NATO/NCIA · UN · UNDP · UNOPS · FREELANCING · EU · EEAS · IBM · ALCATEL/NOKIA · MOTOROLA
06 · ArchitectureTarget-state · ADRs · reference patterns

Architecture — target-state authority

Target-state architecture authority across network, integration, data, identity, security and observability. Most recent measured outcome: ~50% decision lead-time reduction through ADR and exception governance on multi-year programmes.

Mandate type

Architect of record for transformation programmes that need a defensible target-state, reusable reference patterns and ADR-based governance. TOGAF + COBIT applied across business, application, data and technology domains.

Anchor reference

UN HQ (2016–2019) — institutional architecture for 120,000-user estate, hybrid cloud (Azure + AWS), inter-agency harmonisation. Société Générale (BRD) — 848-component enterprise architecture, ICFR / COSO control alignment. IBM EMEA CoE — 28+ migration projects, TOGAF discipline across capability and interoperability requirements.

What I do

Four offers recur on architecture mandates.

  • Target-state architecture & ADRs. Capability map, reference architecture, ADRs and exception governance. Decision lead-time ~50% reduction on multi-year programmes.
  • Reusable reference patterns. Zero Trust, micro-segmentation, HSM/KMS, identity federation, hybrid cloud, integration patterns. Designed once, reused across portfolio.
  • Operating-model alignment. Business / application / data / technology domains tied into one transformation backbone instead of fragmented project work.
  • Interoperability & cross-domain integration. API / iPaaS / eventing, identity federation, secure cross-domain integration aligned to TOGAF and NATO STANAG where applicable.

Frameworks and standards applied

Methods are scoped, not decorative. Each mandate runs against a defined framework stack so decisions remain defensible to internal audit, external supervisors and donors.

  • Architecture & modelling: TOGAF · COBIT · ArchiMate · NATO Architecture Framework (NAF) · STANAG
  • Reference patterns: Zero Trust (NIST 800-207) · micro-segmentation · HSM / KMS · identity federation · hybrid cloud
  • Identity & security: ISO/IEC 24760 · X.509 PKI · OAuth / OIDC · SAML · PAM / IAM
  • Integration: ISO 20022 · SWIFT · API gateways · iPaaS · event-driven patterns
  • Delivery: PRINCE2 · SAFe / Agile · ITIL · CMF (Capability Management Framework)
A4 infographic on enterprise architecture authority: target-state, ADRs, exception governance, reference patterns.
Architecture infographic — executive A4 visual for web, briefings and PDF capability packs. A4 · Premium high-tech briefing style
Scope detail · auto / manual scroll →
Target-state architecture & ADRs

Defensible decisions, recorded once

Capability map, reference architecture, ADRs and exception governance. The institution gets a target-state that survives leadership change.

Scope:
  • TOGAF + COBIT discipline across multi-year programmes
  • ADR template + exception governance + decision-authority matrix
  • ~50% decision lead-time reduction (measured)
  • Applied across UN, NATO, EEAS, Société Générale, IBM IC
Reference patterns

Zero Trust · micro-segmentation · HSM/KMS

Reusable reference patterns: designed once, governed centrally, replicated across the portfolio.

Scope:
  • Zero Trust (NIST 800-207) reference architecture
  • Network micro-segmentation and HSM/KMS key-management patterns
  • Identity federation (OAuth / OIDC / SAML) and PAM/IAM
  • Hybrid cloud reference (Azure + AWS + GCP)
Operating-model alignment

Business · app · data · technology into one backbone

Domain-by-domain operating-model alignment instead of project-by-project fragmentation.

Scope:
  • Business + application + data + technology domain alignment
  • Capability maps and multi-year roadmaps
  • Portfolio coherence across 100+ application estates
  • Operating-model design with named ownership and SLAs
Cross-domain integration

API · iPaaS · eventing · STANAG-aware

Integration architecture across regulated and classified contexts. API gateways, iPaaS, event-driven patterns, secure cross-domain.

