Peter Newcombe
Principal Cloud & Zero Trust Architect
Cloud security, identity-first access and multi-cloud platforms, designed and delivered at enterprise scale.
- Location
- Buckinghamshire, UK
- pete@newcombe.dev
- Web
- newcombe.dev
- linkedin.com/in/peternewcombe
Open to conversations about Zero Trust, identity and cloud architecture.
- 10,000+
- users supported by enterprise Zero Trust architecture
- 5,000+
- servers in global infrastructure estates earlier in my career
- ~1,200
- Windows endpoints in an enterprise Intune deployment
- ~500
- Linux endpoints brought under managed compliance controls
Profile
Principal-level cloud and security architect who still writes the PowerShell, reads the routing table and debugs the identity flow. Three decades in enterprise infrastructure, the last eight years in cloud and Zero Trust: I designed and delivered a multi-year Zero Trust programme that replaced legacy VPN access across a global technology estate, led the vendor RFI and proof of concept that chose the platform, and built the automation and governance that keeps it operable.
I work where infrastructure, identity, networking and security meet, across Azure, AWS and Google Cloud, and I share the practical side of that work publicly through conference sessions, webinars, long-form articles and open engineering projects at newcombe.dev.
Experience
Infrastructure Technical Architect / Principal Cloud & Zero Trust Architect
Architectural lead for cloud security, Zero Trust and access modernisation across a global technology estate.
- Led the design and delivery of an enterprise Zero Trust architecture, replacing legacy VPN-based access with identity- and policy-driven controls.
- Owned vendor selection, RFI and multi-vendor proof-of-concept programmes, taking a longlist of nine vendors to a production-ready platform through weighted scoring and proofs of concept run against real identity, posture and operational requirements.
- Sequenced the programme so that identity, device management and application inventory were strengthened before product selection, so the proof of concept tested real conditions rather than a laboratory scenario.
- Architected and implemented Cloudflare Zero Trust: private application access, public access controls, DNS security, L4/L7 policy and TLS inspection.
- Designed and delivered device posture and endpoint compliance enforcement, integrating device health into access decisions.
- Implemented Linux endpoint management with Kolide, bringing the Linux user estate under managed compliance controls and directly enabling SOC 2 compliance.
- Established automation-first governance in Azure DevOps and Terraform: policy as code, administrative access controls, configuration-drift remediation and safe deployment pipelines for Zero Trust changes.
- Moved international users off a UK-backhauled VPN path onto nearby points of presence; some global access paths became roughly five to six times faster.
- Led the migration from a single-subscription Azure model to Enterprise Scale landing zones, and reviewed Virtual WAN, VPN and ExpressRoute designs to improve resilience, security posture and cost.
- Acted as senior technical authority, partnering with security, platform and identity teams to embed security by design, and mentored engineers and architects.
Senior Microsoft Cloud Solutions Engineer
Senior engineering and architecture role underpinning Azure adoption and platform modernisation.
- Architected and delivered the Azure cloud migration using Azure DevOps, Terraform and PowerShell.
- Designed and implemented Azure Virtual WAN to connect satellite offices over Microsoft’s global backbone.
- Architected and deployed Microsoft Intune device management for the Windows estate across multiple business units.
- Led the re-architecture of Azure environments to Microsoft Enterprise Scale and the Cloud Adoption Framework.
- Designed and maintained hybrid identity and infrastructure services: Active Directory, DNS, DHCP, Entra ID and monitoring platforms.
- Automated infrastructure operations, patching and maintenance to remove manual processes and improve reliability.
Senior Infrastructure Engineer
Senior technical and architectural role within a large global cybersecurity organisation.
- Delivered and operated large-scale global infrastructure estates of virtual and physical servers across the UK, US and India.
- Led datacentre, disaster-recovery and colocation migrations, achieving near-zero downtime for critical platforms.
- Architected and expanded VMware-based platforms, including major version upgrades, storage and network refreshes and capacity scaling.
- Designed developer self-service provisioning on VMware vCloud to accelerate delivery and improve engineering productivity.
- Improved security posture through standardised multi-platform patching, infrastructure hardening and operational controls.
- Mentored and led engineers across multiple geographies, acting as senior escalation point for complex issues.
Expertise
- Zero Trust and secure access
- ZTNA, device posture, private and public application access, DNS and HTTP(S) policy, TLS inspection, SASE operations, enterprise browser controls.
- Identity
- Active Directory, Entra ID, hybrid identity, SAML and OIDC federation, conditional access, access governance.
- Multi-cloud architecture
- Azure Enterprise Scale landing zones, Virtual WAN and ExpressRoute; AWS; Google Cloud; hybrid connectivity and multi-cloud strategy.
- Automation and governance
- Terraform, PowerShell, Azure DevOps, GitLab CI/CD, policy as code, configuration-drift remediation, security controls in delivery pipelines.
- Endpoint
- Microsoft Intune, Linux endpoint management and compliance, device posture as code.
- Leadership
- Vendor evaluation and RFI/PoC programmes, executive stakeholder engagement, reference architectures, mentoring engineers and architects.
Certifications
Security
- Certified Information Systems Security Professional (CISSP)
- Certified Cloud Security Professional (CCSP)
- Microsoft Cybersecurity Architect Expert
- Google Professional Cloud Security Engineer
Architecture
- AWS Certified Solutions Architect — Professional
- Google Professional Cloud Architect
- Microsoft Azure Solutions Architect Expert
- TOGAF Certified
Networking
- Google Professional Cloud Network Engineer
- Cisco CCNA / CCDA
DevOps and platforms
- Microsoft Azure DevOps Engineer Expert
- VMware VCP
- Red Hat RHSE
- ITIL
AI leadership
- Google Generative AI Leader
- Microsoft AI Transformation Leader
In progress
- Certified Ethical Hacker (CEH)
Education
- HND Electronic EngineeringUniversity of Hertfordshire, 1994 – 1996
- HNC Electronic EngineeringUniversity of Bedfordshire, 1986 – 1994
Earlier career
- Storage ExpertiPSL, 2003 – 2006
- Technical Team LeaderComputacenter, 1999 – 2001
- IT ManagerRegtransfers, 1998 – 1999
- Regional Network AdministratorTechnical Indexes, 1995 – 1997
- Electronic technician apprentice, then senior quality procurement engineerBritish Aerospace, 1986 – 1995
Speaking
- Scaling SASE faster: Simplify deployment to accelerate time to value
- From Robotics to Remote Access: Implementing Zero Trust in an Era of Evolving Threats
- Ditch the VPN: Extend Zero Trust controls from apps to infrastructure
- The Pragmatic Approach to Zero Trust
- Zero Trust: Is the Juice Worth the Squeeze?
Open engineering work
- Cloudflare Multi-Cloud Zero Trust DemoA Terraform-managed lab across AWS, Azure and Google Cloud with Access, Gateway, WARP routing and device posture.
- Zero Trust operations WorkersCloudflare Workers that turn Access denials and Gateway blocks into support-friendly diagnostics, gate applications on training completion, and manage allow-list changes.
- Cloudflare Gateway ad blocking with TerraformRemote domain feeds normalised into Zero Trust lists and a Gateway DNS policy, rebuilt from data on every apply.
34 articles, 32 short technical notes and 8 projects published at newcombe.dev.