Scott Drinkwater

I ran incident command at Meta’s TOC, managing critical severity events across EMEA hyperscale data centres. Now I run production infrastructure for international clients from a sailboat near Barcelona. Looking for roles where infrastructure, security, AI, and marine systems converge — including superyacht IT/AV and maritime technology consulting.

18 years building and securing systems — from hyperscale data centres and critical national infrastructure at LSEG, through to cloud platforms, Docker/Kubernetes workloads, and AI infrastructure. I also bring deep marine systems expertise: Victron energy systems, onboard networking, satellite communications, and marine electronics. I live on a sailboat, so I understand what “remote” actually means. I’m autistic, which for operational work is a genuine advantage — I spot anomalies in complex data that most people miss. Based between London and Barcelona, available for permanent, contract, or rotation-based roles (remote UK/EU, superyacht rotations).

18 years designing and deploying secure network architectures across enterprise, data centre, and maritime environments. Cisco switching, OSPF routing, SD-WAN multi-site bonding, Cloudflare Zero Trust, and structured cabling including fibre.

Cisco switchingPepwave SD-WAN/SpeedFusionOmadapfSenseWatchGuardDrayTekVPNs (IPsec, OpenVPN, WireGuard)Secure tunnelsSD-WAN platformsCloudflare Zero TrustVLANsOSPFStructured cablingFibre

Multi-cloud architecture across AWS, Azure, GCP, and bare-metal providers. 18 servers running production across Hetzner, DigitalOcean, and InMotion. Container orchestration with Docker and Kubernetes, self-hosted Coolify for PaaS, and CI/CD pipeline design for production deployments.

AWSAzureGCPDigitalOceanHetznerVercelCloudflare (WAF, Tunnel, DNS)Docker (Compose, networking)K8s/K9sPodmanOrbstackTerraformCI/CD (GitHub Actions, GitLab CI, Jenkins)Rancher

Zero Trust architecture design, enterprise endpoint protection (ESET training lead, Bitdefender, Defender), SIEM deployment (Splunk, ELK), compliance frameworks (SOC 2, PCI DSS, GDPR), penetration testing, and self-hosted security recon (reNgine, Kali Linux).

ESET Business ProtectionBitdefenderMicrosoft DefenderQualysSplunkELKPenetration testingThreat modellingSOC 2PCI DSSGDPRZero Trust architectureMFA & Identity FederationSSO / SAML / OIDC

Meta TOC — managed SEVs (Severity Events), coordinated cross-team wake-up trees, routed to DBA/networking/power teams. On-call operational leadership across EMEA, managing GSOC escalation and critical outage response across hyperscale infrastructure.

SEV managementTOC operationsCross-team coordinationWake-up treesGSOC escalationRoot cause analysisIncident responseOn-call rotationRunbook authoring

Full IT lifecycle management from procurement to decommissioning. MDM with Intune/Autopilot, service desk platforms (ServiceNow, Zendesk, Freshdesk), backup and disaster recovery with Veeam and Acronis.

ManageEngine SuiteMicrosoft Intune/AutopilotSolarWinds RMMFreshdeskServiceNowZendeskosTicketVeeamAcronisAWS Backup

Hypervisor management across VMware vSphere, Hyper-V, Proxmox VE, and Citrix. Sizing, deploying, and maintaining virtualised infrastructure for enterprise workloads and homelab environments alike.

VMware vSphereHyper-VProxmox VECitrix HypervisorOracle VirtualBox

Production code in Python, TypeScript, Rust, PowerShell, Bash, and Go. Full-stack applications with React/Next.js, Node.js, and SQL. AI/ML development with Hugging Face, LangChain, and custom agent frameworks. Infrastructure automation with Terraform and Puppet. Linux and Windows Server administration.

PowerShellPythonTypeScript / JavaScriptRustBashTerraform / HCLPuppetPHPGoSwiftNode.jsReact / Next.jsSQLLinux (Ubuntu/Debian/CentOS)Windows Server (AD, GPO, DNS, DHCP)

Core speciality — 10+ years designing and delivering PACS/ACS for hyperscale data centres and critical infrastructure. Gallagher, CCURE 9000, Genetec, Avigilon, and Milestone VMS. End-to-end commissioning of Axis, Bosch, and Commend hardware.

