Microsoft 365IntuneUniFiZero TrustCyber EssentialsAzure / Entra IDDefenderCost ReductionCloudflareStarlinkSAML / OAuthExchange MRMConditional AccessUAC HardeningPrivileged AccessEmail GovernanceCompliance NotificationsBYOD Policies Microsoft 365IntuneUniFiZero TrustCyber EssentialsAzure / Entra IDDefenderCost ReductionCloudflareStarlinkSAML / OAuthExchange MRMConditional AccessUAC HardeningPrivileged AccessEmail GovernanceCompliance NotificationsBYOD Policies
Portfolio // 2026

Bartosz
Borowski

IT Lead · Duchy Homes Ltd

Building robust, efficient, and secure technology infrastructure. Leading the IT function — operations, security posture, and strategic decisions that support growth and optimise for cost.

5+Years Experience
Problems Solved
20%+IT Cost Reductions Delivered
LeedsUK Based
Cyber Essentials Certified
Open to Connect
01

About

// Who · What · Where

I'm Bartosz Borowski, an IT Lead based in Leeds, UK with a passion for building robust, efficient, and secure technology infrastructure.

At Duchy Homes Ltd, I lead the IT function — from day-to-day operations and infrastructure management to strategic technology decisions that support business growth and optimise for cost. My recent work has been delivered using AI-assisted research, design, and implementation, including internal application development, infrastructure planning, and security programme design — enabling rapid, high-quality delivery without external dependency.

I enjoy solving complex problems, automating wherever possible, and building systems that just work. I follow the work of SpaceX, Anthropic, Tesla and FigureAI — organisations pushing the boundary of what's possible. Outside of IT, I'm interested in nutrition, fitness, mountain climbing, and US financial markets.

RoleIT Lead
CompanyDuchy Homes Ltd
LocationLeeds, UK
FocusInfrastructure, Networking & Security
Cyber EssentialsCertified (×2 Audits)
StatusOpen to connect
02

Experience

// 5 Roles · Newest First
Jan 2025 — Present IT Lead Duchy Homes Ltd — Leeds

Leading all IT operations across a Leeds office and 7 remote development sites (~50 staff, ~250 endpoints). Responsible for network architecture, security posture, Microsoft 365 administration, vendor management, and digital transformation. Delivered multiple cost-saving initiatives reducing IT expenditure by 20%+, including a Sophos-to-Defender migration saving ~£6k/year, AI-assisted internal tooling replacing Adobe Acrobat Pro licences (~£1750/year), and migration of remote site network connectivity from managed solutions (£300–400/month/location) to an in-house Starlink fleet (sub-£100/month/site). Leading the company's Cyber Essentials compliance programme.

Microsoft 365 & IntuneUniFi / SD-WANAzure / Entra IDCyber EssentialsZero TrustCost Optimisation
Nov 2023 — Jan 2025 System Support Engineer Alpha Omega Computer Ltd — Batley

Managed client DNS, Windows Server (2016–2022) environments, and Linux (CentOS) LAMP stacks. Designed and deployed open-source management platforms including SnipeIT, Zabbix, and Zammad. Upgraded large-scale networking using Brocade, Ruckus, and pfSense. Provided remote support to 100+ users across West Yorkshire. Led the Royal Armouries network infrastructure refresh — a 10G, 3-building, 7-switch stack designed to serve ~3,000 concurrent clients at the annual UKREiiF conference.

Windows ServerLinux / CentOSpfSenseBrocade / RuckusDNS ManagementLarge-scale Networking
May 2023 — Nov 2023 1st Line Support Engineer BW Legal — Leeds

First point of contact for internal IT support in a highly regulated legal environment. Managed a hybrid Azure/on-premises Active Directory, maintained Citrix VMs, and configured Ubiquiti switches and access points. Built and configured 10-Zig Zero Clients and supported YubiKey MFA rollout. Tested internally developed Citrix Beta releases ahead of business-wide deployment.

Azure ADCitrixUniFiYubiKey MFARegulated Environment
Aug 2022 — May 2023 IT Support Technician Makehappen Group (now Future Network Solutions) — Leeds

Provided 1st and 2nd line support across UK offices including Leeds, Manchester, Thetford, Cleckheaton, and Liverpool. Deployed Ubiquiti infrastructure, managed Microsoft Exchange Online, and built SharePoint portals. Deployed and managed company devices via Microsoft Autopilot and Intune. Overhauled Grandstream VoIP systems and supported Sage server maintenance.

Autopilot / IntuneExchange OnlineSharePointVoIPMulti-site Support
Jun 2021 — Aug 2022 IT Support Technician (Apprenticeship) Woodspeen Training — Huddersfield

Completed an Infrastructure Technician Apprenticeship while delivering IT support and infrastructure improvements. Guided the company through Cyber Essentials certification, introduced an IT lifecycle strategy, participated in the migration from on-premises systems to Office 365 and SharePoint, and transitioned the company to VoIP. Established the IT asset inventory and overhauled the new starter/leaver process.

