Skip to content
BigTree108

Cloud, DevOps and security

Cloud, DevOps and security services: cloud architecture and consulting, AWS and Google Cloud engineering, Kubernetes, DevOps and CI/CD, site reliability and platform engineering, Terraform and infrastructure as code, FinOps, cybersecurity and penetration testing, cloud security, SOC and compliance, IT infrastructure, Linux administration and network engineering. Dedicated engineers for your team, projects delivered end to end, and take-overs of estates other teams built.

Cloud, DevOps and security services

Each page covers the work we take on, the ways to work with us and the questions clients ask first. Azure, the cloud we run our own company on, has a page of its own.

Covered elsewhere on the site

The same rules on every estate

One engineer in your platform team or a whole function: cloud architecture and infrastructure on AWS, Azure, Google Cloud and your own hardware, Terraform and Ansible, Kubernetes and internal developer platforms, pipelines, site reliability, on-call and observability, FinOps and cloud cost control, penetration tests, security monitoring and compliance, and the Linux servers, networks and devices an office runs on.

Everything as code: infrastructure in Terraform, pipelines in the repository, and policies and configuration under version control, so an environment can be rebuilt from Git and every change has a reviewer. Credentials are federated or held in a vault, networks deny by default, tests run in the pipeline, and a security advisory is an unconditional upgrade.

A take-over starts with a read-only review and a written list of risks, before anyone changes anything. We have inherited nine systems from other teams so far, the oldest written in 2008, and the same first step applies to a cloud account, a cluster or an office network.

How we run our own estate

Our company runs on a platform we built on .NET, Angular and Azure, under the rules on these pages: every resource in Terraform, GitHub Actions with federated credentials and actions pinned by hash, secrets only in Key Vault, deny-by-default firewalls, personal and financial columns Always Encrypted, CodeQL on every push and drift detection on a schedule. Beyond the cloud, our laptops are checked by an agent we wrote in Rust against our security baseline, on Windows, macOS and Ubuntu, with checks mapped to ISO 27001, CIS, Cyber Essentials, Essential Eight and SOC 2. Read the case study.

Questions about cloud, DevOps and security

Which cloud, DevOps and security services do you provide?

Cloud architecture and consulting; AWS, Azure and Google Cloud engineering; Kubernetes; DevOps and CI/CD; site reliability engineering with service-level objectives, observability and on-call; platform engineering with Backstage portals and golden paths; Terraform, OpenTofu and Ansible; FinOps and cloud cost optimisation; cybersecurity and penetration testing, cloud security, SOC and compliance; and IT infrastructure, Linux administration and network engineering.

Which clouds do you work on?

AWS, Azure and Google Cloud, Kubernetes on any of them or on your own hardware, and hybrid estates that mix cloud services with servers in an office or a data centre, with the same infrastructure-as-code and pipeline rules on each. Azure has a page of its own.

Which industries do your cloud, DevOps and security engineers work in?

Mostly fintech and banking, cloud, hosting and telecom companies, e-commerce and retail, SaaS products, healthcare, AI and data products, cybersecurity companies, and industrial and energy firms. Each page describes what the work looks like in those industries.

Do you need administrator access to our cloud accounts?

Not to start. A review begins with read-only access through a role you create and can revoke. Changes arrive as pull requests your team approves, and any write access is limited to the environments and the period the work needs, then removed.

How is the work contracted and billed?

One agreement with BIG TREE 108 LLC and one invoice a month. Time is logged in our own portal through the month, and the same figures produce the invoice.

Who owns the infrastructure code and pipelines?

You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.

Need cloud, DevOps or security engineers?

Tell us what runs where and what needs to change. You get an answer within one business day: a plan for the work or candidate profiles.