GallagherCCURE 9000GenetecAvigilonMilestoneHikvisionAxisBoschCommendPACS/ACS design

Full-time liveaboard sailor with thousands of offshore miles. Designed and installed complete Victron energy systems (solar, MPPT, lithium, inverters). Marine electronics and protocols: NMEA 2000, SeaTalk, Signal K. Built Raspberry Pi marine navigation system with sensor networks. Engine maintenance (diesel). RYA Day Skipper, VHF license, ICC certified.

Victron Energy systemsSolar / MPPT / lithium / invertersDC electrical (12V/24V)NMEA 2000 / SeaTalkSignal KMarine networkingSatellite commsRaspberry Pi marine navDiesel engine maintenanceRYA Day SkipperVHF LicenseICCOff-grid systems designOnboard WiFi/LAN

RIBA Stages 2–5 delivery of ICT and security infrastructure for data centres and commercial developments. CAD/BIM review, design specifications, vendor coordination, commissioning, and handover documentation.

RIBA Stages 2–5CAD/BIM reviewDesign specsCommissioningVendor coordinationConfluence/SharePoint/IT Glue

Built a crypto trading agent in Rust that orchestrates three local LLMs. Experienced with MCP (Model Context Protocol), CrewAI, LangGraph, and function calling. I design agent systems for production — not the kind that work in a demo and fall over at scale.

Function calling / tool useAgent frameworks (CrewAI, LangGraph)MCP (Model Context Protocol)Multi-agent orchestrationAutonomous agent designTool-augmented LLMs

Production RAG pipelines — architecture, chunking strategies, retrieval optimisation. Vector databases (ChromaDB, Qdrant, pgvector), embedding model selection, Graph RAG with knowledge graphs. Have built and run these end-to-end, so I know where they break.

RAG architecture designChromaDBQdrantpgvectorEmbedding models & selectionGraph RAG & knowledge graphsChunking strategiesHybrid search (vector + keyword)Re-ranking pipelines

Model quantisation (GGUF, GPTQ, AWQ), inference optimisation, local deployment of open-weight models. Run Ollama and LM Studio daily. Self-hosted inference on Mac and Kubernetes. I know when to quantise and when a smaller model is the better answer.

Model quantisation (GGUF, GPTQ, AWQ)Inference optimisationOllama / LM StudioLocalAI self-hosted inferenceLoRA / QLoRA fine-tuningModel evaluation & benchmarkingPrompt cachingBatch inference

Comfortable with DeepSeek, Llama, Mistral, and Qwen model families. Proficient on Hugging Face — pipelines, inference endpoints, model hubs. I follow the open-weight model space closely and have a soft spot for Liquid AI’s smaller-fewer-parameters approach.

DeepSeek familyLlama familyMistral familyQwen familyHugging Face platformHF pipelines & inferenceLocal / open-weight model ecosystemLiquid AI

GPU cloud platforms for training and inference. Understanding of data sovereignty and regulated workloads from Meta SEV experience. Can design the infrastructure layer for AI deployments — compute, networking, storage, and security — in environments where data locality matters.

Cloud GPU platformsRunPod / Lambda Labs / Vast.aiApple Silicon inference (MLX)CUDA-aware schedulingSovereign AI infrastructureGPU cost optimisation

AI-assisted coding workflows with Cursor, Copilot, and Kilo Code. LLM-powered content generation and RSS automation pipelines. Built AI applications for WordPress, Chrome extensions, and SaaS platforms. Multilingual AI work including cross-lingual embeddings and model routing by language.

AI-assisted coding workflowsLLM API integration (OpenAI, Claude, Gemini)AI content generation / RSS automationComfyUI / Stable DiffusionMultilingual RAGCross-lingual embeddingsModel routing by languagemacOS UI automationIoT / mesh networking (Meshtastic)

The question I ask most: does this actually need AI? Cost optimisation mindset from running real infrastructure. Know when an API call is enough, when self-hosting makes sense, when fine-tuning pays off, and when you should just write a script. Active in AI tooling communities — early adopter, not a hype chaser.

AI cost optimisationAI landscape & trend awarenessMake vs buy decision frameworksAI readiness assessmentPrompt engineeringCode generation models

Full email deliverability stack for 10+ client domains: DMARC, DKIM, SPF, SSL certificate lifecycle management, and spam/malware protection. Multi-TLD DNS management, CDN and QUIC configuration. Web server management across OpenLiteSpeed, Apache, and Nginx with cPanel administration.

