Open to senior architecture roles and consulting engagements.
Client: Bank of Canada, Role: Network Security Solution Architect
Period: Sep 2024 - Nov 2025
Context / Challenge
The Bank of Canada operates some of Canada's most sensitive and consequential financial technology infrastructure. As the country's central bank, its network security posture is subject to scrutiny that most enterprise environments never encounter: regulatory, institutional, and national in scope. By 2024, the Bank's firewall architecture needed to evolve — from a traditional stateful inspection model to a modern, elastic, and policy-rich firewall fabric capable of supporting the Bank's Zero Trust security program and its growing hybrid-cloud footprint.
The challenge was not simply technical. It was architectural: designing a firewall fabric that could scale elastically with traffic demand, integrate with the Bank's Cisco APIC-driven network policy model, enforce multi-tenant segmentation across sensitive workload boundaries, and do so in a way that was auditable, documented, and operable by the Bank's NOC and SOC teams. Critically, the architecture needed to support migration from the existing environment without production disruption — which required detailed runbooks and validated rollback procedures for every phase.
Approach
I led the architecture from the initial design phase through documentation and migration planning. My approach was rooted in the governance discipline I'd developed across previous Bank of Canada engagements: begin with a clear HLD that captures architectural intent, develop LLDs that translate intent into specification, and produce migration runbooks that give implementation teams step-by-step procedures with decision checkpoints.
The design process involved close coordination with the Bank's APIC and SDN teams, its SOC and NOC stakeholders, and vendor technical resources. Rather than designing in isolation and handing off, I drove a collaborative architecture review process — ensuring that the design was validated against operational constraints before any configuration was committed to production.
The firewall fabric was built on the Check Point Maestro Hyperscale Network Security platform — a purpose-built architecture that enables elastic scaling of firewall capacity through a shared fabric model, without the complexity of traditional active-passive HA pairs or the limitations of fixed-chassis appliances.
Key design elements included:
Elastic scaling:
The Maestro fabric was designed to add or remove Security Group Members (SGMs) dynamically, allowing firewall throughput to scale with workload demand without traffic disruption or policy reconfiguration.
APIC integration:
Policy enforcement was integrated with the Bank's Cisco Application Policy Infrastructure Controller (APIC), enabling network segmentation policy to be expressed and enforced consistently across both the ACI fabric and the firewall layer — eliminating the policy fragmentation that typically exists between SDN and perimeter security.
Multi-tenant policy enforcement:
The architecture incorporated distinct tenant policy domains mapped to the Bank's workload classification model — ensuring that lateral movement between sensitive workload categories was controlled at the fabric level, not dependent on host-based controls alone.
Zero Trust alignment:
The firewall fabric served as a key enforcement point in the Bank's broader Zero Trust architecture — working in conjunction with the micro-segmentation design (NIST 800-207) and identity-aware access controls to enforce least-privilege connectivity at scale.
SOC/NOC telemetry integration:
Logging, alerting, and telemetry pipelines were designed to feed the Bank's Splunk SIEM and NOC monitoring infrastructure, ensuring that firewall events were visible, correlated, and actionable within the Bank's incident-response workflows.
Migration runbooks covered each phase of the cutover from the legacy environment — with explicit rollback procedures validated against production scenarios, and defined go/no-go criteria at each phase gate.
The completed architecture provided the Bank of Canada with a modern, elastic firewall fabric capable of supporting the next phase of its Zero Trust program and hybrid cloud growth. The governance artifacts — HLD, LLD, migration runbooks, and rollback plans — gave the Bank's internal teams confidence in the architecture and a documented basis for future change management. The APIC integration eliminated a persistent pain point: policy synchronization between the SDN fabric and the firewall layer, which had previously required manual coordination and was a known source of configuration drift.
Key Result: Delivered a production-ready, elastic Check Point Maestro firewall fabric with APIC integration and multi-tenant policy enforcement — documented from HLD through rollback runbook — for Canada's central bank.
