| Region | Timezone | Start | End | Day |
|---|
$ whoami
$ cat role.txt
$ echo $MISSION
Designing, building & securing the networks that connect the world. Specialising in enterprise infrastructure, cloud networking & network automation.
$ _
I'm a Network & Cloud Infrastructure Engineer with extensive experience designing, implementing, and maintaining complex network and cloud infrastructures. From enterprise campus redesigns and Zero Trust security deployments to cloud-based access with Zscaler ZPA and ZIA, I bridge the gap between reliable connectivity and modern security architecture.
My work spans perimeter security with Cisco ASA firewalls, wireless migrations to Ubiquiti UniFi, and enterprise telephony — including VoIP, SIP Trunk provisioning, and unified communications platforms such as TalkDesk, RingCentral, Horizon, and Wildix. I take a holistic approach to infrastructure: secure by design, resilient by default, and built to scale.
More recently, my focus has expanded into cloud and platform engineering — administering Azure, AWS, and VMware environments, automating deployments with Terraform and GitHub-based CI/CD, and embedding DevSecOps practices such as IAM/RBAC and vulnerability management into every release. I also build the observability, backup, and disaster recovery foundations — using Datadog, Nagios, CloudWatch, and Veeam — that keep those platforms reliable, alongside multi-site Active Directory administration for enterprise identity services.
Full redesign of a multi-building campus network serving 2,000+ users. Implemented spine-leaf architecture, 802.1X authentication, and automated provisioning with Ansible. Led a phased migration from legacy infrastructure to Ubiquiti UniFi, deploying UniFi access points, switches, and the UniFi Network Controller for centralised management — significantly reducing operational overhead while improving wireless coverage and visibility across all buildings.
Architected and deployed hybrid multi-cloud connectivity bridging AWS and Azure environments. On the AWS side, leveraged Transit Gateway for centralised routing across VPCs, and on Azure used vNet Peering and Virtual Network Gateways for cross-region and cross-subscription connectivity. Secured site-to-site communication with IPsec tunnels, enforcing encrypted transit between cloud environments and on-premises infrastructure. The entire network topology was defined and provisioned as code using Terraform and deployed through GitHub-based CI/CD pipelines, embedding DevSecOps practices — including IAM/RBAC access controls and automated vulnerability scanning — into every release and eliminating manual configuration drift.
Designed and deployed a comprehensive Zero Trust security architecture leveraging Zscaler ZPA (Zero Trust Access) for secure private application access and Zscaler ZIA (Internet Access) for cloud-based web filtering and threat prevention. Integrated Cisco ASA firewalls for perimeter enforcement and stateful inspection, enabling granular policy control at the network edge. The solution eliminated implicit trust across the environment, enforcing least-privilege access for users regardless of location.
Designed and managed enterprise telephony environments with a focus on VoIP and SIP Trunk deployments. Worked across multiple platforms including TalkDesk and RingCentral for cloud-based contact centre and UCaaS solutions, Horizon (Gamma) for hosted telephony, and Wildix for unified communications. Configured and maintained SIP trunk provisioning, dial plans, call routing, and failover — ensuring high availability and quality of service across voice infrastructure.
Built and matured observability across cloud and on-premise platforms using Datadog, Nagios, and CloudWatch — designing dashboards, alerting policies, and telemetry pipelines to proactively surface incidents before they impacted users. Partnered closely with cloud, network, and cybersecurity teams to reduce mean-time-to-resolution (MTTR) and improve service reliability, while automating routine operational tasks with PowerShell, Bash, and TypeScript. Integrated GitHub Copilot and Claude into daily workflows to accelerate script development, log analysis, and technical documentation.
Administered enterprise backup and disaster recovery solutions using Veeam and Azure Storage Accounts, managing backup policies, restore procedures, and DR readiness testing across cloud and on-premise workloads. Ensured service continuity and recovery objectives were consistently met through regular DR exercises, clear documentation, and close coordination with infrastructure and cloud teams.
Administered a multi-site Active Directory environment spanning multiple domain controllers, including AD Sites & Services replication topology, DNS, cross-domain Trusts, and Group Policy Objects (GPOs). Maintained secure, consistent identity services across geographically distributed sites, supporting authentication and policy enforcement for the wider enterprise infrastructure.
| # | Network | HostMin | HostMax | Broadcast | Hosts |
|---|
| Name | Network | Prefix | HostMin | HostMax | Hosts Avail. |
|---|
| Prefix | Netmask | Wildcard | Addresses | Usable Hosts |
|---|
Type in any field to convert instantly. Useful for ACLs, packet captures and subnet masks.
| CIDR Block | Hosts | Network | Broadcast |
|---|
Encapsulation Overhead
| Port | Protocol | Service | Description |
|---|
| DSCP Name | Decimal | Hex | Binary | CoS | PHB | Typical Use |
|---|
| Standard | Speed | Media | Wavelength | Max Distance | Connector |
|---|
Common Interface Costs (ref-bw 10000 Mbps)
| Interface Type | Bandwidth | Cost (ref 100) | Cost (ref 1000) | Cost (ref 10000) |
|---|
| ASN Range | Type | Description |
|---|
| OID | Name | Description | Type |
|---|
| Region | Timezone | Start | End | Day |
|---|
Paste this into the ZPA API: POST /mgmtconfig/v1/admin/customers/{customerId}/application
Whether you need help designing a resilient network, automating your infrastructure, or just want to talk shop — I'd love to hear from you.