Pete Newcombe · aka Duke

Technology changes.
The engineering principles endure.

I’m a cloud, security and infrastructure architect with a career that has moved from traditional enterprise infrastructure through virtualisation, cloud and identity into Zero Trust, automation and modern security architecture.

newcombe.dev is where I document that journey — the systems I’ve worked with, the problems I’ve had to solve, the approaches that worked, and the things I would do differently next time.

Engineering across the modern enterprise.

My work sits where infrastructure, identity, networking and security meet. I design and deliver platforms that have to work not only on an architecture diagram, but for real users and operational teams at enterprise scale.

In recent years that has centred heavily on Zero Trust: moving away from perimeter and VPN-led access models toward identity- and policy-driven controls, integrating endpoint posture, automating governance, and designing access across cloud and private environments.

I still consider myself hands-on. Architecture is more useful when you understand the APIs, PowerShell, routing, DNS, identity flows and operational failure modes underneath it.

Zero Trust & Security

Cloudflare Zero Trust, identity-first access, device posture, private access, DNS security, L4/L7 policy and security-by-design.

Identity

Active Directory, Entra ID, hybrid identity, authentication, access governance and the evolution from traditional directory services to modern identity.

Cloud

Azure, AWS and Google Cloud architecture, networking, landing zones, hybrid connectivity and multi-cloud strategy.

Automation

PowerShell, APIs, Terraform, Azure DevOps, CI/CD and policy-as-code — reducing repetitive operations and making infrastructure auditable.

Endpoint & Browser

Windows, Intune, Linux endpoint management, WARP, enterprise browser technology and device posture.

Architecture

Turning complex infrastructure and security requirements into platforms that can be operated, governed and evolved at enterprise scale.

From infrastructure to identity-first security.

The technologies have changed considerably. Understanding how systems connect, fail and recover has remained surprisingly consistent.

2021 — Present

Principal Cloud & Zero Trust Architect

Cloud security, identity-first access, Zero Trust architecture and multi-cloud platform modernisation at enterprise scale.

2018 — 2021

Senior Microsoft Cloud Solutions Engineer

Azure adoption, hybrid identity, networking, endpoint management and infrastructure automation.

2006 — 2018

Senior Infrastructure Engineer

Large-scale global infrastructure, virtualisation, datacentre and disaster-recovery migrations, automation and operational engineering.

Earlier career

Infrastructure, technical leadership & IT management

A career foundation spanning electronic engineering, infrastructure operations, storage, networking and technical leadership.

10,000+users supported by enterprise Zero Trust architecture
5,000+servers in global infrastructure estates earlier in my career
1,200+Windows endpoints in an enterprise Intune deployment
500+Linux endpoints brought under managed compliance controls

Certification is useful when the knowledge survives the exam.

I’ve accumulated certifications across security, architecture, cloud, networking, Microsoft, Google, AWS, VMware, Cisco and Linux. The part I’m interested in writing about is what was actually worth learning.

Certification notes and study experience →

Certified Cloud Security Professional (CCSP)AWS Certified Solutions Architect — ProfessionalGoogle Professional Cloud ArchitectGoogle Professional Cloud Security EngineerGoogle Professional Cloud Network EngineerMicrosoft Azure Solutions Architect ExpertMicrosoft Azure DevOps Engineer ExpertMicrosoft Cybersecurity Architect ExpertTOGAF CertifiedCisco CCNA / CCDAVMware VCPRed Hat RHSEITIL

Because useful engineering knowledge is often buried in tickets, scripts and old documentation.

Over a long technical career you accumulate a lot of things that never make it into vendor documentation: migration lessons, odd DNS behaviour, PowerShell patterns, architecture decisions, failed approaches and the reason a design ended up the way it did.

This site is my attempt to capture some of that knowledge while it is still useful — from Active Directory and PowerShell through Azure, AWS and Google Cloud to Cloudflare, Zero Trust, enterprise browsers and whatever comes next.

Some posts will be deep architecture. Others will be short notes about one command or one problem that took far too long to understand.

“Automate the repeatable. Understand the failure modes. Keep the architecture operable. Never stop learning.”

A note about this site: newcombe.dev is my personal technical site. The opinions and material published here are my own and do not represent those of my employer. Examples are intentionally generalised and sanitised.