bash — portfolio

$ whoami

$ cat role.txt

$ echo $MISSION

Designing, building & securing the networks that connect the world. Specialising in enterprise infrastructure, cloud networking & network automation.

$ _

scroll

About Me

I'm a Network & Cloud Infrastructure Engineer with extensive experience designing, implementing, and maintaining complex network and cloud infrastructures. From enterprise campus redesigns and Zero Trust security deployments to cloud-based access with Zscaler ZPA and ZIA, I bridge the gap between reliable connectivity and modern security architecture.

My work spans perimeter security with Cisco ASA firewalls, wireless migrations to Ubiquiti UniFi, and enterprise telephony — including VoIP, SIP Trunk provisioning, and unified communications platforms such as TalkDesk, RingCentral, Horizon, and Wildix. I take a holistic approach to infrastructure: secure by design, resilient by default, and built to scale.

More recently, my focus has expanded into cloud and platform engineering — administering Azure, AWS, and VMware environments, automating deployments with Terraform and GitHub-based CI/CD, and embedding DevSecOps practices such as IAM/RBAC and vulnerability management into every release. I also build the observability, backup, and disaster recovery foundations — using Datadog, Nagios, CloudWatch, and Veeam — that keep those platforms reliable, alongside multi-site Active Directory administration for enterprise identity services.

0+ Networks Deployed
0.9% Uptime Achieved
0+ Years Experience

Certifications

CCNA / CCNP Cisco Systems
AWS Solutions Architect Amazon Web Services
CompTIA Network+ CompTIA
Azure Network Engineer Microsoft

Tech Stack

Network Infrastructure

Cisco IOS/IOS-XE Juniper Junos BGP / OSPF / EIGRP MPLS / VPN VLAN / STP SD-WAN Load Balancing

Security

Firewalls (Firepower / FortiGate / Palo Alto) IDS / IPS Zero Trust 802.1X / NAC IPsec / SSL VPN SIEM SentinelOne (EDR) IAM / RBAC DevSecOps

Automation & Tooling

Python / Netmiko Ansible Terraform Nornir NAPALM Git / CI-CD REST APIs PowerShell Bash TypeScript GitHub Copilot / Claude

Cloud & Virtualization

AWS VPC / Transit GW Azure vNet VMware Hybrid Connectivity

Observability & Monitoring

Datadog CloudWatch Nagios Zabbix / Grafana SNMP / NetFlow Wireshark SolarWinds

Identity, Backup & DR

Active Directory (Multi-Site) AD Sites & Services DNS / Trusts / GPOs Veeam Azure Storage (DR)

Featured Work

Enterprise Campus Network Redesign

Full redesign of a multi-building campus network serving 2,000+ users. Implemented spine-leaf architecture, 802.1X authentication, and automated provisioning with Ansible. Led a phased migration from legacy infrastructure to Ubiquiti UniFi, deploying UniFi access points, switches, and the UniFi Network Controller for centralised management — significantly reducing operational overhead while improving wireless coverage and visibility across all buildings.

Cisco CatalystOSPFAnsible802.1XUniFi

Multi-Cloud Network Interconnect

Architected and deployed hybrid multi-cloud connectivity bridging AWS and Azure environments. On the AWS side, leveraged Transit Gateway for centralised routing across VPCs, and on Azure used vNet Peering and Virtual Network Gateways for cross-region and cross-subscription connectivity. Secured site-to-site communication with IPsec tunnels, enforcing encrypted transit between cloud environments and on-premises infrastructure. The entire network topology was defined and provisioned as code using Terraform and deployed through GitHub-based CI/CD pipelines, embedding DevSecOps practices — including IAM/RBAC access controls and automated vulnerability scanning — into every release and eliminating manual configuration drift.

AWSAzureTerraformIPsecGitHub CI/CDDevSecOps

Zero Trust Network Architecture

Designed and deployed a comprehensive Zero Trust security architecture leveraging Zscaler ZPA (Zero Trust Access) for secure private application access and Zscaler ZIA (Internet Access) for cloud-based web filtering and threat prevention. Integrated Cisco ASA firewalls for perimeter enforcement and stateful inspection, enabling granular policy control at the network edge. The solution eliminated implicit trust across the environment, enforcing least-privilege access for users regardless of location.

Zscaler ZPAZscaler ZIACisco ASAZero Trust

Telecommunications & VoIP Infrastructure

Designed and managed enterprise telephony environments with a focus on VoIP and SIP Trunk deployments. Worked across multiple platforms including TalkDesk and RingCentral for cloud-based contact centre and UCaaS solutions, Horizon (Gamma) for hosted telephony, and Wildix for unified communications. Configured and maintained SIP trunk provisioning, dial plans, call routing, and failover — ensuring high availability and quality of service across voice infrastructure.

TalkDeskRingCentralHorizonWildixVoIPSIP Trunk

Enterprise Observability & Reliability Engineering

Built and matured observability across cloud and on-premise platforms using Datadog, Nagios, and CloudWatch — designing dashboards, alerting policies, and telemetry pipelines to proactively surface incidents before they impacted users. Partnered closely with cloud, network, and cybersecurity teams to reduce mean-time-to-resolution (MTTR) and improve service reliability, while automating routine operational tasks with PowerShell, Bash, and TypeScript. Integrated GitHub Copilot and Claude into daily workflows to accelerate script development, log analysis, and technical documentation.

DatadogCloudWatchNagiosPowerShellCopilot / Claude

Enterprise Backup & Disaster Recovery

Administered enterprise backup and disaster recovery solutions using Veeam and Azure Storage Accounts, managing backup policies, restore procedures, and DR readiness testing across cloud and on-premise workloads. Ensured service continuity and recovery objectives were consistently met through regular DR exercises, clear documentation, and close coordination with infrastructure and cloud teams.

VeeamAzure StorageDisaster RecoveryBackup Policies

Multi-Site Active Directory Infrastructure

Administered a multi-site Active Directory environment spanning multiple domain controllers, including AD Sites & Services replication topology, DNS, cross-domain Trusts, and Group Policy Objects (GPOs). Maintained secure, consistent identity services across geographically distributed sites, supporting authentication and policy enforcement for the wider enterprise infrastructure.

Active DirectoryDNSGPOsAD ReplicationMulti-Site

Network Tools

PrefixNetmaskWildcardAddressesUsable Hosts

Type in any field to convert instantly. Useful for ACLs, packet captures and subnet masks.

Encapsulation Overhead

PortProtocolServiceDescription
DSCP NameDecimalHexBinaryCoSPHBTypical Use
StandardSpeedMediaWavelengthMax DistanceConnector

Common Interface Costs (ref-bw 10000 Mbps)

Interface TypeBandwidthCost (ref 100)Cost (ref 1000)Cost (ref 10000)
ASN RangeTypeDescription
OIDNameDescriptionType

              

Get In Touch

Whether you need help designing a resilient network, automating your infrastructure, or just want to talk shop — I'd love to hear from you.