Enterprise security policy and standards, identity and privilege architecture, and compliance-driven design across CJIS, HIPAA, NIST 800-53, PCI and Florida public records law simultaneously on shared infrastructure.
The firewall estate was run directly, not only designed, across two platform generations: the enterprise Juniper security platform — every rule, every change, every upgrade — and the Cisco ASA platforms serving the library system and the Clerk of Courts data centre, before architecting the Palo Alto Networks multi-tenant platform that succeeded them.
Being the person who lives with the rule base is what makes the next architecture better than the last one.
A recurring design principle, learned the hard way: security controls that take the network with them when they fail do not survive contact with an operations team. The disaster recovery path was built with diverse carrier circuits and aggregated links into redundant next-generation firewall pairs in high availability with hardware bypass, so a failure of the inspection layer degraded to open rather than to down.
Subtopics
- Criminal Justice Information BoundarySeparating CJI-bearing paths from general traffic end to end, reviewed with the state's CJIS authority and carried through thirty-five revisions.
- FortinetVDOM-separated inline intrusion prevention at the enterprise core, with separate inspection policy per internet path.
- Intrusion Prevention & DetectionInline inspection at the core designed to fail open rather than down, with monitoring segments planned in from the start.
- Juniper NetworksThe city's security estate for a period, and a deliberate second vendor track twelve years into holding a CCIE.
- Link & Platform CryptographyMACsec at the link layer and FIPS 140-2 validated platforms, where the standard is a compliance obligation rather than a preference.
- Multi-Tenant IsolationSix independently governed agencies on shared infrastructure, none able to reach, disrupt or inherit the regulatory exposure of any other.
- Palo Alto NetworksThe platform underneath the city's multi-tenant firewall boundary — multi-vsys, per-tenant routing domains and policy on shared hardware.
- Post-Quantum CryptographyCrypto-agility at scale, which is an inventory and mass-change problem before it is a cryptography problem.
Applied in
- NRI Post-Quantum Cryptography LabA lab built with NRI Japan to prepare clients in both regions for the transition to quantum-resistant cryptography.
- Enterprise Multi-Tenant Firewall ArchitectureSix independently governed agencies on shared infrastructure, none able to reach, disrupt or inherit the regulatory exposure of any other.
- Cecil Disaster Recovery Data CentreFacility and network design for the recovery site — power, cooling and carrier entry as well as what ran inside.
- Enterprise Fortinet IPS DeploymentVDOM-separated inline intrusion prevention at the enterprise core, with separate policy per internet path.
- Duval County Courthouse Technology ProgrammeA $12M IT programme inside a $350M, 800,000 square foot capital facility, cut over live to a fixed date.
- E-Commerce Site ArchitecturePIX firewalls, content switches and SSL accelerators for early commercial web estates.
- Water Treatment Facilities WAN/LANWAN and LAN design for water treatment facilities, with PIX firewall and web monitoring.
Through subtopics
5 further projects reference a subtopic of this entry rather than the entry itself.
- Enterprise Architecture Practice BuildA fourteen-person architecture practice built and led, delivering against one design language rather than individual preference.
- Annex to Main Data Centre ConsolidationMoving one data centre into another with the estate live throughout, on three design documents at revisions ten, twelve and ten.
- Consolidated CAD/911 Dispatch SystemTwo agencies with separate commands onto one dispatch platform, cutting response times from five to ten minutes down to one to two.
- Fort Stewart Mobile Disaster Recovery FleetA fleet of vehicles able to deploy across Georgia during disasters and operate where fixed infrastructure was gone.
- SOCOM Transportable Wireless KitA two-site voice, video and data package over a point-to-point link where no fixed infrastructure existed.
Career
- Director of Services, Enterprise Networking · NRI North America (formerly Core BTS)
- Principal Architect, Hybrid Infrastructure · NRI North America
- Founder and Principal Consultant · Young Tech Systems, LLC
Documents
- Enterprise Multi-Tenant Firewall ArchitectureTwenty-six revisions over its life. Palo Alto Networks asked repeatedly to publish it as a vendor white paper; the answer was no every time.
- Enterprise Security Committee CharterThe charter for the body that served as the city's enterprise architecture review board — written so its chair could be outvoted. Revision 5.0.
Attested by
- Cisco Expert-Track Written ExaminationsFour expert-track written examinations passed across eight years. These carried CCIE recertification through successive cycles — the exam record behind twenty years of maintaining #10042.
- JNCIAJuniper Networks Certified Associate, taken in January 2012 as the City of Jacksonville estate took on Juniper security platforms.
- JNCIS-SECJuniper Networks Certified Specialist, Security.
- JNCIP-SECJuniper Networks Certified Professional, Security — the professional tier of the Juniper security track.