brew_coffee() and a very nice working environmentJoris Oversteyns
Senior Network & Security Architect/Engineer
Designing resilient, secure enterprise networks — from branch to datacenter and cloud.
Experience
Senior Network & Security Architect/Engineer — Global Engineering & Architecture
Rejoined Johnson Controls as part of the Global Engineering team, transitioning into the Global Architecture and Engineering team from 2025. Responsible for designing and delivering complex global network and security solutions across a multi-vendor enterprise environment.
- Engineered and implemented a cloud-based private voice solution for NICE: designed a dedicated MPLS network to offload voice traffic to two Equinix colocation facilities in the UK, with seamless automatic failover to a public internet path in case of private link failure. Solution used Silverpeak SD-WAN for WAN connectivity, Cisco for LAN infrastructure, and Fortinet firewalls for segmentation between the corporate network and the NICE environment in the colos.
- Engineered and implemented an end-to-end migration from Microsoft DHCP to Infoblox BloxOne Universal DDI (engineering to production), including IPAM migration from Men & Mice to Infoblox IPAM. Developed Python automation scripts using the Infoblox API to facilitate the migration of 10,000+ subnets across more than 1,000 remote sites globally.
- Investigated and evaluated network automation platforms — Ansible, n8n, and Itential — to define a strategy for scalable network automation, exploring integration opportunities with AI to further reduce manual operational overhead.
Senior Network & Security Engineer
Part of the Belgium network team responsible for datacenter infrastructure and remote branch networks across Belgium. Highly focused on network segmentation and security across all layers of the infrastructure.
- Maintained and enhanced a Cisco Nexus datacenter infrastructure using VRFs, OTV, vPC, and advanced Nexus technologies for high-availability and multi-tenancy.
- Managed LAN and WLAN rollout and refreshes for remote branches, implementing 802.1x port-based access control using Cisco ISE for endpoint authentication and segmentation.
- Core team member for the SD-WAN implementation across 650 remote sites in Belgium using the Cisco Viptela solution.
- Applied consistent segmentation and security policies across datacenter and branch environments to meet ING's strict compliance requirements.
- Migration project where we migrated from Check Point firewalls to Palo Alto using virtual systems (VSYS) and inter-VSYS routing to enforce strict traffic segmentation and meet financial security regulations.
- Delivered end-to-end wireless infrastructure migration from legacy controllers to Cisco Catalyst 9800 series with Cisco 9160 access points, covering full engineering, lab validation, and production rollout.
Senior Network & Security Architect/Engineer
Senior architect and engineer at a global automotive seating manufacturer (spun off from Johnson Controls in 2016). Responsible for global network and security architecture, engineering, and large-scale project delivery.
- Rolled out Zscaler Cloud Security globally to 90,000 users, including local breakout on 200+ DMVPN remote sites with TCL automation scripts.
- Led global DMVPN separation project: built 4 new headend infrastructures using F5 SLB, new IOS-based PKI, new ACS cluster, and migrated 700+ remote spoke routers.
- Introduced Cisco 4000 series routers combining MPLS and DMVPN services with local breakout, ZBF, VRFs, NAT, and PBR.
- Technical lead for datacenter catalyst-to-Nexus migration (Nexus 7010, 5500, 2200).
- Migrated centralised datacenter firewalls from ASA 5545/5555 to 5585x in Active/Active multiple context mode.
Senior Network & Security Engineer
Member of the Network Connectivity & Security Operations team in a complex international enterprise environment. Responsible for remediating and standardising remote sites across EMEA to JCI network standards.
- Redesigned L2/L3 branch office networks to JCI standards, installing core/distribution/access layer devices across EMEA.
- Installed and reconfigured wireless LAN controllers (WiSM, Flex, LWAPP, FlexConnect) and standalone APs.
- Managed installation, troubleshooting, and change requests for local and centralised Cisco ASA firewalls.
- Implemented DMVPN solution for remote sites and installed BlueCoat proxy servers.
- Prepared LAN equipment for IPT rollout and handled network/security change requests.
Network & Security Support Engineer
Network and system engineer providing international support, installing and configuring network hardware, and managing Windows server infrastructure for Belgian and EMEA operations.
- Installed and configured routers, ASA firewalls, switches, APs, and wireless LAN controllers.
- Led WiFi network rollout and managed wireless devices across Belgian sites.
- Managed Windows Server infrastructure including DHCP, File & Print, and Active Directory.
- Programmed and maintained Alcatel Omnivista 4760 voice hub and telephone cabling.
- Applied ITIL change and problem management using CA Unicenter and Remedy ticketing systems.
iSeries Operator / 2nd Level Support
2nd level support for AS400/iSeries operations including monitoring, backups, and disaster recovery infrastructure.
- Second level support for AS400: monitoring backups, printers, software, hardware, and network.
- Responsible for AS400 bridge and Disaster Recovery bridge infrastructure including monitoring PCs.
- Maintained customer procedures and operational manuals.
Skills & Certifications
Routing & Protocols
Security
Network Infrastructure
Network Management & DDI
Cloud Networking
Automation & Platforms
Certifications
CCIE Routing & Switching — Written
Cisco · Issued Jan 2015
CCNP Routing and Switching
Cisco · Issued Jan 2012
CCNA
Cisco · Issued Jan 2011
CCNA Security
Cisco · Issued Jan 2009
Configuring BGP on Cisco Routers (642-661)
Cisco · Issued Jan 2008
Training
Deploying Aruba SD-WAN Technologies
Extending Silverpeak / Aruba SD-WAN expertise · 2024
Advanced SD-WAN Deployments and Troubleshooting SD-WAN Networks
Extending Silverpeak / Aruba SD-WAN expertise · 2024
Cisco Viptela SD-WAN Training
Extending SD-WAN expertise · 2022
Palo Alto Network Security Professional
Extending Palo Alto NGFW expertise · 2021
F5 Training — GTM & GSLB
In-house training for migration from ACE to F5 · 2016
BlueCoat ProxySG Administration and Professional
ProxySG administration and professional certification · 2014
CCIE Routing & Switching
Online training — INE · 2014
Nexus Data Center Switching
Improving Nexus skills · 2013
642-524 Securing Networks with ASA Foundation
Certification as Cisco Certified Security Specialist · 2013
CCIE Security v4
Online training class — INE · 2013