2.9 KiB
title, outcome, summary, role, period, stack, featured, order, cover
| title | outcome | summary | role | period | stack | featured | order | cover | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Global Infrastructure Modernisation | Modernised a global, multi-region estate at scale - ~1,000 VMs, flat-to-segmented networks, and a migration to Azure and Microsoft 365 - on a live 24/7 business. | Across global IT roles at Virtus Health and Linde Asia Pacific: a ~1,000-VM VMware estate managed centrally, a flat-to-segmented network redesign with SD-WAN and Aruba ClearPass, Palo Alto / FortiGate firewall redesigns, and migration to Azure (Blob, AVS) and Microsoft 365. | Infrastructure Engineer · Virtus Health & Linde Asia Pacific | 2019 - 2025 |
|
false | 40 | global-infra-modernisation |
Problem
Enterprise estates accrete. Flat networks, sprawling VM counts, aging firewalls, and on-prem-only services become a security and operations drag. The work: modernise a global, multi-region business that runs 24/7 - without breaking it.
Constraints
- Keep the lights on - change a live, multi-region estate without downtime.
- Security and compliance - segmentation, patching, and auditability throughout.
- Cost-aware - modernise to cloud where it pays, justified through CapEx/OpEx cases.
Design
Across global roles I ran and improved a ~1,000-VM VMware estate, managed centrally for the IT team and operated across regions including the UK. I re-segmented flat sites into isolated VLAN ranges with ACLs, layering in SD-WAN and Aruba ClearPass with 802.1x onboarding for a tiered, authenticated network. Palo Alto / FortiGate firewalls were upgraded and redesigned around the new segmentation - RCA, staging through FortiManager, and a flat-to-segmented redesign.
On the platform side: workloads and identity moved to Azure (Blob storage, AVS - lifting existing vSphere environments) and Microsoft 365, with a hybrid AD sync I architected to bridge on-prem and cloud identity. The estate work also covered an ERP hardware refresh with a new DR / mainframe solution, file shares to Azure Blob over Kerberos auth, Veeam backups, and a region-wide PBX-to-VoIP migration (RingCentral).
Security & reliability decisions
- Flat → segmented - isolation by design, not by exception.
- Authenticated access (ClearPass, 802.1x) - the network knows who's on it.
- Patched, current firewalls - closing the easy doors first.
- DR built in - recovery designed, not assumed.
Outcome
A more secure, segmented, cloud-leaning estate that's cheaper to run and easier to operate - delivered against live-business constraints across multiple regions.
Future improvements
The throughline from this work to the edge platforms: take the same segmentation and identity rigour and express it as code, so a thousand-VM estate and a single edge node are governed the same way.