DMARCDKIMSPFSSL certificate managementSpam/malware protectionEmail deliverabilityMulti-TLD DNSCDN / QUICOpenLiteSpeedApacheNginxcPanel

VoIP/SIP deployment with 3CX and Teams Calling. Linux system administration (Ubuntu, Debian, CentOS). WordPress/WP-CLI site management, structured cabling, fibre termination, and UPS/power monitoring.

VoIP/SIP (3CX, Teams Calling)PaperCutUPS/power monitoringStructured cabling & fibreLinux adminRaspberry Pi/IoTWordPress / WP-CLIMDX / documentation systems

Experience

Nov 2024 – Present

Infrastructure & Security Engineer — Consultant

TechSquad London

  • Advising on secure SD-WAN rollout, cloud migration strategy, and physical security design
  • Building SaaS products and developer tooling with Node.js, Next.js, and Docker
  • Cloudflare Zero Trust deployments and Kubernetes cluster architecture
Oct 2023 – Present

Senior Security Engineer

Total Security Protection Ltd

  • Designed advanced IP-based CCTV systems for enterprise clients
  • Led data centre security infrastructure migration projects
  • Deployed enterprise-level security systems across multiple sites
Aug 2018 – Nov 2024

IT Manager

O-Negativ (3D Design Studio)

  • Managed all IT for a 15-seat design studio — Omada switches/WiFi, Pepwave Max Transit multi-WAN bonding, firewalls, render farm
  • Administered ESET Business Advanced Protection across endpoint security, antivirus, and threat monitoring
  • Sole IT manager owning vendor relationships, procurement, security posture, and end-user support
  • Used ManageEngine for remote desktop support, patch management, and IT asset management
Jul 2017 – Oct 2023

Technical Operations Center — Incident Commander & CCURE 9000 Administrator

Meta EMEA (via M.C. Dean)

  • Managed SEVs (Severity Events) — Meta’s critical incident classification system — from the EMEA TOC
  • Coordinated cross-team wake-up trees, routing to DBA, networking, and power teams during major incidents
  • Years of CCURE 9000 administration at Meta scale across hyperscale data centres
  • Delivered physical security systems (CCURE 9000, Genetec, intercoms) for Meta’s EMEA data centre programme
  • Reference: Gavin Singh, UK Services Manager at Meta (M.C. Dean)
2015 – 2018

Security Systems Engineer

London Stock Exchange Group

  • Physical and electronic security for critical national infrastructure
  • Access control system design, CCTV architecture, and intercom integration
  • Commend, Bosch, Axis deployment across LSE campus
Apr 2014 – May 2016

Senior Tech Support & Training Lead

Gallagher Security

  • Ran training programmes for Gallagher access control systems across the UK market
  • Key account manager for top UK universities, financial district sites, and high-profile London venues
  • Security and CCTV project management lead for new developments and existing site upgrades
  • Lead security advisor providing product presentations to consultants and end clients
2008 – 2015

Network & Security Engineer

Various — New Zealand & UK

  • Cisco switching and routing, VLAN design, OSPF
  • Firewall deployment (pfSense, WatchGuard, DrayTek)
  • Structured cabling, fibre, data centre build-out — moved from NZ to London
  • Transitioned from pure networking to security engineering

Work I’ve done

SPANC Portal wastewater inspection dashboard

SPANC Portal — Municipal SaaS Platform

Production SaaS for French municipalities managing wastewater inspections. Offline-first PWA with React 19, TypeScript, Supabase, FastAPI PDF generation, i18n (FR/EN), and Recharts dashboards. Built solo with AI-assisted development, deployed with CI/CD.

React 19TypeScriptSupabaseFastAPIPWA
View project →
ContentPilot AI WordPress plugin architecture

ContentPilot — AI WordPress Plugin

Advanced WordPress plugin for AI-driven content generation with multi-LLM routing (OpenAI, Claude, OpenRouter), SEO optimisation via RankMath, RSS filtering, scheduled publishing, and fallback handling. Production-deployed.

WordPressOpenAIClaudeRankMathPHP
github.com/scottnzuk/ContentPilot →
Commodore Yachting sailing school website

Commodore Yachting — Hosting & DevOps

Full IT management for a 25+ year RYA sailing school in Gosport Marina. Dockerised WordPress hosting (OpenLiteSpeed + MariaDB), SSL management, SEO optimisation, content strategy, and Tripadvisor/Google review management.

