Open to senior architecture roles and consulting engagements.
I'm a Senior Security, Network and Cloud Architect based in Calgary, Alberta, with more than 15 years of experience designing and delivering enterprise infrastructure that operates reliably in complex, high-stakes environments. My career has been defined by a consistent pattern: organizations bring me into their most demanding network and security challenges, and I build architectures that are technically sound, clearly documented, and operationally sustainable. My longest and most substantive engagement — spanning nearly a decade in various roles at the Bank of Canada — reflects the trust that comes from consistently delivering at that level.
My expertise sits at the intersection of three disciplines that are increasingly inseparable: network architecture, security design, and hybrid cloud connectivity. I hold the Microsoft Azure Solutions Architect Expert credential (AZ-305), TOGAF Level 1 and 2 certification training, and a CCNA — backed by hands-on delivery of Cisco ACI multipod fabrics, Check Point Maestro firewall environments, Zero Trust micro-segmentation mapped to NIST 800-207, and Azure hybrid connectivity using ExpressRoute, CSR, and BGP. I don't just design on whiteboards — I author the HLDs, LLDs, migration runbooks, and cutover plans that turn architecture into delivery. I also coordinate with SOC and NOC teams to ensure what I build integrates cleanly into how the organization operates.
As a consultant and architect, I work with enterprise and mid-market clients who need clear-headed, technically rigorous guidance — not vendor-driven recommendations or overly complex designs that their teams can't maintain. I communicate directly, document thoroughly, and focus on outcomes that last beyond the engagement. If you're building something that matters and needs to be done right, I'd like to hear about it.
The foundation was built in a classroom at Algonquin College in Ottawa, where a Computer System Technician diploma gave me the technical underpinning that everything since has been built on. That grounding — not in theory alone, but in how systems actually work — has shaped how I approach every architecture problem I've encountered since.
My first significant professional responsibility came at Pinecrest-Queensway Community Health Centre (PQCHC) in Ottawa, where I managed secure network infrastructure for a multi-service community health organization from 2009 to 2016. Clinical systems, patient data, and a community depending on reliable access: this environment taught me that network design isn't abstract. It has consequences. I led digital transformation initiatives there that required both technical precision and the ability to communicate clearly with non-technical stakeholders — a combination I've found equally important at every level since.
During this period, I also supported the Olde Forge Community Resource Centre on a contract engagement, where I designed and integrated a new Cisco‑based small‑business phone system into their existing network. I scoped, bid, and delivered the project end‑to‑end — from quoting to configuration to deployment. It was a compact engagement, but an important one: it reinforced the value of designing solutions that fit the scale, constraints, and realities of the organization they serve.
In 2016, I joined the Bank of Canada, initially as a Senior Connectivity Specialist. Over six years in that role, I built deep expertise in WAN design — implementing DMVPN and BGP-based connectivity for secure branch infrastructure — and supported the Bank's datacenter networking operations, firewall migrations, and compliance readiness work. It was the kind of role where you learn the organization's infrastructure intimately, and that intimacy became the platform for what came next.
In 2022, I was engaged as Network Solution Architect — a transition from implementation into full architectural ownership. In that capacity, I led the Bank's multi-datacenter modernization program: designing and delivering Cisco ACI multipod fabrics, architecting Azure hybrid connectivity via CSR and ExpressRoute, and building a dual-ISP BGP internet edge with MPLS integration. I authored the architecture governance artifacts — standards, templates, HLDs, LLDs, runbooks — that gave the organization confidence in what was being built and how.
In 2024, the scope evolved again: I moved into the Network Security Solution Architect role, where I led the Bank's Zero Trust and hybrid-cloud security architecture program. This work included engineering a Check Point Maestro firewall fabric with elastic scaling and APIC integration, designing micro-segmentation mapped to NIST 800-207, and coordinating SOC and NOC telemetry and incident-response workflows. It is the kind of work that requires holding multiple complex domains in tension simultaneously — and delivering, documented and on schedule.
That is the path. Not a straight line, but a deliberate accumulation of depth — from hands-on technician to connectivity specialist to network architect to security architect — each stage building the capability that makes the next one possible.
Good architecture is not a diagram. It's a set of decisions, documented with enough rigor that the people who implement it — and the people who operate it three years from now — understand not just what was built, but why. I produce HLDs and LLDs because I believe that the discipline of writing an architecture down forces precision that whiteboard conversations can obscure.
Enterprise environments are already complex. My job is to reduce that complexity where possible, manage it where necessary, and never add it gratuitously. Every design decision I make is tested against a simple question: will the team that maintains this be able to understand it, troubleshoot it, and evolve it without me? If the answer is no, the design needs rework.
Security controls bolted onto existing architectures are the most expensive kind — in money, in performance, and in operational burden. I design with security as a first-order constraint, not an afterthought. Zero Trust, micro-segmentation, and least-privilege network access are not vendor features I apply; they are architectural principles I build from. NIST 800-207 is not a compliance checkbox — it's a design framework I know how to operationalize.
An architecture that isn't documented doesn't exist — it's just tribal knowledge waiting to leave with someone. I treat HLDs, LLDs, migration runbooks, and cutover plans as core deliverables, not administrative overhead. The organizations I've worked with have benefitted not just from the technical designs, but from the institutional clarity those documents create.