Scope:
  • API gateway and iPaaS reference patterns
  • Event-driven / streaming integration patterns
  • ISO 20022, SWIFT, SEPA for financial estates
  • NATO STANAG and federated mission-system integration

Typical deliverables

Standard artefact set on an architecture mandate.

  • Target-state architecture (business, application, data, technology) with capability map
  • Reference patterns library (Zero Trust, HSM/KMS, identity, integration)
  • ADR system and exception governance with decision-authority matrix
  • Multi-year transformation roadmap with named dependencies
  • Operating-model design with named owners, SLAs and audit hooks
  • Cross-domain integration designs (API / iPaaS / event / STANAG)
Measurable outcomes · auto scroll →
~50%
decision lead-time reduction via ADR / exception governance
848
component portfolio governed end-to-end (Société Générale · BRD)
120K+
users on UN institutional architecture (95% workforce coverage)
300+
applications under unified architecture (UNFCU)
28+
migration projects led under TOGAF discipline (IBM EMEA CoE)
11+
sovereign governments — replicated DPI reference patterns

Architecture earns authority when its decisions are recorded, defensible and reused — not when its diagrams are pretty. Target-state, ADRs and reference patterns are how an institution keeps coherence after the architect leaves.

Relevant projects05 · Architecture, delivery & operations · 18 matching

Projects in this domain

Engagements filtered by primary domain from the full 270+ project record. Full detail and NDA-gated evidence packs available on request.

Public
Hybrid cloud · Content collaboration

NATO content-collaboration hybrid-cloud migration

NATO / NCIA · The Hague · 2023 – 2024

Migrated all NATO content-collaboration systems to hybrid cloud. Immutable / audit-ready versioning patterns. PAM/IAM, SIEM/SOAR and GRC platforms integrated with satellite and terrestrial networks for mission-critical environments.

Key activities

  • Designed secure-infrastructure architecture aligning controls with NIST 800-53, ISO 27001, PCI DSS and NCA ECC
  • Delivered 3rd-line operational support and advanced troubleshooting across classified estates
  • Integrated satellite-enabled PAM/IAM with SIEM/SOAR and GRC for cross-domain access governance
  • Translated complex security-architecture concepts into actionable guidance for stakeholders

Frameworks: NIST 800-53 · ISO 27001 · PCI DSS · NCA ECC · Hybrid-cloud reference architecture

Public
DR · Continuity

EEAS Disaster Recovery Centre

EEAS · Brussels · 2022 – 2023

Disaster Recovery Centre design and implementation for EEAS critical mission systems. RTO / RPO definition, failover testing and continuity evidence.

Frameworks: ISO 22301 · ISO 27031 · NIST CSF

Public
Apps migration · Hybrid cloud

EEAS apps migration & hybrid-cloud adoption

EEAS · Brussels · 2022 – 2023

Cloud-security and architecture programmes across AWS, Azure and GCP. Apps migration combined with containerisation, serverless and hybrid-cloud patterns for scalability, automation and operational resilience.

Frameworks: AWS Well-Architected · Azure CAF · GCP Cloud Adoption · DevSecOps · ITIL v3 · ISO 27001

NDA — named in CV
DevSecOps · Containers

IBM DevSecOps pipeline — containers + secrets management

IBM Innovation Center · 2019 – 2024

Containerised workloads (Docker, Kubernetes, OpenShift) with DevSecOps pipelines (Jenkins, GitLab CI/CD, HashiCorp Vault) enforcing security-as-code across IBM Innovation Center delivery.

Frameworks: DevSecOps · CIS Kubernetes Benchmark · OWASP · ISO 27001 · NIST 800-53

Public
M365 E5 · Endpoint security

UN M365 E5 Security Suite deployment

UN OICT · 2016 – 2019

Deployment of Microsoft 365 E5 Security Suite across UN workforce — DLP, MFA, Intune MDM, Conditional Access — supporting the global cybersecurity and digital-workplace transformation.

