AWS cloud architecture from an engineer who's actually done it.
BlueLake IT is led by Liam Curran, an AWS-certified Lead Cloud Architect with 9+ years of hands-on AWS experience and 25+ years in enterprise IT — designing secure, cost-efficient cloud environments for financial services, utilities, manufacturing, and public sector clients.
I specialise in designing, implementing, and optimising AWS solutions for enterprise clients — from multi-account security governance to Well-Architected reviews to hands-on delivery with Terraform and CloudFormation. I've delivered AWS cost optimizations exceeding £500k per year for individual clients, and I'm equally comfortable advising at C-level on cloud strategy as I am in the console or the codebase.
More recently, I've been building AI-assisted application development into how I work — using Amazon Kiro's spec-driven, agentic approach to build production tools in Python and Go, including an automated Windows Server fleet upgrade tool and an AWS network diagramming tool that auto-generates HLD/LLD diagrams from live VPC and Transit Gateway topology.
Practical AWS delivery, not just slide decks
Architecture, cost, security, and code — the same person from design through to delivery.
Cloud Architecture & Migration
HLD/LLD design and delivery aligned to the AWS Well-Architected Framework, including multi-account environments.
Cost Optimization (FinOps)
Rightsizing, Reserved Instances, Savings Plans, and architectural redesign — with a track record of £500k+/year in savings.
Security & Governance
Multi-account governance with IAM, SCPs, Security Hub, AWS Config, and GuardDuty to enforce compliance posture.
Infrastructure as Code & DevOps
Terraform and CloudFormation delivery, container platforms on EKS/ECS, and CodePipeline automation.
AI-Assisted Application Development
Spec-driven, agentic development with Amazon Kiro to build governed, production-ready Python and Go tooling.
Hybrid & Enterprise Identity
Hybrid Active Directory, AWS Directory Service, and Route53 Resolver for seamless on-prem-to-cloud integration.
A sample of past delivery
Drawn from 25+ years across enterprise IT and cloud architecture.
-
Managed
Services£500k+/year AWS cost optimization
Delivered cost optimizations for enterprise clients through rightsizing, Reserved Instance strategy, and architectural redesign, as named AWS consultant across a multi-million-pound client portfolio.
-
Energy &
UtilitiesGreenfield IL3-accredited infrastructure
Designed and delivered government-regulated server infrastructure for a major new-build programme in the energy sector — VMware, Citrix, multi-site PKI, SQL clusters, and secure remote access.
-
Automotive
ManufacturingSecure UK-to-China application platform
Architected a critical application access platform enabling Chinese market sales for a global automotive manufacturer, publishing UK line-of-business applications securely across borders as part of an international joint venture.
-
Retail &
E-commerceFully Terraform-managed e-commerce platform
Built and maintain an AWS e-commerce platform for a cosmetics retailer with end-to-end IaC ownership across VPC, EC2, RDS, ELB, Auto Scaling, and Route53.
Tracking AWS's new agentic security tooling
Most security reviews happen too late to change the design, and too rarely to catch what changed since the last one. AWS Security Agent runs design review, threat modeling, code review, and penetration testing on demand — here's what it does, the problems it solves, and how to roll it out.
AWS Security Agent: What It Is, What It Solves, and How to Implement It
Design review, threat modeling, code review, and on-demand penetration testing — and a 10-step guide to implementing it.
Designing Transit Gateway for security, not just connectivity
Transit Gateway is easy to stand up but easy to get wrong at the routing layer. Here's a walkthrough of three proven TGW patterns — from simple hub-and-spoke through to fully segmented, inspected traffic flows.
AWS Transit Gateway: Three Best-Practice Architecture Patterns
Hub-and-spoke, segmented isolation, and centralized inspection — how to design TGW route tables for connectivity, environment separation, or forced traffic inspection.
Just-in-time admin access: closing AWS's most common security gap
Permanent admin credentials are one of the most common findings in an AWS security review. Here's what AWS TEAM is, and a full step-by-step walkthrough of deploying it on top of IAM Identity Center.
AWS TEAM: Temporary Elevated Access Management with IAM Identity Center
Executive summary, architecture overview, and a 9-step deployment walkthrough — from delegated admin setup through to SAML integration and policy configuration.
Verified Access checks every request, not just the connection
Traditional VPNs grant broad network-level access the moment you connect. Here's what AWS Verified Access is, and how to replace VPN-based access with per-application, identity- and device-aware decisions.
AWS Verified Access: Secure Application Access Without a VPN
Architecture patterns for single and multi-application access, common use cases, and a step-by-step guide covering trust providers, policy groups, and endpoint setup.
An autonomous teammate for on-call, or an expensive dashboard?
AWS is pushing agentic AI from buzzword to product category with DevOps Agent. Here's what it actually does, how it's architected, what it costs, and what early customer evidence says about whether it lives up to the hype.
AWS DevOps Agent: An In-Depth Look at AWS's Autonomous Operations Teammate
Architecture, pricing breakdown, a comparison against Amazon Q Developer, and a candid look at where the real limits are today.
Let's talk about your AWS environment
Whether it's a cost review, a security posture check, or a full migration — happy to have a straightforward conversation about what's actually going on in your account.
- 📍 Poole, Dorset, UK
- ✉️ lcurran@bluelakeit.co.uk
- 🔗 linkedin.com/in/lcurran