Available for engagements
Network & Cloud Architect — CCIE #9893 — designing enterprise-grade infrastructure that earns approval at review boards and C-level executives.
Principal Consultant at
About Me
CCIE-certified Network and Cloud Architect with over 20 years of experience designing and delivering enterprise-grade infrastructure across New Zealand and Australia. Proven track record spanning dual data centre fabric design, hybrid cloud transformation, and large-scale WAN modernisation — consistently delivering architecture that earns approval at review boards and C-level executives.
Deep technical expertise across on-premises data centre networking (EVPN/VXLAN spine-and-leaf fabrics, HPE Aruba CX, Cisco Nexus/ACI) and Azure cloud infrastructure (Landing Zones, ExpressRoute, Hub-and-Spoke, Azure Firewall, Private DNS). Trusted by major New Zealand organisations across public transport, government, financial services, and insurance to translate complex business requirements into secure, scalable, and board-ready architecture.
Known for producing high-quality architectural artefacts (HLD, DLD, ARB/DRB submissions), effective stakeholder engagement at all levels, and the ability to lead technical delivery independently or within cross-functional teams. Equally comfortable in permanent architecture roles and senior contract engagements.
What I Deliver
Focused on enterprise and government engagements where accuracy, security, and board-level communication matter.
End-to-end enterprise network design including spine-leaf data centre fabrics, WAN strategy, and security zone architecture — built to survive Review Boards.
Greenfield and brownfield data centre transformations — from collapsed core to modern EVPN/VXLAN spine-leaf, single and dual DC designs, and live migrations.
Azure Enterprise Landing Zones, hub-spoke topologies, ExpressRoute integration, and hybrid connectivity — aligned to CAF and the Well-Architected Framework.
Board-ready HLDs, LLDs, and Reference Architecture documents structured for both C-level and engineering audiences — clear, precise, and approval-ready.
Large-scale IoT and surveillance network architectures — including MPLS IP VPN designs for thousands of endpoints across geographically distributed sites.
Independent technical advisory for Architecture and Design Review Boards — including peer review of existing designs, risk identification, and gap analysis.
Selected Work
A selection of enterprise engagements across government, transport, and financial services. Client details anonymised where required.
Designed a cloud-scale, multi-tenanted dual data centre overlay network using HPE Aruba CX 10K EVPN/VXLAN spine-and-leaf fabric with multi-VRF segmentation, integrated security zones, and hub-and-spoke topology providing hybrid connectivity between on-premises and Azure NZ North. Separately designed a fully redundant Azure ExpressRoute solution connecting both DC sites to Azure.
Developed the high-level architecture for an Azure NZ North Landing Zone aligned with the Microsoft Well-Architected Framework and Landing Zone principles for scalability, governance, and operational excellence. Authored reusable architectural templates and standards enabling consistent delivery of networking modules across single and dual DC deployments.
Designed a secure identity and access management architecture using Microsoft Entra ID (Identity Governance and Entitlement Management) to control cross-agency access to shared physical and virtual resources in a pioneering All-of-Government shared accommodation initiative. Architecture approved by ARB and templated for reuse across other government shared-resource initiatives.
Designed a new Azure Hub-and-Spoke networking architecture (Azure VNet, Azure Firewall, Azure VPN Gateway) as the connectivity foundation for a major acquisition integration programme. Designed centralised DNS using Azure Private DNS Resolver with conditional forwarding, Private Endpoint and Private Link configurations for Azure Storage Accounts.
Authored the comprehensive High-Level Architecture for a major data centre modernisation programme — the first significant platform upgrade in nearly eight years. Defined a standards-based Cisco Nexus 9K spine-and-leaf fabric underpinned by Cisco ACI, encompassing current state assessment, future state design, and phased migration strategy. Approved by NZ and Group stakeholders.
Designed a highly redundant core/access network using Cisco C3560X/C2960S with Dark Fibre primary and Layer 3 MPLS failover for a major public transport organisation — delivered as a precursor to the Rugby World Cup 2011. Separately architected a major Auckland stadium's LAN using Cisco 6506E with VSS technology and 10GigE trunks, supporting 300+ Digital Media Players and IPTV.
Career History
Over two decades across enterprise, government, and financial services in New Zealand and beyond.
Get In Touch
Available for contract and consultancy engagements across enterprise and government in New Zealand. If you have an upcoming project, a Review Board deadline, or need an independent architectural review — reach out.
Private Area
Architecture assistant — restricted to authorised users only.
Sign in with your authorised email to continue.