only. I never change anything in your accounts during a review. If you want the fixes built, an Implementation Sprint follows. It's optional and has its own fixed price.

AWS Cost & Reliability Review

£2,950Fixed · 2 weeks

For teams spending £5k–£100k a month on AWS who suspect waste, or who have had outages they shouldn't have.

  • Cost breakdown by service, team and environment
  • Top 10 savings, ranked by effort and risk, with estimated £ impact: right-sizing, scheduling, storage, Savings Plans
  • Reliability check: single points of failure, backups nobody has restored, alerts that don't reflect user impact
  • Written report, 60-minute walkthrough with your team, and a follow-up call after 30 days

Background: cut AWS costs by 63% at Moorfields Private Eye Hospital while keeping patient-facing systems at 99.95% uptime.

Book a free 30-minute call

AI Spend & Guardrails Review

£3,450Fixed · 2 weeks

For teams using OpenAI, Anthropic, Bedrock or Azure OpenAI in production, or giving AI agents access to internal systems.

  • Where the money goes: spend per feature, team and model, and the 3–5 changes that cut it (model routing, caching, token limits)
  • What data leaves: what is sent to which provider, where it's processed and what gets logged, from a UK GDPR point of view
  • What your agents can touch: permissions of API keys, MCP servers and agent tools, and your exposure to prompt injection
  • How you'll see it: an observability plan with cost and latency per call (OpenTelemetry) and budget alerts
  • Written report, prioritised fixes, 60-minute walkthrough and a follow-up call after 30 days

Approach: LLMs can draft; deterministic controls decide. See my open-source LLM guardrails gateway.

Book a free 30-minute call
After a review

Implementation Sprint

£4,950Fixed · 2 weeks · scoped from your report

For teams who've had a review and want the top fixes built, tested and handed over, rather than just a list.

Ask about a sprint
  • AI guardrails: a human approval step for risky agent actions (Slack or Teams), least-privilege keys and tool allow-lists, per-team LLM budgets and alerts, personal-data redaction before logging, and an audit log of every decision
  • AWS cost and reliability: the top savings implemented in Terraform (right-sizing, scheduling, storage tiers), backups restored and tested, and alerts that fire on user impact
  • All changes go through your repos and your normal pull-request review, with tests, a runbook and a handover session

How I work: I fix my own findings in public. For example, an AI assistant that could delete any order, APIs with no authorizer, and a ~$600/month storage setting. Each is written up in a "Fixed" note in the README, and the code fixes have tests.

How it works

  1. Free 30-minute call. We check the review fits your situation. If it doesn't, I'll say so.
  2. Scope in writing. A one-page scope and a fixed price before any work starts.
  3. Two weeks of work. Week 1: read-only access and short interviews. Week 2: analysis and report.
  4. Walkthrough and handover. You keep the report and can act on it with or without me.
  5. Optional: Implementation Sprint. If you want the fixes built, we scope a sprint from the report. Fixed price, no obligation.

Questions

What access do you need?
A read-only role. For AWS I provide the template to create it, and you can remove it the day the review ends.
Can you implement the fixes?
Yes, through the Implementation Sprint: fixed price, scoped from your report, with changes going through your own pull-request review. There's no obligation, and you can hand the report to your own team instead.
What access does a sprint need?
Only what the agreed fixes require, scoped to named repos and environments, and removed at handover.
Will you sign an NDA?
Yes, before we look at anything.
Who do we contract with?
HumanLayer AI Ltd, a UK registered company (no. 17023325).

Experience

Six years running production infrastructure

HumanLayer AI LtdFeb 2026 – Present
London, UK

Founder & Cloud / AI Infrastructure Consultant

  • Independent consultancy delivering AWS cost and reliability reviews, AI spend and guardrails reviews, and implementation sprints for UK engineering teams
  • Open-sourced an AWS FinOps tool and an LLM guardrails gateway (see Open source, above)
Luul Solutions LtdAug 2022 – Present
London, UK

Site Reliability Engineer & Cloud AI Integration Specialist

  • Implemented an SLA/SLO/SLI framework with automated monitoring across 15+ services
  • Built a golden-image pipeline (Packer, Trivy, Amazon Inspector) and a Terraform-provisioned Jenkins platform on AWS with a disposable, EFS-backed controller and security-gated infrastructure pipelines
  • Delivered GitOps on Azure AKS: layered Terraform, build-once images promoted by Git commit, ArgoCD, Key Vault secrets via CSI, and a Trivy image gate with SBOMs
  • Ran production Kubernetes (EKS, AKS, GKE) and CI/CD with GitHub Actions and AWS CodePipeline; maintained reusable Terraform modules for AWS, Azure and GCP
  • Built AI integrations with guardrails: Amazon Bedrock drafting IAM policies within permission boundaries, and serverless services orchestrating Azure AI Speech, OpenAI and Google Vision
  • Built monitoring, logging and alerting (Prometheus, Grafana, CloudWatch, ELK) with on-call rotation and postmortems
Moorfields Private Eye HospitalFeb 2021 – Aug 2022
London, UK

Cloud Engineer & Infrastructure Specialist

  • Reduced AWS costs by 63% through right-sizing, automation and scheduling
  • Ran highly available infrastructure for patient-facing systems at 99.95% uptime
  • Built automated backup and disaster-recovery procedures, with regular testing
Chelsea & Westminster Hospital NHS Foundation TrustMar 2020 – Feb 2021 · Contract
London, UK

System Administrator & Production Support

  • Administered Windows Server, Active Directory, DNS and Group Policy for 1,000+ staff
  • Automated patching and maintenance with PowerShell; managed RDS for clinical remote access
  • Maintained SQL databases and secure SFTP transfers between hospital departments

Skills

Core technical expertise

Cloud

AWS: EC2, EKS, Lambda, DynamoDB, S3, IAM, CloudWatch, Bedrock

Azure: AKS, Key Vault, ACR, AI Speech

GCP: GKE, Vision AI

Platform engineering

IaC: Terraform, Packer, CloudFormation

Kubernetes: EKS, AKS, Helm, ArgoCD

CI/CD: GitHub Actions, Jenkins, AWS CodePipeline

Languages: Python, Bash, PowerShell, TypeScript/Node.js

DevSecOps

Scanning: Trivy, tfsec, Checkov, Semgrep, Gitleaks, SBOMs

Cloud security: IAM least privilege, permission boundaries, GuardDuty, Security Hub

Observability & SRE

Observability: OpenTelemetry, Prometheus, Grafana, CloudWatch, ELK, Jaeger

Practice: SLOs and error budgets, alerting, runbooks, postmortems

AI infrastructure & FinOps

LLM integration: OpenAI (tool calling), Amazon Bedrock, Azure AI

AI guardrails: least-privilege and ownership checks for agent tools, deterministic checks on model output

Cloud cost: right-sizing, scheduling, cost automation

AWS Certified Solutions Architect – Associate AWS
Certified Kubernetes Administrator (CKA) CNCF / Linux Foundation
BSc Computer Science University of Greenwich

Contact

Have a platform, security or cost problem?

Send a short note and I'll reply within two working days. The first call is free, and if a review isn't the right fit, I'll say so.