×
Kam Lagan

Kam Lagan

IT Executive

Dartford, Kent, UK, DA1 2TU
+44 7303 159 152

Background


About

About

Results-driven technology executive with 15+ years of success across finance, insurance, and media. Specialising in leading high-performing, globally distributed teams, managing strategic vendor and stakeholder relationships to define organisational IT strategy and managing multi-million-pound IT budgets (up to £4M).

Core strengths include:
• Strategic Governance: ISO 27001:2022 Lead Auditor , successfully implementing technical controls for DORA and establishing Architecture Review Board establishing Architecture Review Boards to enforce strategic governance across the entire SDLC. Expert in achieving Operational Resilience and managing IT risk appetite

• Financial Optimisation (FinOps): Delivering significant FinOps results, including strategic cloud spending reductions of up to 75% through architectural restructuring, SKU governance, and spending by policy.

• Cloud & Enterprise Architecture: TOGAF Certified Enterprise Architect with deep expertise in architecting and implementing large-scale Azure and multi-cloud solutions including foundational identity modernisation (AD to Entra ID).

• Emerging Technology Leadership: Drove the rollout of Microsoft Co-pilot and authored the AI policy, with a specific focus on policy-driven Data Governance for AI (e.g., Purview/Varonis).

• Platform Leadership: Ownership of Platform Engineering and Site Reliability Engineering (SRE) functions , drastically improving operational stability and reducing critical incidents (P1/P2) by 75-80%

Work Experience

Work Experience

  • IT DirectorCarne Group

    Sep, 2022 - Jul, 20252 years 10 months

    Leading provider of fund management, regulatory, and governance solutions for the asset management industry, offering expertise and technology through its digital platform.

    • Executive Leadership: Restructured the IT organisation to improve independence and efficiency, managing a £4M annual IT budget.

    • Team & Function Ownership: Owned and directed the unified Platform Engineering & SRE function, integrating ITSM, End-User Workplace Management (EUWM), and Security Operations teams across international locations.

    • Governance & Compliance (DORA/ISO 27001): Spearheaded the implementation of technical controls and successfully managed end-to-end delivery of DORA compliance and ISO 27001 renewals across technology.

    • Architecture & Strategy: Established an Architecture Review Board and managed IT policy and procedures to ensure technology investments aligned with business objectives and risk appetite.

    • Service Assurance: Accountable for outsourced service operations, ensuring continuous operational excellence ('stay at green' status) and zero critical customer issues. Defined and delivered performance metrics for infrastructure and service performance.

    • Digital Workplace Automation: Directed JML (Joiner, Mover, Leaver) automation project, reducing employee onboarding from three weeks to one hour and creating a fully automated off-boarding system.

    • Emerging Technology: Planned and rolled out Microsoft Co-pilot across the organisation, authored the AI policy on management and usage, and prepared corporate data for AI use.

  • Head of PlatformRDT Ltd

    Mar, 2022 - Aug, 20225 months

    Advanced engineering and IT solutions, empowering insurers with innovative software for claims management, fraud detection, and workflow automation.

    • Strategic Direction: Planned the strategic direction of product and engineering and directed team deliveries for the platform, which provides innovative software for claims management, fraud detection, and workflow automation.

    • DevOps Modernisation: Augmenting DevOps practices across engineering departments and modernised the CI/CD environment.

    • CI/CD Migration: Migrated classic CI/CD pipelines to templated YAML pipelines to improve consistency and maintainability.

    • Leadership & Coaching: Managed the team product backlog and coached junior members of staff in Azure and agile development practices.

  • Azure ConsultantCabot Credit Management

    May, 2019 - Nov, 20196 months

    Leading European provider of credit management services, specialising in debt purchasing, contingency collections, business process outsourcing, and litigation for various sectors including banking, utilities, and telecommunications.

    • DevOps Implementation: Introduced and enforced modern software development workflows, including GitVersion, GitFlow, DevOps, Branch Policy, and new Development and Release Pipelines.

    • Cloud Architecture & Migration: Designed and architected solutions for partial and full migration of the existing on- premise IT estate to Azure.

    • Hybrid Cloud Solution: Engineered and migrated existing on-premise .NET solutions into scalable Azure-compliant solutions, utilising Azure Relay and Azure Service Bus to ensure seamless communication with on-premise services.

    • API Exposure: Implemented public endpoints via HTTP Azure Functions exposed behind an API Management layer with Traffic Manager for high availability and load distribution.

    • IaC and Tooling: Implemented Infrastructure as Code (IaC) using PowerShell, Azure CLI, ARM, and Terraform to deploy and manage resources.

