Cloud, DevOps and security
Cloud, DevOps and security services: cloud architecture and consulting, AWS and Google Cloud engineering, Kubernetes, DevOps and CI/CD, site reliability and platform engineering, Terraform and infrastructure as code, FinOps, cybersecurity and penetration testing, cloud security, SOC and compliance, IT infrastructure, Linux administration and network engineering. Dedicated engineers for your team, projects delivered end to end, and take-overs of estates other teams built.
Cloud, DevOps and security services
Each page covers the work we take on, the ways to work with us and the questions clients ask first. Azure, the cloud we run our own company on, has a page of its own.
AWS development
AWS development services: EKS and ECS containers, serverless, landing zones, migrations, databases, data platforms, Bedrock generative AI, security and cost optimisation, with dedicated AWS engineers or project delivery.
Google Cloud development
Google Cloud development services: Cloud Run and GKE, BigQuery, Firebase backends, Cloud SQL and AlloyDB, Gemini on Agent Platform, security and migrations, with dedicated Google Cloud engineers or project delivery.
Kubernetes consulting
Kubernetes consulting and development: clusters on EKS, AKS, GKE and on premises, Helm, GitOps with Argo CD or Flux, cluster security, upgrades and GPU workloads, with dedicated Kubernetes engineers or project delivery.
DevOps and CI/CD
DevOps and CI/CD services: pipelines, Terraform infrastructure as code, observability, SRE and on-call, DevSecOps, platform engineering and FinOps, with dedicated DevOps and SRE engineers or ongoing DevOps work.
Cybersecurity and pentesting
Cybersecurity and penetration testing services: web, mobile, API, network and cloud pentests, secure code review, SOC and incident response, ISO 27001 and SOC 2, with dedicated security engineers or defined projects.
IT infrastructure
IT infrastructure and system administration services: Windows and Linux servers, networks, Microsoft 365 and Entra ID, virtualisation, backups and telecom, with dedicated system administrators or ongoing support.
Site reliability engineering
Site reliability engineering services: SLOs, OpenTelemetry observability, on-call and incident management, load testing, disaster recovery and chaos engineering, with dedicated SRE engineers or project delivery.
Platform engineering
Platform engineering services: internal developer platforms, Backstage portals, golden paths and templates, self-service infrastructure and Kubernetes platforms, with dedicated platform engineers or project delivery.
Cloud architecture
Cloud architecture and consulting services: designs for AWS, Azure and Google Cloud, migration plans, landing zones, Well-Architected reviews, resilience and cost, with dedicated cloud architects or project delivery.
FinOps
FinOps and cloud cost optimisation services: cost allocation, rightsizing, savings plans and reservations, Kubernetes, data and AI costs, budgets and anomaly alerts, with dedicated FinOps engineers or project delivery.
Terraform and IaC
Terraform and infrastructure as code services: Terraform and OpenTofu modules, imports, plan and apply pipelines, drift control, policy as code and Ansible, with dedicated Terraform engineers or project delivery.
Linux administration
Linux administration services: Ubuntu, Debian, RHEL, Rocky Linux and AlmaLinux servers set up, patched, hardened, monitored and backed up, and end-of-life upgrades, with dedicated Linux administrators or ongoing support.
Network engineering
Network engineering services: routing and switching, firewalls, SD-WAN and zero-trust access, cloud networking, Wi-Fi and automation on Cisco, Juniper and Fortinet, with dedicated network engineers or project delivery.
Cloud security
Cloud security services: CSPM and CNAPP, IAM reviews, Kubernetes security, network and data protection and cloud compliance on AWS, Azure and Google Cloud, with dedicated cloud security engineers or project delivery.
SOC and security monitoring
SOC as a service and security monitoring: managed SOC, SIEM deployment, log onboarding, detection engineering, EDR, threat hunting and incident response retainers, with dedicated SOC analysts or ongoing monitoring.