Frameworks: Microsoft Zero Trust · ISO 27001 · NIST 800-53 · GDPR

Public
Oracle EBS R12 · Encryption

UN Oracle EBS R12 upgrade — tokenisation & database encryption

UN OICT · 2016 – 2019

Oracle E-Business Suite R12 upgrade across UN estate with tokenisation and database encryption embedded, aligning ERP security to PCI DSS-grade controls.

Frameworks: PCI DSS · ISO 27001 · NIST 800-53

Public
DR · Active-active DC

UN active-active data-centre architecture

UN OICT · 2016 – 2019

Active-active data-centre architecture with automated failover using VMware SRM and Azure Site Recovery. Tested results: 99.98% availability, RTO < 4h, RPO 15 min.

Frameworks: ISO 22301 · ISO 27031 · NIST CSF

99.98% availability · RTO < 4h · RPO 15 min (tested)

DR · Virtualization

Disaster recovery + 90% server virtualization

NATO HQ · 2015 – 2016

Designed and executed first disaster-recovery centre fail-over. Successful DR plan and business continuity plan. Led server virtualization effort — virtualized 90% of systems infrastructure. AIS audits and system accreditation for classified systems.

IBM Data-Center · Tier 4

IBM Data-Center — Tier 4 (~8000 m²)

Romania · 2009 – 2011

Led from business case through Go Live: new IBM Data-Center (~8000 m², 99.995%/year). Defined and implemented business and operational processes. Service Catalogue, Budget management, SLA monitoring. Service-provider processes for PaaS, AaaS, SaaS, IaaS (cloud private, hybrid, public). ISO 27001/27002 risk assessment. PCI-DSS & ISO 2700x certification support.

SD consolidation: 45 small SD → 1 central · €500K/year saving

Application rationalisation · CSIS

Motorola estate cyber-rationalisation + CSIS

Worldwide · 2006 – 2008

Assessed >3,000 legacy applications, consolidated 839. Defined Motorola Cybersecurity policy and standards (zero-trust concept). Redesigned Internet Access Point and network topology (firmware rules, VPNs, router security, SSL). Established Center for Secure Information Systems (CSIS). Implemented Motorola's first internal/external cybersecurity audit and compliance program.

Oracle PeopleSoft · ERP

Oracle PeopleSoft — HRMS, FMS, SCM, CRM, EPM

Worldwide · 2006 – 2008

Implemented Oracle PeopleSoft (HRMS, Financial Management Solutions, SCM, CRM, Enterprise Performance Management) and Oracle ESB at organisational level.

US$45M budget executed

CMMI L3 · PMO

CMM/CMMI Level III + Motorola Romania PMO (120+ resources)

Bucharest · 2006 – 2008

Led CMM/CMMI software process improvement programme — achieved Level III. Set up local Motorola PMO (120+ resources) aligned with Freescale's PMO framework. Lean Six Sigma process improvement.

US$2.93M IT savings · 9.88% below budget

Croatia · Ucka Tunnel

Ucka Tunnel — modernization of integrated electronic safety system

Croatia · 2002 – 2006

Croatia Ministry of Transportation — Ucka Tunnel modernization of integrated electronic safety system.

>€1M

OMV Petrom

OMV Petrom — Tier 3 data centre + DR

Romania · 2002 – 2006

New data centre (Tier 3), cyber security, business continuity and disaster-recovery data centre.

>€250K

Philip Morris

Philip Morris — SCADA + WMS + BAS + HVAC

Romania · 1996 – 2002

Security systems, warehouse management system, SCADA, Building Automation System, HVAC.

British American Tobacco

BAT — security + warehouse mgmt + BAS

Romania · 1996 – 2002

Security systems, warehouse management system, Building Automation System.

Showing 16 of 18 relevant projects · View all on Projects page →