    • Mentorship: Coached junior staff members in Azure services and agile development methodologies.

  • Azure ConsultantClearbank

    Sep, 2018 - May, 20198 months

    UK’s first new clearing bank in over 250 years, providing cloud-based payment processing, clearing services, and multi-currency banking solutions to financial institutions and FinTechs.

    • Platform Architecture & Development: Led platform development of key cloud system components, focusing on robust, high availability, and scalability, including Service Fabric health checks.

    • Regulatory Compliance (PSD2/Open Banking): Architected and implemented the required systems for ClearBank to adhere to Open Banking regulations (PSD2 compliance) in the UK cloud.

    • Automation & Tooling: Enhanced incomplete code generators using Roslyn to migrate OpenAPI specifications to .NET code.

    • Full-Stack Ownership: Responsible for all build scripts, resource templates, deployment monitoring, and support from front to back-end.

    • System Transition: Architected and documented the system and service transition plans.

    • Agile Environment: Operated within an agile development environment.

  • Chief Cloud ArchitectAprexo Ltd

    Jan, 2018 - Sep, 20224 years 8 months

    Specialises in providing cloud-native Enterprise Data Management solutions tailored for asset managers, asset services, and asset owners, enabling centralised data storage, full data lineage, and API-driven access.

    • Architectural Acquisition Success: As Chief Cloud Architect, I designed and implemented a scalable, multi-tenant architectural template developed for hosting on Azure, AWS, and GCP. This robust template was adopted and utilised by the purchasing company following the startup's successful acquisition.

    • Cost Optimisation (FinOps): Achieved a significant 83% reduction in cloud costs, reducing monthly spending from £12k to £2k. Managed cost reporting using tags and environment management .

    • Security & Compliance: Defined, implemented, and enforced IT service areas for ISO 27001 compliance. Enhanced Continuous Integration/Continuous Deployment (CI/CD) pipelines by integrating security and quality controls, introducing static code analysis (SCA) with Whitesource Bolt, source composition analysis with SonarQube, and static application security testing with Trivy and Checkov .

    • Infrastructure & Platform Design: Defined and implemented Infrastructure as Code (IaC) using Terraform, AZ CLI, PowerShell, and Bash. Architected and implemented application containerisation and disaster recovery strategies.

    • Agile Leadership: Served as the Agile lead and managed daily stand-ups and board management

  • Vice PresidentPershing, a BNYM company

    Aug, 2014 - Aug, 20184 years

    BNY Pershing provides clearing, custody, trading, and settlement services, along with wealth management and investment solutions, to financial institutions, advisors, and asset managers globally.

    • Executive Management: Served as a Vice President, managing globally distributed software teams (two teams in the UK and two in India).

    • Strategic Governance: Implemented IT Governance across the organisation and successfully implemented Change Management processes.

    • Architectural Leadership: Provided infrastructure architecture and implementation for key systems.

    • CI/CD Implementation: Architected and implemented Continuous Integration/Continuous Deployment (CI/CD) pipelines to modernise software delivery.

    • Project & Service Ownership: Oversaw technical deliveries via Project Management and maintained Service Management and ownership for platform systems.

    • Stakeholder Communication: Managed C-Level communication and reporting.

    • Talent Development: Engaged in Line Management duties and led mentoring and coaching through 1:1 meetings.

  • .NET ConsultantGlobal Aerospace

    Jun, 2012 - Dec, 20131 year 6 months

    • Greenfield Development: Led greenfield architecture and development of a new endorsement system using Windows Presentation Framework (WPF).

    • Systems Analysis: Conducted comprehensive systems analysis and requirements gathering to devise new endorsement systems.

    • Mentorship: Mentored junior team members in development best practices

  • Systems AnalystSaggezza Ltd

    Mar, 2012 - May, 20122 months

    • Conducted systems analysis and requirements gathering for legacy and new system enhancements.

    • nd new system enhancements. •

  • .NET ConsultantSpafax Ltd

    Apr, 2008 - Nov, 20113 years 7 months

    • Application Overhaul: Overhauled and rebuilt the existing web application, introducing workflows with Windows Workflow (WF).

    • Agile Transformation: Introduced XP and agile techniques (including Pair programming and Test-Driven Development – TDD).

    • Implemented continuous integration and conducted requirements analysis

  • .NET ConsultantGold Medla Travel

    May, 2007 - Feb, 20089 months

    • High Availability Design: Redesigned and implemented a charter flight service using a plug-in framework, addressing high traffic demands that required high availability, scalability, resiliency, and error handling.

