Peter Newcombe

Principal Cloud & Zero Trust Architect

Cloud security, identity-first access and multi-cloud platforms, designed and delivered at enterprise scale.

Location
Buckinghamshire, UK

Open to conversations about Zero Trust, identity and cloud architecture.

10,000+
users supported by enterprise Zero Trust architecture
5,000+
servers in global infrastructure estates earlier in my career
~1,200
Windows endpoints in an enterprise Intune deployment
~500
Linux endpoints brought under managed compliance controls

Profile

Principal-level cloud and security architect who still writes the PowerShell, reads the routing table and debugs the identity flow. Three decades in enterprise infrastructure, the last eight years in cloud and Zero Trust: I designed and delivered a multi-year Zero Trust programme that replaced legacy VPN access across a global technology estate, led the vendor RFI and proof of concept that chose the platform, and built the automation and governance that keeps it operable.

I work where infrastructure, identity, networking and security meet, across Azure, AWS and Google Cloud, and I share the practical side of that work publicly through conference sessions, webinars, long-form articles and open engineering projects at newcombe.dev.

Experience

Infrastructure Technical Architect / Principal Cloud & Zero Trust Architect

Ocado TechnologyJanuary 2021 – Present

Architectural lead for cloud security, Zero Trust and access modernisation across a global technology estate.

  • Led the design and delivery of an enterprise Zero Trust architecture, replacing legacy VPN-based access with identity- and policy-driven controls.
  • Owned vendor selection, RFI and multi-vendor proof-of-concept programmes, taking a longlist of nine vendors to a production-ready platform through weighted scoring and proofs of concept run against real identity, posture and operational requirements.
  • Sequenced the programme so that identity, device management and application inventory were strengthened before product selection, so the proof of concept tested real conditions rather than a laboratory scenario.
  • Architected and implemented Cloudflare Zero Trust: private application access, public access controls, DNS security, L4/L7 policy and TLS inspection.
  • Designed and delivered device posture and endpoint compliance enforcement, integrating device health into access decisions.
  • Implemented Linux endpoint management with Kolide, bringing the Linux user estate under managed compliance controls and directly enabling SOC 2 compliance.
  • Established automation-first governance in Azure DevOps and Terraform: policy as code, administrative access controls, configuration-drift remediation and safe deployment pipelines for Zero Trust changes.
  • Moved international users off a UK-backhauled VPN path onto nearby points of presence; some global access paths became roughly five to six times faster.
  • Led the migration from a single-subscription Azure model to Enterprise Scale landing zones, and reviewed Virtual WAN, VPN and ExpressRoute designs to improve resilience, security posture and cost.
  • Acted as senior technical authority, partnering with security, platform and identity teams to embed security by design, and mentored engineers and architects.

Senior Microsoft Cloud Solutions Engineer

Ocado TechnologyMay 2018 – January 2021

Senior engineering and architecture role underpinning Azure adoption and platform modernisation.

  • Architected and delivered the Azure cloud migration using Azure DevOps, Terraform and PowerShell.
  • Designed and implemented Azure Virtual WAN to connect satellite offices over Microsoft’s global backbone.
  • Architected and deployed Microsoft Intune device management for the Windows estate across multiple business units.
  • Led the re-architecture of Azure environments to Microsoft Enterprise Scale and the Cloud Adoption Framework.
  • Designed and maintained hybrid identity and infrastructure services: Active Directory, DNS, DHCP, Entra ID and monitoring platforms.
  • Automated infrastructure operations, patching and maintenance to remove manual processes and improve reliability.

Senior Infrastructure Engineer

McAfeeJuly 2006 – May 2018

Senior technical and architectural role within a large global cybersecurity organisation.

  • Delivered and operated large-scale global infrastructure estates of virtual and physical servers across the UK, US and India.
  • Led datacentre, disaster-recovery and colocation migrations, achieving near-zero downtime for critical platforms.
  • Architected and expanded VMware-based platforms, including major version upgrades, storage and network refreshes and capacity scaling.
  • Designed developer self-service provisioning on VMware vCloud to accelerate delivery and improve engineering productivity.
  • Improved security posture through standardised multi-platform patching, infrastructure hardening and operational controls.
  • Mentored and led engineers across multiple geographies, acting as senior escalation point for complex issues.

Expertise

Zero Trust and secure access
ZTNA, device posture, private and public application access, DNS and HTTP(S) policy, TLS inspection, SASE operations, enterprise browser controls.
Identity
Active Directory, Entra ID, hybrid identity, SAML and OIDC federation, conditional access, access governance.
Multi-cloud architecture
Azure Enterprise Scale landing zones, Virtual WAN and ExpressRoute; AWS; Google Cloud; hybrid connectivity and multi-cloud strategy.
Automation and governance
Terraform, PowerShell, Azure DevOps, GitLab CI/CD, policy as code, configuration-drift remediation, security controls in delivery pipelines.
Endpoint
Microsoft Intune, Linux endpoint management and compliance, device posture as code.
Leadership
Vendor evaluation and RFI/PoC programmes, executive stakeholder engagement, reference architectures, mentoring engineers and architects.

Certifications

Security

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Microsoft Cybersecurity Architect Expert
  • Google Professional Cloud Security Engineer

Architecture

  • AWS Certified Solutions Architect — Professional
  • Google Professional Cloud Architect
  • Microsoft Azure Solutions Architect Expert
  • TOGAF Certified

Networking

  • Google Professional Cloud Network Engineer
  • Cisco CCNA / CCDA

DevOps and platforms

  • Microsoft Azure DevOps Engineer Expert
  • VMware VCP
  • Red Hat RHSE
  • ITIL

AI leadership

  • Google Generative AI Leader
  • Microsoft AI Transformation Leader

In progress

  • Certified Ethical Hacker (CEH)

33 active Microsoft certifications, 64 exams passed.

Education

  • HND Electronic EngineeringUniversity of Hertfordshire, 1994 – 1996
  • HNC Electronic EngineeringUniversity of Bedfordshire, 1986 – 1994

Earlier career

  • Storage ExpertiPSL, 2003 – 2006
  • Technical Team LeaderComputacenter, 1999 – 2001
  • IT ManagerRegtransfers, 1998 – 1999
  • Regional Network AdministratorTechnical Indexes, 1995 – 1997
  • Electronic technician apprentice, then senior quality procurement engineerBritish Aerospace, 1986 – 1995

Speaking

  • Scaling SASE faster: Simplify deployment to accelerate time to valueCloudflare Connect London 2026 · Customer fireside-chat participant · April 2026
  • From Robotics to Remote Access: Implementing Zero Trust in an Era of Evolving ThreatsCloudflare webinar · Customer guest · September 2025
  • Ditch the VPN: Extend Zero Trust controls from apps to infrastructureCloudflare Connect London 2025 · Customer speaker · April 2025
  • The Pragmatic Approach to Zero TrustCDS webinar · Customer panel participant · March 2025
  • Zero Trust: Is the Juice Worth the Squeeze?CDS Zero Trust panel · Customer panel participant · July 2024

Full details and recordings on the speaking page.

Open engineering work

34 articles, 32 short technical notes and 8 projects published at newcombe.dev.