Check Point Maestro | Cisco APIC | Cisco ACI | NGFW Fabric Design | Multi-Tenant Segmentation | NIST 800-207 | Splunk SIEM | Zero Trust Architecture
Client: Bank of Canada, Role: Network Solution Architect
Period: May 2022 - Sep 2024
Context / Challenge
The Bank of Canada was already running a Cisco ACI/APIC‑based datacenter fabric, but the architecture had grown unwieldy. Dual‑site features in use were being deprecated, and the existing design relied on large, physically isolated domains (Foundation, Operations, Innovation, etc.) that were difficult for the operations team to support and evolve.
At the same time, hardware and power costs were rising: multiple parallel fabrics, underutilized switching capacity, and significant datacenter power consumption were putting pressure on the operational budget. The Bank needed a way to simplify the architecture, reduce physical sprawl, and modernize its dual‑site model without disrupting critical workloads or compromising resilience.
Approach
As Network Solution Architect, I led the modernization program from assessment through delivery.
I began with a detailed review of the existing ACI/APIC deployment, focusing on feature deprecation, operational pain points, and hardware utilization.
Rather than continuing with physically isolated fabrics, I proposed a tenant‑based isolation model — using logical separation to represent Foundation, Operations, Innovation and other domains, while consolidating the physical footprint.
I evaluated both multi‑site and multipod options against the Bank’s architecture and operational requirements. Given the constraints and the need for simpler orchestration, I recommended a multipod design.
The Bank operated two active datacenter sites in the eastern region of Canada and one DR datacenter in the western region. The final architecture provided independent multipod designs for the eastern and western regions, connected via WAN rather than a single multi‑site fabric, aligning with resilience and operational requirements.
The modernization centered on redesigning the ACI fabric into cleaner, more manageable multipod architectures:
Tenant‑based isolation:
Workloads such as Foundation, Operations, and Innovation were isolated using ACI tenants and VRFs instead of separate physical fabrics. This reduced hardware sprawl while preserving clear separation of duties and risk domains.
Eastern region multipod design:
Two active datacenter sites approximately 50 km apart were designed as ACI pods within a single multipod fabric.
Cisco ONS provided 400 Gbps optical connectivity between pods, delivering high‑bandwidth, low‑latency inter‑pod links.
The design supported workload mobility between the two eastern sites without IP readdressing or complex policy rewrites.
Western region DR multipod design:
The western DR datacenter was designed as an independent multipod fabric, aligned to DR and recovery requirements.
It did not participate in a multi‑site ACI domain with the east, but was connected via WAN technologies, maintaining clear separation while still supporting failover and recovery patterns.
Simplified orchestration and operations:
By consolidating physical fabrics and using tenants for logical isolation, the operations team gained a more manageable APIC environment, fewer hardware platforms to maintain, and clearer policy boundaries.
Governance artifacts included updated HLDs, pod‑specific LLDs, tenant and VRF standards, inter‑pod connectivity designs, migration plans, cutover runbooks, and rollback procedures validated against production scenarios.
The redesigned ACI architecture replaced a complex, physically fragmented fabric with a tenant‑driven, multipod‑based design that was easier to operate, more cost‑efficient, and better aligned with the Bank’s resilience strategy.
Hardware and power consumption were reduced by consolidating fabrics and eliminating unnecessary physical isolation.
Operations gained a clearer, more governable APIC environment with logical separation that matched how the Bank actually worked.
Eastern region active sites achieved high‑bandwidth, resilient connectivity with 400 Gbps Cisco ONS links, enabling practical workload mobility.
The western DR site remained independent but integrated via WAN, preserving DR patterns without overcomplicating the ACI domain.
Key Result: Delivered a modern, tenant‑based Cisco ACI multipod architecture for both eastern and western datacenter regions — simplifying operations, reducing hardware and power overhead, and enabling high‑bandwidth, resilient connectivity between active sites while maintaining a clear, governable separation of production and DR environments.
Cisco APIC | Cisco ACI | ACI Multipod Architecture | EVPN‑VXLAN Overlay Networking | Tenant / VRF-Based Isolation Model | Inter-Pod Network (IPN) | WAN Routing (BGP) | Datacenter Spine-Leaf Switching | Hybrid Connectivity Readiness | DMVPN | MPLS |
Client: Bank of Canada, Role: Network Solution Architect
Period: May 2022 - Sep 2024
Context / Challenge
The Bank of Canada already operated a large‑scale DMVPN architecture that connected its datacenters, regional sites, and head office. As the Bank expanded its cloud footprint into two Azure regions (East and Central), the challenge was to integrate Azure into this existing routing and security model without introducing new trust boundaries, operational complexity, or architectural fragmentation.