Cyber EssentialsOffice 365VoIPAsset ManagementApprenticeship
03

Skills

// Stack · Tooling · Capability
Microsoft 365 & Cloud
M365 & Azure Stack
IntuneEntra IDDefenderPurviewAzure SQLAutopilotExchange OnlineSharePoint
Infrastructure
Network & Systems
UniFiMerakiBrocadeRuckusVLANsSD-WANVPNDNS
Security
Cybersecurity
Zero TrustpfSenseSonicWallIDS/IPSMFA / YubiKeyCyber EssentialsASR RulesDKIM/DMARC
Device Management
MDM & Endpoint
IntuneApple Business ManagerWindows AutopilotPowerShellWin32 PackagingCitrix
Systems
Linux & Servers
UbuntuCentOSLAMP StackWindows ServerActive DirectoryVirtualisation
Leadership & Strategy
IT Management
Vendor ManagementBudgetingProcurementAI-assisted DevelopmentDocumentationCost Optimisation
Identity & Access
SaaS SSO & IAM
SAML / OAuthEntra ID IntegrationDynamic GroupsProcoreHubSpotAutoDeskVendor Coordination
Email & Data
Exchange Online Governance
Mailbox ArchivingMRM PoliciesPurview RetentionData LifecycleGDPR ComplianceSAR Management
Compliance & Governance
Device & Endpoint Control
BYOD PoliciesAndroid ComplianceCompliance NotificationsUAC HardeningPrivilege ManagementConditional Access
04

Work Projects

// Delivered · Professional · Highlights
Professional · Duchy Homes LtdW1
WiFi Infrastructure Modernisation
Completed June 2025 · IT Lead

Company-wide replacement of end-of-life Cisco Meraki APs with Ubiquiti UniFi U7 Pro Max (WiFi 7) across the main office and two remote sales centres. Projected savings of ~£5,000 over five years.

Professional · Duchy Homes LtdW2
Apple Device MDM
Completed May 2025 · IT Lead

Full MDM solution for all corporate Apple devices (iPhones, iPads, Macs), integrating ABM with Intune to achieve Cyber Essentials compliance and replace an entirely unmanaged device estate.

Professional · Duchy Homes LtdW3
Network Security Upgrade
Completed December 2025 · IT Lead

Replaced the company's ageing DrayTek router with a UniFi Enterprise Fortress Gateway. One-time hardware investment, fully managed in-house vs expensive managed enterprise alternatives. Delivered IDS/IPS, encrypted DNS, and VLAN segmentation.

Professional · Duchy Homes LtdW4
Endpoint & Email Security Migration
Completed January 2026 · IT Lead

Replaced Sophos Intercept X and Sophos Email with Microsoft Defender, leveraging existing M365 Business Premium licences. Projected savings of ~£15,500 over three years, eliminating ~£6,000 in annual recurring costs, without compromising security.

Professional · Duchy Homes LtdW5
AI-Assisted Internal App Development
April 2026 · IT Lead

Used AI-assisted development to build an internal PDF tooling suite from scratch with no prior development background, replacing high-volume Adobe Acrobat Pro workflows, while improving efficiency. (~£1,750/year saved).

Professional · Alpha Omega Computers LtdW6
Royal Armouries Network Refresh
Feb – May 2024 · System Support Engineer

Led the design and delivery of a 10G network infrastructure refresh across three buildings at the Royal Armouries Museum, designed to serve ~3,000 concurrent clients during the annual UKREiiF conference.

Professional · Duchy Homes LtdW7
Security Review & Modernisation Programme
Jan 2025 – Mar 2026 · IT Lead

Led a comprehensive 17-initiative security and infrastructure modernisation programme. Delivered Apple ABM/Intune MDM, Windows 11 upgrades, network hardening, endpoint migration, and Zero Trust enforcement. £6k investment generated £10k+ savings and improved Microsoft Secure Scores from ~55% to ~80%. (88% as of June 2026)

Professional · Duchy Homes LtdW8
SaaS Single Sign-On (SSO) Integration
Jan – Jun 2026 · IT Lead

Designed and implemented SAML/OAuth SSO for 6 enterprise SaaS platforms (Procore, Zutec, HubSpot, AutoDesk, EVA Check-In, SolarWinds). Centralised authentication via Entra ID, improved user experience, and enhanced governance through dynamic group assignment.

Professional · Duchy Homes LtdW9
Zero Trust Identity & Compliance Framework
Ongoing · IT Lead

Multi-component initiative including Exchange Online mailbox archiving, modernised compliance notifications with self-remediation, NUC privilege model redesign using identity-based elevation, and Android BYOD compliance policies—all aligned with Zero Trust principles.

05

Personal Projects

// 4 Home Lab Builds
Personal · Home ServerP1
Self-Hosted Plex Media Server

Self-built SFF home server running since 2021 on Ubuntu LTS (current release) for long-term security support. Hardware selected specifically for 4K Dolby Vision / HDR transcoding via Intel QuickSync. Accessible remotely through a Cloudflare Tunnel — no open ports.

Personal · Home ServerP2
AI-Powered Home Assistant

Self-hosted Home Assistant with Claude API integration for energy analysis and recommendations. Connects SolisCloud, Intelligent Octopus Go, Saving Sessions, Free Energy Sessions, AxleVPP, MyEnergi Zappi, Tesla Fleet, Solar Forecast, Google, Zigbee2MQTT, and Thread/Google Home.

Personal · Home NetworkP3
Self-Managed UniFi Home Network

Self-managed UniFi network built around a UDR7 router with a static public IP, managed via UniFi Site Manager. Security enforced through Zero Trust firewall rules in combination with Cloudflare Tunnels.

Personal · Home LabP4
Cloudflare Tunnels — Secure Remote Access

Evolved from DuckDNS with open ports → own domain on Cloudflare → Cloudflare Tunnels with zero open ports. All home lab services run exclusively through Cloudflare's edge with Zero Trust access policies enforced.