Scott Drinkwater
I ran incident command at Meta’s TOC, managing critical severity events across EMEA hyperscale data centres. Now I run production infrastructure for international clients from a sailboat near Barcelona. Looking for roles where infrastructure, security, AI, and marine systems converge — including superyacht IT/AV and maritime technology consulting.
18 years building and securing systems — from hyperscale data centres and critical national infrastructure at LSEG, through to cloud platforms, Docker/Kubernetes workloads, and AI infrastructure. I also bring deep marine systems expertise: Victron energy systems, onboard networking, satellite communications, and marine electronics. I live on a sailboat, so I understand what “remote” actually means. I’m autistic, which for operational work is a genuine advantage — I spot anomalies in complex data that most people miss. Based between London and Barcelona, available for permanent, contract, or rotation-based roles (remote UK/EU, superyacht rotations).
18 years designing and deploying secure network architectures across enterprise, data centre, and maritime environments. Cisco switching, OSPF routing, SD-WAN multi-site bonding, Cloudflare Zero Trust, and structured cabling including fibre.
Cisco switchingPepwave SD-WAN/SpeedFusionOmadapfSenseWatchGuardDrayTekVPNs (IPsec, OpenVPN, WireGuard)Secure tunnelsSD-WAN platformsCloudflare Zero TrustVLANsOSPFStructured cablingFibre
Multi-cloud architecture across AWS, Azure, GCP, and bare-metal providers. 18 servers running production across Hetzner, DigitalOcean, and InMotion. Container orchestration with Docker and Kubernetes, self-hosted Coolify for PaaS, and CI/CD pipeline design for production deployments.
AWSAzureGCPDigitalOceanHetznerVercelCloudflare (WAF, Tunnel, DNS)Docker (Compose, networking)K8s/K9sPodmanOrbstackTerraformCI/CD (GitHub Actions, GitLab CI, Jenkins)Rancher
Zero Trust architecture design, enterprise endpoint protection (ESET training lead, Bitdefender, Defender), SIEM deployment (Splunk, ELK), compliance frameworks (SOC 2, PCI DSS, GDPR), penetration testing, and self-hosted security recon (reNgine, Kali Linux).
ESET Business ProtectionBitdefenderMicrosoft DefenderQualysSplunkELKPenetration testingThreat modellingSOC 2PCI DSSGDPRZero Trust architectureMFA & Identity FederationSSO / SAML / OIDC
Meta TOC — managed SEVs (Severity Events), coordinated cross-team wake-up trees, routed to DBA/networking/power teams. On-call operational leadership across EMEA, managing GSOC escalation and critical outage response across hyperscale infrastructure.
SEV managementTOC operationsCross-team coordinationWake-up treesGSOC escalationRoot cause analysisIncident responseOn-call rotationRunbook authoring
Full IT lifecycle management from procurement to decommissioning. MDM with Intune/Autopilot, service desk platforms (ServiceNow, Zendesk, Freshdesk), backup and disaster recovery with Veeam and Acronis.
ManageEngine SuiteMicrosoft Intune/AutopilotSolarWinds RMMFreshdeskServiceNowZendeskosTicketVeeamAcronisAWS Backup
Hypervisor management across VMware vSphere, Hyper-V, Proxmox VE, and Citrix. Sizing, deploying, and maintaining virtualised infrastructure for enterprise workloads and homelab environments alike.
VMware vSphereHyper-VProxmox VECitrix HypervisorOracle VirtualBox
Production code in Python, TypeScript, Rust, PowerShell, Bash, and Go. Full-stack applications with React/Next.js, Node.js, and SQL. AI/ML development with Hugging Face, LangChain, and custom agent frameworks. Infrastructure automation with Terraform and Puppet. Linux and Windows Server administration.
PowerShellPythonTypeScript / JavaScriptRustBashTerraform / HCLPuppetPHPGoSwiftNode.jsReact / Next.jsSQLLinux (Ubuntu/Debian/CentOS)Windows Server (AD, GPO, DNS, DHCP)
Core speciality — 10+ years designing and delivering PACS/ACS for hyperscale data centres and critical infrastructure. Gallagher, CCURE 9000, Genetec, Avigilon, and Milestone VMS. End-to-end commissioning of Axis, Bosch, and Commend hardware.
GallagherCCURE 9000GenetecAvigilonMilestoneHikvisionAxisBoschCommendPACS/ACS design
Full-time liveaboard sailor with thousands of offshore miles. Designed and installed complete Victron energy systems (solar, MPPT, lithium, inverters). Marine electronics and protocols: NMEA 2000, SeaTalk, Signal K. Built Raspberry Pi marine navigation system with sensor networks. Engine maintenance (diesel). RYA Day Skipper, VHF license, ICC certified.