Hybrid cloud connectivity in a central banking environment requires more than basic cloud networking. It must be:
Encrypted and resilient
Integrated with existing WAN and routing policy
Governed under strict security and audit requirements
Capable of supporting production workloads without re‑architecture
The Bank needed Azure to behave like an extension of its private network — not a separate island — while maintaining the same routing predictability, failover behavior, and security posture already established in the DMVPN design.
Approach
As Network Solution Architect, I led the redesign of hybrid connectivity to ensure Azure could be added to the Bank’s existing DMVPN architecture seamlessly.
Key principles guided the design:
Reuse proven architecture rather than introduce unnecessary new patterns
Extend existing routing and security controls into Azure
Ensure encrypted, resilient connectivity across MPLS and Internet transports
Maintain consistent behavior for datacenters, regional sites, and cloud workloads
Document every decision to support governance, audit, and long‑term operations
I worked closely with WAN, datacenter, security, and Azure platform teams to ensure the design aligned with all operational and compliance requirements.
The hybrid connectivity architecture extended the Bank’s DMVPN design into Azure using a combination of MPLS, Internet, and cloud‑based routing components.
Azure cloud datacenters were integrated directly into the Bank’s existing DMVPN architecture:
MPLS as the primary underlay transport
Internet as the secondary underlay transport
Encrypted DMVPN tunnels providing secure connectivity for all cloud workloads
Consistent routing behavior across on‑premises datacenters, regional sites, head office, and Azure VNets
This ensured Azure became a natural extension of the Bank’s private WAN.
The design provided full resilience:
Primary path: MPLS‑based DMVPN
Secondary path: Internet‑based DMVPN
Automatic failover governed by routing policy
Encrypted tunnels across both transports
This eliminated single points of failure and ensured predictable failover behavior.
Both Azure regions were added to the DMVPN fabric:
Each region connected through redundant DMVPN hubs
Routing policy ensured controlled advertisement of cloud prefixes
Regional workloads could communicate with datacenters and branches without re‑architecture
The design aligned with the Bank’s established security model:
Encrypted tunnels
Controlled route propagation
No unauthorized VNet‑to‑VNet communication
No trust boundary violations
Full auditability of routing behavior
The final architecture provided consistent connectivity for:
On‑premises datacenters
Regional branches
Head office
Azure workloads across two cloud regions
All using the same routing and security patterns already familiar to operations.
The Bank of Canada gained a fully resilient, encrypted, production‑ready hybrid cloud connectivity architecture that extended its proven DMVPN design into Azure without introducing new complexity.
Azure became a natural extension of the Bank’s private WAN
MPLS + Internet dual‑transport provided high availability and predictable failover
Regional sites and datacenters could reach cloud workloads without new routing models
Security posture remained consistent and auditable
The architecture supported future workload growth without redesign
Key Result: Delivered a fully integrated Azure hybrid connectivity architecture using DMVPN over MPLS and Internet, providing secure, resilient, encrypted connectivity between on‑premises datacenters, regional sites, head office, and two Azure regions — all governed under the Bank’s existing routing and security model.
DMVPN (Hub-and-Spoke) | MPLS WAN | Internet Underlay | Encrypted Tunnels (IPsec)| Azure Virtual Networks | Multi-Region Azure (East + Central) | Routing Policy / BGP | WAN Resilience Architecture | Existing Network Security Architecture |
Client: Bank of Canada, Role: Network Solution Architect / Network Security Architect
Period: May 2022 - Nov 2025
Context / Challenge
The Bank of Canada’s remote sites were backhauling all internet traffic through the datacenter, creating latency, performance bottlenecks, and single points of failure. This centralized model could not support modern cloud applications, SaaS adoption, or the increasing demand for remote connectivity.
The Bank needed a distributed internet architecture that improved performance, reduced dependency on datacenter egress, and maintained strict routing and security governance. At the same time, the Network Security team lacked architectural leadership for Secure Web Gateway (SWG) integration with Netskope — a critical component for securing local internet breakout.