Security compliance
Security compliance and audit readiness: ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, NIS2 and DORA controls, gap assessments and audit evidence, with dedicated compliance engineers or a readiness project.
Covered elsewhere on the site
Cloud and DevOps
Azure Functions, Azure SQL with Always Encrypted, Terraform for every resource and GitHub Actions pipelines, with drift detection and cost control built in from the start.
Managed application support
Second and third line support of live systems inside your SLA and your ticket queue: triage, fixes, releases, patching and on-call cover, by engineers who also build, on European or North American hours.
Go development
Go development services: Golang microservices and APIs, fintech and SaaS back ends, Kubernetes operators, event pipelines and network and security software, with dedicated Go developers or project delivery.
Rust development
Rust development services: backend services and APIs, blockchain and Web3, systems and infrastructure software, security tooling, embedded firmware and WebAssembly, with dedicated Rust developers or project delivery.
The same rules on every estate
One engineer in your platform team or a whole function: cloud architecture and infrastructure on AWS, Azure, Google Cloud and your own hardware, Terraform and Ansible, Kubernetes and internal developer platforms, pipelines, site reliability, on-call and observability, FinOps and cloud cost control, penetration tests, security monitoring and compliance, and the Linux servers, networks and devices an office runs on.
Everything as code: infrastructure in Terraform, pipelines in the repository, and policies and configuration under version control, so an environment can be rebuilt from Git and every change has a reviewer. Credentials are federated or held in a vault, networks deny by default, tests run in the pipeline, and a security advisory is an unconditional upgrade.
A take-over starts with a read-only review and a written list of risks, before anyone changes anything. We have inherited nine systems from other teams so far, the oldest written in 2008, and the same first step applies to a cloud account, a cluster or an office network.
How we run our own estate
Our company runs on a platform we built on .NET, Angular and Azure, under the rules on these pages: every resource in Terraform, GitHub Actions with federated credentials and actions pinned by hash, secrets only in Key Vault, deny-by-default firewalls, personal and financial columns Always Encrypted, CodeQL on every push and drift detection on a schedule. Beyond the cloud, our laptops are checked by an agent we wrote in Rust against our security baseline, on Windows, macOS and Ubuntu, with checks mapped to ISO 27001, CIS, Cyber Essentials, Essential Eight and SOC 2. Read the case study.
Questions about cloud, DevOps and security
Which cloud, DevOps and security services do you provide?
Cloud architecture and consulting; AWS, Azure and Google Cloud engineering; Kubernetes; DevOps and CI/CD; site reliability engineering with service-level objectives, observability and on-call; platform engineering with Backstage portals and golden paths; Terraform, OpenTofu and Ansible; FinOps and cloud cost optimisation; cybersecurity and penetration testing, cloud security, SOC and compliance; and IT infrastructure, Linux administration and network engineering.
Which clouds do you work on?
AWS, Azure and Google Cloud, Kubernetes on any of them or on your own hardware, and hybrid estates that mix cloud services with servers in an office or a data centre, with the same infrastructure-as-code and pipeline rules on each. Azure has a page of its own.
Which industries do your cloud, DevOps and security engineers work in?
Mostly fintech and banking, cloud, hosting and telecom companies, e-commerce and retail, SaaS products, healthcare, AI and data products, cybersecurity companies, and industrial and energy firms. Each page describes what the work looks like in those industries.
Do you need administrator access to our cloud accounts?
Not to start. A review begins with read-only access through a role you create and can revoke. Changes arrive as pull requests your team approves, and any write access is limited to the environments and the period the work needs, then removed.
How is the work contracted and billed?
One agreement with BIG TREE 108 LLC and one invoice a month. Time is logged in our own portal through the month, and the same figures produce the invoice.
Who owns the infrastructure code and pipelines?
You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.
Need cloud, DevOps or security engineers?
Tell us what runs where and what needs to change. You get an answer within one business day: a plan for the work or candidate profiles.