Design the core network connectivity foundation — Azure VNets/subnets, Application Gateway, WAF, and Azure Firewall with NSGs and Route Tables — as the foundational layer that all other Azure automation modules depend on
Architect the DNS and NetBox IPAM integration: internal zones/records, public authoritative DNS, and the prefix/role/tenant/site/VRF data model, reconciling existing on-premises and Azure network estate data into a single source of truth
Design multi-vendor firewall automation architecture across PaloAlto, F5, and Cloudflare (security rules, address/service objects, NAT, VIP/pool configuration, WAF policy attachment, certificate binding), including commit/lock handling for concurrent pipeline execution
Architect VMware NSX-T network segments (segments/T1 routers), distributed firewall (DFW) rules/groups/tags, and load balancing/NAT, ensuring addressing consistency with NetBox
Define hybrid connectivity architecture for Azure VMware Solution (AVS)/ExpressRoute, ensuring consistent routing and security posture between on-premises, VMware, and Azure environments
Contribute network-architecture input to next-phase capabilities identified in the roadmap, including global traffic management/multi-region patterns and additional infrastructure modules (SSE/ZTNA, BGP/routing)
Partner with the Azure Architect, VMware Architect, and Integration Architect (Security Focus) to ensure network design aligns with identity, certificate, and secrets architecture
Provide architectural governance for network and firewall change control, given the high blast-radius nature of these changes, and support production validation during Implementation and Adoption