DockerWordPressOpenLiteSpeedSEODevOps
View project →
Natural NZ Pet Food WooCommerce store

Natural NZ Pet Food — WooCommerce Store

Full IT management for a NZ-based natural pet food e-commerce store. WooCommerce/WordPress with Elementor, product catalogue, cart/checkout, customer accounts, shipping configuration, and email marketing integration.

WooCommerceWordPressElementorE-Commerce
View project →
Meta hyperscale data centre Dublin

Meta Dublin — Greenfield Data Centre Build

Key engineering contributor for Meta’s greenfield hyperscale data centre in Clonee, Dublin. Managed ICT and security infrastructure design, vendor coordination, commissioning, and integration with MEP works. All phases delivered on time and within budget.

CCURE 9000GenetecCommendICT InfrastructureData Centre
View project →
Global Switch London data centre campus

Global Switch London — Data Centre Campus

Full system migration and greenfield design for London data centre campus. End-to-end delivery including stakeholder coordination, vendor management, and commissioning. Detailed design specs, CAD/BIM drawings, and technical documentation.

CAD/BIMSecurityICTNetworkData Centre
View project →
Meta EMEA multi-site infrastructure migration

Meta EMEA — Multi-Site Infrastructure Migration

Planned and executed zero-downtime migration of critical infrastructure across 4 new EMEA data centre facilities. Designed phased migration strategy with redundant failover, maintained 100% availability during all live cutovers. Standardised approach adopted as EMEA regional template.

MigrationCCURE 9000GenetecZero DowntimeEMEA
View project →
Meta Reality Labs Cork Ireland office

Meta Cork — Reality Labs Office Fit-Out

Security and ICT infrastructure for Meta’s Reality Labs R&D office in Cork City centre (Capitol Building, Grand Parade). Access control, CCTV, and network design for hardware engineering and semiconductor R&D facility housing 90+ researchers across 30 nationalities.

Access ControlCCTVNetworkR&D LabIreland
View project →
Meta London office Brock Street Kings Cross

Meta London — Office Infrastructure (Brock Street & King’s Cross)

Physical security systems and ICT infrastructure for Meta’s London offices at 10 Brock Street, Regent’s Place and the King’s Cross campus. Access control, CCTV, and intercom deployment across 320,000 sq ft of West End office space.

Access ControlCCTVCommendLondonOffice Fit-Out
View project →
London Stock Exchange Group security infrastructure

London Stock Exchange Group — Critical National Infrastructure

Physical and electronic security for critical national infrastructure at LSEG’s London campus. Access control system design, CCTV architecture, and intercom integration. Commend, Bosch, and Axis deployment across the trading floor and campus facilities.

CNIAccess ControlCCTVCommendBosch
View project →
Tekjump independent IT consultancy The Shard UCL

Tekjump LTD — Independent IT & Systems Consultancy

Founded and operated independent IT consultancy delivering enterprise infrastructure architecture, system integration, and technical advisory. Clients included The Shard, King’s College London, UCL, National Grid, and City Bank. Managed full business operations and project delivery.

ConsultancyEnterprise ArchitectureThe ShardUCLNational Grid
View project →
AI developer tools WordPress plugin Chrome extension

AI Developer Tooling — WordPress Plugin & Chrome Extension

Built and published AI-powered developer tools: an automated WordPress news aggregation plugin with AI-generated summaries (OpenAI), and a curated AI prompt library Chrome extension. Both published and available on GitHub and the Chrome Web Store.

WordPressOpenAIChrome ExtensionJavaScriptPHP
github.com/scottnzuk →

What people say

Scott is a highly skilled individual, a great communicator, a people’s person and someone who delivers. He is an asset and would add value to any company he walks into.

Gavin Singh UK Services Manager at Meta (M.C. Dean)

Scott kept our studio running through some of the most intense production cycles. When you’re a 3D design studio with tight deadlines, you can’t afford IT downtime. He designed our network, managed the render farm, and handled everything from security to end-user support. A rare mix of deep technical knowledge and genuine people skills.

Creative Director O-Negativ (3D Design Studio)

Get in touch

Thanks for reaching out! I’ll get back to you as soon as possible.