Mark Milenkovic

Infrastructure & Identity Architect · Available for Contract

Infrastructure Architect with 25 years across enterprise virtualisation, datacentre design and, most recently, identity & access governance. Currently designing and delivering resilience, software-defined networking and IAM/OIG programmes for a regulated financial services platform. Comfortable owning a design end-to-end — from architecture decision records and stakeholder sign-off through to hands-on implementation, and equally at home leading a team as working the problem directly.

AWS Certified Solutions Architect VMware VCP6-DCV Cisco CCNA
25 years
enterprise infrastructure, 2001 – present
6 years
as Architect, Interactive Investor
3 disciplines
virtualisation & DR · SDN · IAM/OIG
40+ sites
international infrastructure delivered

Core Competencies

Architecture & Delivery

  • Enterprise & Solution Architecture
  • Disaster Recovery & Resilience
  • Datacentre Migration & Design
  • Technical Leadership & Delivery

Identity & Access

  • Identity & Access Governance (IAM/OIG)
  • Okta (Workflows, OIG, Privileged Access)
  • ServiceNow (CSDM, ITSM integration)
  • Access Certification & Role Modelling

Platform & Infrastructure

  • VMware vSphere / NSX / SRM / Aria
  • Pure Storage · EMC · Cisco UCS
  • AWS
  • Windows Server · Active Directory · SCCM

Also Comfortable With

  • Docker · Rancher · Red Hat Enterprise Linux
  • Prometheus monitoring
  • Cisco / HP switching · Fortigate · Cisco ASA
  • PKI, network security & PCI-DSS scope design

Key Engagements

Infrastructure Architect
Interactive Investor — Leeds
Apr 2020 – present

Grew from a contract Infrastructure Engineer role into the permanent Architect position, and now carry technical ownership of both the resilience/networking estate and, since late 2025, the identity & access governance programme.

  • Redesigned the platform's disaster recovery architecture: an NSX-based metro cluster giving VM mobility across datacentres with no network reconfiguration, backed by synchronous Pure Storage replication in place of the previous asynchronous design — closing the gap between "recoverable" and "resilient."
  • Led adoption of VMware NSX as the software-defined networking platform, now being extended into micro-segmentation across the estate.
  • Led mapping of business and technical services into ServiceNow CSDM, giving the organisation a common model linking infrastructure components to the services they support for incident and change impact analysis.
  • Led design and delivery of an Okta Identity Governance (OIG) access-governance rollout for a regulated business unit — role-based entitlement model, tiered certification design, and an automated revoke-to-ServiceNow workflow with built-in verification.
  • Ran a capability assessment of Okta Privileged Access against the incumbent PAM tooling, producing an evidence-based phased replacement recommendation rather than one driven by vendor roadmap dates.
  • Authored an Architecture Review Board paper and RFC on an identity-assurance gap in Service Desk-assisted credential recovery, presenting options against recognised assurance-level frameworks for board decision.
  • Built Okta Workflows automation integrating HR, ServiceNow and Okta for joiner/mover/leaver processing, and reviewed a custom Okta↔IBM i SCIM connector, producing an improvement roadmap for its role-assignment and directory-provisioning logic.
Read the DR architecture case study →    Read the identity & access governance case study →
Senior Infrastructure Services Engineer
Interactive Investor — Leeds (Contract)
Jan 2019 – Apr 2020
  • Technical lead for formulating the datacentre migration strategy, ahead of the metro cluster/DR redesign that followed.
  • Designed and implemented the disaster recovery process across current and target-state platforms, selecting and integrating multiple vendor technologies to bring down RTO/RPO.
  • Ongoing technical advisory role on emerging technologies and techniques for the Infrastructure team's roadmap.
Senior Infrastructure Engineer
Medical Protection Society — Leeds (Contract)
Sep 2018 – Jan 2019
  • Delivered an SCCM and Windows 10 Enterprise-based streamlined desktop OS deployment platform, with planned upgrade lifecycles for ongoing maintenance.
  • Packaged applications and defined criteria-driven device collections for targeted application rollout.
  • Resolved legacy application compatibility issues and pre-requisites blocking the rollout.
  • Built security-hardened Group Policy baselines aligned to Microsoft hardening recommendations, and rolled out BitLocker/MBAM disk encryption.
Senior Infrastructure Engineer
Sky Betting & Gaming — Leeds (Contract)
Mar 2018 – Sep 2018
  • Supported the infrastructure team through a server expansion project.
  • Implemented a containerised Prometheus monitoring solution (Rancher/Docker) with a long-term storage backend.
  • Provided general Linux environment support and BAU operations.
Infrastructure Services Team Leader / Senior Infrastructure Services Engineer
Interactive Investor (formerly TD Direct Investing) — Leeds (Contract)
Sep 2015 – Mar 2018