    • Utilised XML and XLST heavily for message routing across multiple services.

    • Managed external provider API consumption with an early form of service management.

Projects Experience

Projects Experience

  • ISO 27001

    - Present

    Implemented ISO27001 technical controls and contributed to business-wide
    governance. Served as IT lead for internal audits and external ISO reviews.
    Implemented ISO 27001 and DORA technical controls by enforcing compliance across
    infrastructure with daily IaC (Terraform) drift analysis and leveraging Azure Policy for
    resource-level reporting and remediation.• Infrastructure as Code (IaC): Terraform, ARM, Bicep, AZ CLI, and Azure
    PowerShell.
    • CI/CD & Containers: Azure DevOps, Docker, Kubernetes, Octopus Deploy, GitHub.
    • Observability & Monitoring (SRE): Service Reliability Engineering (SRE), Azure
    Monitor, Prometheus, Grafana, and Dynatrace.
    • FinOps: Budgets, Policy, Data Factsheets, Cost Reduction Strategy

  • Digital Operational Resilience Act

    - Present

    Implemented DORA technical controls and contributed to governance rollout business-wide.

  • Security Baselines

    - Present

    Implemented CIS and NIST controls throughout IT systems. Introduced Passkeys across the organisation to further improve our security posture

  • On-prem to cloud migration and uplift

    - Present

    Migrated and modernised data centre workloads to Microsoft Azure using Azure
    Landing Zones, Terraform IaC, Azure Policy, Defender for Cloud, and External Attack
    Surface Management (EASM).

  • JML Automation

    - Present

    Organisational rules were integrated into the cloud with Azure dynamic groups, access packages, and lifecycle workflows. Hardware vendors onboarded endpoints directly
    into our management app, enabling OOTB setup and allowing HR to manage employee provisioning via an HR system linked to Entra ID using SCIM. Reduced the employee onboarding process from three weeks to one hour, accelerating time-to-productivity for new hires and creating a fully automated off-boarding system.

  • Cybersecurity augmentations

    - Present

    Established Security Operations oversight, addressed insider risks and risky sign-ins,
    implemented passkey authentication to streamline access and boost security, reducing
    vulnerabilities and breaches by 90%.

  • Architected and implemented cloud infrastructure

    - Present

    Cloud architect and implementor to a startup that was ultimately acquired, with
    responsibility for the design and implementation of key systems. Experience includes
    AGW, WAF, firewall, ALZ, IaC, PIM, Entra ID OIDC, scalable stamp model, and multi-
    tenant environments. Developed to be hosted on Azure, AWS and GCP with
    comprehensive pipelines and deployment workflows, incorporating gating mechanisms
    by environment and product ownership.
    This template was used by the purchasing company.

  • FinOps

    - Present

    Reduced cloud spending by 50% and 75% at different organisations through architectural restructuring (e.g., database choice) and governance (restricting SKU choices).. Enforced spending by policy and visibility by monitoring and
    notification. Monthly insights distributed to product teams with recommendations.

  • Artificial Intelligence (AI)

    - Present

    Planned and rolled out Microsoft Co-pilot across organisation for employees. Authored
    AI policy on management and usage. Prepared corporate data for AI use by
    implementing Microsoft Purview/Varonis for data categorisation, protection, and
    enforcement of residency/retention policies.

  • Foster relationships with vendors

    - Present

    Directed technology partnerships with Microsoft, AWS, MSP, SOC, and Networks. Led
    negotiations for preview features and complimentary services to advance
    organisational goals.

  • Architectural Modernisation

    - Present

    Executed the foundational migration from on-prem AD to Entra ID to enable modern
    security and automation. Digital Workplace Automation: Directed JML automation built
    on this new identity platform, reducing employee onboarding from three weeks to one
    hour and managing security via dynamic groups and entitlement based on function.

  • Operational Resilience & Service Reliability

    - Present

    Established the SRE function and improved service quality, reducing critical (P1/P2) incidents by over 75% (from 4-5 to less than 1 per quarter). Implemented high-availability strategies (active/active or hot/warm status).

Skills

Skills

  • Microsoft Azure
  • Hashicorp Terraform
  • AZ CLI
  • Bash
  • Docker
  • Microsoft Azure DevOps
  • Octopus Deploy
  • ARM
  • ISO 27001
  • DORA
  • Microsoft Defender
  • Microsoft Sentinel
  • Passkeys
  • Active Directory
  • NIST
  • CIS
  • OAuth2/OIDC
  • DLP
  • Threat Vulnerability Management
  • ITIL
  • BCDR
  • Microsoft Co-pilot