--- title: "Global Infrastructure Modernisation" outcome: "Modernised a global, multi-region estate at scale - ~1,000 VMs, flat-to-segmented networks, and a migration to Azure and Microsoft 365 - on a live 24/7 business." summary: "Across global IT roles at Virtus Health and Linde Asia Pacific: a ~1,000-VM VMware estate managed centrally, a flat-to-segmented network redesign with SD-WAN and Aruba ClearPass, Palo Alto / FortiGate firewall redesigns, and migration to Azure (Blob, AVS) and Microsoft 365." role: "Infrastructure Engineer · Virtus Health & Linde Asia Pacific" period: "2019 - 2025" stack: ["VMware / vSphere", "Azure (Blob, AVS)", "Microsoft 365", "SD-WAN", "Aruba ClearPass", "Palo Alto / FortiGate", "Veeam"] featured: false order: 40 cover: "global-infra-modernisation" --- ## Problem Enterprise estates accrete. Flat networks, sprawling VM counts, aging firewalls, and on-prem-only services become a security and operations drag. The work: modernise a global, multi-region business that runs 24/7 - without breaking it. ## Constraints - **Keep the lights on** - change a live, multi-region estate without downtime. - **Security and compliance** - segmentation, patching, and auditability throughout. - **Cost-aware** - modernise to cloud where it pays, justified through CapEx/OpEx cases. ## Design Across global roles I ran and improved a **~1,000-VM VMware estate**, managed centrally for the IT team and operated across regions including the UK. I re-segmented **flat sites into isolated VLAN ranges** with ACLs, layering in **SD-WAN** and **Aruba ClearPass** with 802.1x onboarding for a tiered, authenticated network. **Palo Alto / FortiGate** firewalls were upgraded and redesigned around the new segmentation - RCA, staging through FortiManager, and a flat-to-segmented redesign. On the platform side: workloads and identity moved to **Azure** (Blob storage, AVS - lifting existing vSphere environments) and **Microsoft 365**, with a **hybrid AD sync** I architected to bridge on-prem and cloud identity. The estate work also covered an **ERP hardware refresh with a new DR / mainframe solution**, file shares to Azure Blob over Kerberos auth, **Veeam** backups, and a region-wide **PBX-to-VoIP** migration (RingCentral). ## Security & reliability decisions - **Flat → segmented** - isolation by design, not by exception. - **Authenticated access** (ClearPass, 802.1x) - the network knows who's on it. - **Patched, current firewalls** - closing the easy doors first. - **DR built in** - recovery designed, not assumed. ## Outcome A more secure, segmented, cloud-leaning estate that's cheaper to run and easier to operate - delivered against live-business constraints across multiple regions. ## Future improvements The throughline from this work to the edge platforms: take the same segmentation and identity rigour and express it as code, so a thousand-VM estate and a single edge node are governed the same way.