The challenge was to modernize remote‑site internet access, integrate SWG enforcement, preserve predictable routing for datacenter‑bound workloads, and maintain full auditability across MPLS and Internet transports.
Approach
As the lead architect, I designed and delivered a secure, scalable local internet breakout model for all remote sites and later joined the Network Security team to complete the SWG integration.
My approach focused on:
Reducing datacenter dependency
Improving SaaS and cloud application performance
Maintaining encrypted, resilient connectivity
Preserving routing predictability across MPLS and Internet
Producing clear Solution Architecture Documents (SADs) for stakeholder alignment
Ensuring SWG enforcement aligned with enterprise governance
I evaluated multiple architectural approaches — including SD‑WAN — and recommended a DMVPN‑based solution for initial deployment due to cost efficiency, operational familiarity, and alignment with existing routing and security models.
Technical Solution
1. Local Internet Breakout Architecture
I designed a comprehensive local breakout architecture that eliminated datacenter backhaul for SaaS and general internet traffic while maintaining secure, predictable routing for critical workloads.
Key elements included:
Local Internet Breakout Policy Design
I authored a detailed routing and security policy defining traffic classification and egress behavior:
SaaS and cloud application traffic (Microsoft 365, Teams, Zoom, Salesforce, etc.) exited locally for optimal performance.
SWG‑bound traffic was routed directly to Netskope for inspection and policy enforcement.
Datacenter‑bound traffic (core banking apps, internal services) continued to use DMVPN over MPLS for predictable performance.
This policy eliminated unnecessary backhaul and significantly improved user experience.
Dual‑Internet Redundancy at Each Remote Site
Each site was equipped with two independent internet circuits, providing:
Carrier diversity
Automatic failover
Increased throughput
High availability for SaaS and SWG traffic
This ensured resilient local breakout even during provider outages.
DMVPN Integration for Datacenter‑Bound Workloads
Primary path: MPLS underlay
Secondary path: Internet underlay
Encrypted DMVPN tunnels ensured secure connectivity for critical workloads
This dual‑transport model maintained consistent routing behavior across all sites.
BGP‑Driven Routing Control
Local BGP routing governed path selection, failover, and traffic classification:
SaaS/SWG traffic → Local internet
Datacenter traffic → DMVPN/MPLS
Failover → DMVPN/Internet
This ensured routing remained predictable, auditable, and aligned with enterprise governance.
2. Secure Web Gateway (SWG) Integration — Netskope
The SWG program required architectural leadership, and I stepped in to support and later lead the integration.
Designed SWG routing and security patterns aligned with enterprise governance
Authored all architectural artifacts (SADs, routing models, security workflows)
Ensured SWG enforcement aligned with local breakout policies
Integrated Netskope into the routing model so internet‑bound traffic was inspected without datacenter backhaul
Completed the SWG deployment as Network Security Architect
This provided secure, policy‑driven internet access at all remote sites.
3. Governance & Documentation
I authored comprehensive Solution Architecture Documents (SADs) covering:
Design principles
Routing models
Security controls
Operational workflows
Deployment sequencing
Change management and audit alignment
These documents ensured stakeholder clarity and long‑term operational sustainability.
The Bank of Canada gained a modern, resilient, distributed internet architecture that:
Reduced latency and improved SaaS/cloud performance
Eliminated datacenter backhaul dependency
Improved VPN reliability and throughput
Provided dual‑transport resilience (MPLS + Internet)
Enabled secure local breakout at all remote sites
Integrated SWG (Netskope) for secure web access
Positioned the Bank for future SD‑WAN adoption
The architecture strengthened reliability for critical workloads while improving user experience across the enterprise.
Key Result: Delivered a secure, resilient enterprise internet modernization program — including local internet breakout, dual‑transport DMVPN architecture, and full SWG (Netskope) integration — improving performance, reducing latency, and aligning with the Bank’s security and governance standards.
DMVPN (Hub‑and‑Spoke) | MPLS WAN | Dual Internet Circuits | BGP Routing | IPsec Encryption | Netskope SWG | Local Internet Breakout | Routing Governance | Solution Architecture Documents (SADs) | WAN Resilience Architecture |