What I can answer for end to end, and what I would reach for by default: not a list of everything I have ever touched.
Acquisition, pipelines, storage, integrity and quality across high-frequency and heterogeneous sources.
Acquisition, processing and storage at frequencies up to 1 kHz, with emphasis on integrity, timing, observability and traceability.
Interfaces that turn complex operational data into information a user or a technical team can act on.
Getting data out of systems that were never meant to give it: TLS-faithful clients, rotating proxies, session and rate handling, and a parser that fails loudly when the page changes instead of quietly returning nothing.
Behavioural modelling, forecasting, ranking, similarity and anomaly detection, with hosted and open-source models chosen on what the data and the regulation allow.
APIs, MCP tool surfaces, retrieval that cites its sources, and agents with bounded permissions.
Retrieval over the standards that govern our projects: the exact clause cited, or an explicit "not found" rather than a confident guess.
Scoring, optimisation, simulation and controlled automated actions.
Software architecture, interfaces, user workflows, cloud integration and products that stay maintainable.
Technical direction of complex systems, from backend logic and interfaces to deployment, maintainability and lifecycle decisions.
Electronics, software, operating systems, cloud infrastructure, data pipelines and interfaces integrated as one product system.
Controlled Ubuntu-based environments, reduced to what the product needs, for robustness, security and reproducibility.
Migration and automation: field mapping and reconciliation, rehearsed cutover, defined rollback, and automating what the migration exposes as manual.
Engineering where safety, validation, traceability, privacy and lifecycle requirements constrain the design: MDR and ISO-oriented processes, ISO 27001, IEC, NIS2, the Cyber Resilience Act, GDPR and the EU AI Act.
Software under MDR and ISO-oriented processes, where validation, traceability, risk and change control are part of the architecture.
IT and telecommunications responsibility for industrial deployments: sensors, industrial routers and remote sites, segmented, authenticated and logged.
Taking the organisation to ISO 27001 and preparing for NIS2 and the Cyber Resilience Act: the policies, procedures and evidence behind them.
Limits, supervision, auditability, legal context, financial consequences, and knowing when not to automate.
Technical choices evaluated through legal, regulatory, operational and financial impact, not only implementation effort.
Public-funding strategy and drafting, eligible-cost analysis, and the funding-round side: cap tables, investment types and what each option costs later.
The endpoints, the session and the permission model tested before the product is in front of anyone: with Burp Suite and by hand, and written up so the fix can be verified by someone else.
Tools I use in production, not a list of everything I have touched.