Victron Energy systemsSolar / MPPT / lithium / invertersDC electrical (12V/24V)NMEA 2000 / SeaTalkSignal KMarine networkingSatellite commsRaspberry Pi marine navDiesel engine maintenanceRYA Day SkipperVHF LicenseICCOff-grid systems designOnboard WiFi/LAN
RIBA Stages 2–5 delivery of ICT and security infrastructure for data centres and commercial developments. CAD/BIM review, design specifications, vendor coordination, commissioning, and handover documentation.
RIBA Stages 2–5CAD/BIM reviewDesign specsCommissioningVendor coordinationConfluence/SharePoint/IT Glue
Built a crypto trading agent in Rust that orchestrates three local LLMs. Experienced with MCP (Model Context Protocol), CrewAI, LangGraph, and function calling. I design agent systems for production — not the kind that work in a demo and fall over at scale.
Function calling / tool useAgent frameworks (CrewAI, LangGraph)MCP (Model Context Protocol)Multi-agent orchestrationAutonomous agent designTool-augmented LLMs
Production RAG pipelines — architecture, chunking strategies, retrieval optimisation. Vector databases (ChromaDB, Qdrant, pgvector), embedding model selection, Graph RAG with knowledge graphs. Have built and run these end-to-end, so I know where they break.
RAG architecture designChromaDBQdrantpgvectorEmbedding models & selectionGraph RAG & knowledge graphsChunking strategiesHybrid search (vector + keyword)Re-ranking pipelines
Model quantisation (GGUF, GPTQ, AWQ), inference optimisation, local deployment of open-weight models. Run Ollama and LM Studio daily. Self-hosted inference on Mac and Kubernetes. I know when to quantise and when a smaller model is the better answer.
Model quantisation (GGUF, GPTQ, AWQ)Inference optimisationOllama / LM StudioLocalAI self-hosted inferenceLoRA / QLoRA fine-tuningModel evaluation & benchmarkingPrompt cachingBatch inference
Comfortable with DeepSeek, Llama, Mistral, and Qwen model families. Proficient on Hugging Face — pipelines, inference endpoints, model hubs. I follow the open-weight model space closely and have a soft spot for Liquid AI’s smaller-fewer-parameters approach.
DeepSeek familyLlama familyMistral familyQwen familyHugging Face platformHF pipelines & inferenceLocal / open-weight model ecosystemLiquid AI
GPU cloud platforms for training and inference. Understanding of data sovereignty and regulated workloads from Meta SEV experience. Can design the infrastructure layer for AI deployments — compute, networking, storage, and security — in environments where data locality matters.
Cloud GPU platformsRunPod / Lambda Labs / Vast.aiApple Silicon inference (MLX)CUDA-aware schedulingSovereign AI infrastructureGPU cost optimisation
AI-assisted coding workflows with Cursor, Copilot, and Kilo Code. LLM-powered content generation and RSS automation pipelines. Built AI applications for WordPress, Chrome extensions, and SaaS platforms. Multilingual AI work including cross-lingual embeddings and model routing by language.
AI-assisted coding workflowsLLM API integration (OpenAI, Claude, Gemini)AI content generation / RSS automationComfyUI / Stable DiffusionMultilingual RAGCross-lingual embeddingsModel routing by languagemacOS UI automationIoT / mesh networking (Meshtastic)
The question I ask most: does this actually need AI? Cost optimisation mindset from running real infrastructure. Know when an API call is enough, when self-hosting makes sense, when fine-tuning pays off, and when you should just write a script. Active in AI tooling communities — early adopter, not a hype chaser.
AI cost optimisationAI landscape & trend awarenessMake vs buy decision frameworksAI readiness assessmentPrompt engineeringCode generation models
Full email deliverability stack for 10+ client domains: DMARC, DKIM, SPF, SSL certificate lifecycle management, and spam/malware protection. Multi-TLD DNS management, CDN and QUIC configuration. Web server management across OpenLiteSpeed, Apache, and Nginx with cPanel administration.
DMARCDKIMSPFSSL certificate managementSpam/malware protectionEmail deliverabilityMulti-TLD DNSCDN / QUICOpenLiteSpeedApacheNginxcPanel
VoIP/SIP deployment with 3CX and Teams Calling. Linux system administration (Ubuntu, Debian, CentOS). WordPress/WP-CLI site management, structured cabling, fibre termination, and UPS/power monitoring.
VoIP/SIP (3CX, Teams Calling)PaperCutUPS/power monitoringStructured cabling & fibreLinux adminRaspberry Pi/IoTWordPress / WP-CLIMDX / documentation systems