Technical and team lead responsible for maximum uptime of the hardware, hypervisor and SAN estate. Delivered several large projects and initiatives:

  • vBlock matrix upgrades — coordinated across teams to upgrade production and DR vBlocks with no impact to business-critical trading platforms, fully compliant with VCE (Dell) matrix versions.
  • EMC VNX / Unisphere — owned the critical block and file storage infrastructure: maintenance, system reviews, storage pool/RAID group and host group creation.
  • vRealize monitoring & capacity planning — implemented vBlock/vCenter-integrated monitoring for stress points and fault-finding, and used it to drive capacity policy — reclaiming over-provisioned capacity and mitigating at-risk under-provisioning.
  • P2V and V2V migrations — migrated critical business platforms into the virtual estate, and built out dedicated dev/test silos.
  • VMware Horizon suite — led a team implementing Mirage and Identity Manager, enabling the End User Services team to roll out a new desktop estate.
Information Security Manager / Senior Infrastructure Analyst
Medical Protection Society — Leeds
Oct 2013 – Sep 2015

Line-managed a team of infrastructure analysts; project/technical lead across the virtualised estate (~30 hosts, 300 VMs), working with the solutions design manager to scope forthcoming projects. Promoted to Information Security Manager: formed the group's security policy and IT strategy input, held authority for security infrastructure (firewalls, PKI, VPN), and was responsible for the vulnerability/pen-test remediation programme and third-party security testing.

Senior Infrastructure Analyst
Turner & Townsend PLC — Leeds
Mar 2001 – Oct 2013

Senior consultant and final escalation point for infrastructure across 40+ international offices and ~4,000 users, with local and international travel to oversee delivery. Technical authority for the group's Microsoft server, Active Directory, Citrix and VMware environments, and for its multi-vendor networking (Procurve, Cisco, Gnatbox, Barracuda). Project and technical lead for acquisition/merger-driven site migrations, ensuring acquired businesses were brought onto group IT standards. Worked directly with the CIO to shape group IT strategy and propose new systems and enhancements. See selected achievements from this period below.

Selected Achievements

Virtualisation, Storage & DR

  • Metro cluster — highly available, multi-datacentre virtualised environment (NSX + Pure Storage)
  • Hyper-converged VxRail — implemented Dell EMC VxRail, migrated key office servers
  • All-flash SAN migration — migrated critical VMs with little/no downtime; moved hosts to boot-from-SAN
  • VCE vBlock migration — moved business-critical VMs from legacy hardware/SAN with little/no downtime
  • Offsite DR datacentre design — EMC storage replication + VMware Site Recovery Manager
  • VMware Horizon (Mirage + Identity Manager) — slip-streamed desktop OS upgrades, thin-app delivery

Security & Compliance

  • Two-tier Microsoft PKI — offline root + online intermediate CA, custom certificate templates for non-standard appliances
  • PCI-DSS scope reduction — network redesign isolating voice VLAN onto a non-routable, firewall-protected segment
  • Firewall resiliency redesign — HA replacement with EtherChannel-aggregated throughput across DMZ/protected networks
  • Penetration test remediation programme — introduced regular internal/external scanning and a structured, ongoing remediation programme
  • Symantec Endpoint Protection rollout — replaced McAfee across 4,000 users / 40 offices

Messaging & Platform Lifecycle

  • Exchange 2010 redesign — CAS array + reverse proxy for secure OWA / Outlook Anywhere
  • Email encryption — DPA-driven regex-based routing to a TLS encryption service with portal pickup fallback
  • WSUS — designed and rolled out across 40 offices, ~4,000 users
  • Server 2000/2003 decommissioning — migrated services to supported platforms, upgraded domain functional levels
  • Web Farm (IIS) — load-balanced, DFS-replicated farm removing release inconsistencies across dev/test/live

Network, Telephony & M&A

  • Mitel telephony — 3300 controller rollout across two large offices, migrating off legacy telephony
  • International M&A migrations — email (Exchange → Domino), file/AD integration, user training, VPN and LAN redesign for acquired businesses
  • Rancher / Docker — load-balanced, fully containerised Prometheus monitoring platform with Postgres backend and NFS mount points

Certifications

AWS Certified Solutions Architect VMware VCP6-DCV VMware VCP5-DCV Cisco CCNA (Routing & Switching) Cisco CCNA (Security)