Virgin Australia
Feb 2026 — PresentPrincipal Cloud Security Architect
Leading the enterprise cloud & application security uplift and the Frontier AI program for one of Australia's flagship airlines.
Currently uplifting cloud security & Frontier AI at Virgin Australia
Principal Cloud Security Architect · Ex-AWS
>
23 years architecting secure, compliant multi-cloud platforms across aviation, finance, government and healthcare — from a $1.1 billion transformation program to the frontier of enterprise AI.
Enterprise architecture experience
Transformation program directed
RFPs architected across APAC
Infrastructure cost optimised
Uptime on hybrid-cloud foundations
// the stack I go deep on
cloud platforms
enterprise architecture & threat modeling
cloud native protection · CNAPP / CSPM / CWPP
devsecops & appsec posture · ASPM / SAST / SCA
identity & zero trust · IAM / SASE
security analytics · SIEM / XDR
architecture & risk frameworks
// current mission
Principal Cloud Security Architect · Feb 2026 — Present
Hardening the multi-cloud estate — landing zones, identity, workload guardrails — against Zero-Trust, Essential Eight and ISO 27001.
Embedding DevSecOps across engineering: SAST/DAST/SCA and secrets scanning wired into CI/CD, shifting security left across the lifecycle.
Architecting the secure-adoption framework — model governance, data protection and responsible-AI controls — for generative AI at airline scale.
// how I think
run an attack scenario — or tap any component for the control it enforces
// select a component above — or run a scenario — to see the architecture thinking behind it
// trajectory
Principal Cloud Security Architect
Leading the enterprise cloud & application security uplift and the Frontier AI program for one of Australia's flagship airlines.
Principal Cloud Architect
Led solution architecture and pre-sales for AI-native automation and multi-cloud modernisation — integrating AWS generative AI services (Bedrock, SageMaker, Kendra) into intelligent document-processing platforms that cut manual handling by 70%.
Cloud Architect
Designed secure AWS Landing Zones with IAM, GuardDuty and Security Hub; drove Migration Acceleration Program engagements for AMP, Commonwealth Bank (APRA CPS 234) and CoreLogic's petabyte-scale analytics modernisation.
Lead Architect (APAC)
Secured and led the $1.1B Prudential Singapore multi-cloud transformation; answered 140+ RFPs across APAC as the organisation's AWS Champion; ran Vodafone Hutchison Australia's 3-year data-centre consolidation.
Manager, Infrastructure & Cloud Services
Ran secure infrastructure operations end-to-end and cut infrastructure spend 25% through early cloud cost-benefit engineering.
Application Systems Analyst
Designed and integrated Siebel CRM solutions for enterprise clients — where the systems-thinking began.
// signature work
Lead architect for a multi-year migration of core insurance platforms to AWS and Azure, with regulatory compliance and operational resilience built in from day one.
Problem. Core insurance platforms tied to ageing data centres, with strict regulatory obligations that made a lift-and-shift impossible and a multi-year change program inevitable.
Approach. A dual-cloud blueprint across AWS and Azure — migration waves sequenced by risk, compliance controls designed into the landing zones rather than bolted on, and an execution governance model that kept CxO stakeholders and regulators aligned across years, not sprints.
Outcome. A $1.1 billion transformation delivered with regulatory compliance and operational resilience intact — the program that defines how I approach large, regulated migrations.
AI-driven document automation on AWS Bedrock & SageMaker — 70% reduction in manual handling.
Problem. High-volume insurance documents handled manually — slow, costly, error-prone.
Approach. Unstract's IDP platform integrated with AWS Bedrock and SageMaker, turning unstructured documents into structured, auditable data flows.
Outcome. 70% reduction in manual handling, with an architecture the client could extend to new document classes without re-engineering.
Migrated mission-critical banking apps meeting APRA CPS 234, with CI/CD pipelines that cut time-to-market.
Problem. Mission-critical banking workloads needing cloud agility without compromising APRA CPS 234 information-security obligations.
Approach. Secure migration patterns mapped to CPS 234 controls, with CI/CD pipelines built in so compliance and delivery speed stopped being a trade-off.
Outcome. Mission-critical apps running in cloud, compliant, with materially faster time-to-market.
Petabyte-scale analytics moved to AWS EMR, Glue & Redshift — infrastructure cost down 40%.
Problem. Petabyte-scale property analytics on infrastructure that was expensive to scale and slow to evolve.
Approach. Re-platform onto AWS EMR, Glue and Redshift — managed, elastic, and priced for actual usage rather than peak capacity.
Outcome. Infrastructure cost down 40% with more analytical headroom than before.
Three-year program consolidating regional data centres into one resilient, cloud-integrated platform.
Problem. Regional data centres accumulated through growth and merger — duplicated cost, fragmented operations, uneven resilience.
Approach. A three-year consolidation roadmap into a unified, cloud-integrated platform, sequenced to keep a national telco running while the ground moved under it.
Outcome. One resilient, cost-efficient platform — and an operating model ready for cloud rather than merely colocated.
Secure AWS Landing Zone and hybrid integration that accelerated adoption and cut operational risk.
Problem. A financial-services estate ready to move to AWS, but without the secure foundations to move fast safely.
Approach. AWS Landing Zone with multi-account guardrails — IAM, GuardDuty, Security Hub, Config — plus hybrid integration back to on-premises systems.
Outcome. Migration velocity went up while operational risk went down; the landing zone became the paved road for everything that followed.
// on the record
Excellent technical skills. Great at understanding business requirements — and empathising with business users is a strong point. His ability to articulate technical stuff to business users impressed me the most. Great guy to have in the team.
Towfeeque was a fantastic asset to our team's success. He was part of multiple multi-million-dollar wins and also assisted the team in the execution of these. Great team player, extremely innovative, and most importantly had a constant thirst for anything new and cutting edge.
// arsenal
// on stage
AWS · customer workshops & executive briefings, Sydney
Ran Well-Architected and Migration Acceleration Program workshops for enterprise customers — taking CxO and engineering audiences from portfolio assessment to migration-wave design in the room.
AWS · immersion days & architecture deep-dives
Hands-on sessions on multi-account governance — IAM, GuardDuty, Security Hub, Config — showing engineering teams how compliance becomes a property of the platform rather than a review step.
Tech Mahindra · APAC architect enablement series, as AWS Champion
Internal enablement sessions across APAC solution teams — reference architectures, migration blueprints, and the war stories behind the Prudential Singapore transformation.
Tech Mahindra · executive & innovation workshops with CTOs/CIOs across APAC
Facilitated workshops with technology executives across finance, telco and government — pain-point discovery, adoption roadmaps built on AWS and Microsoft CAF, and business cases that survived their boards.
// field notes
Most uplift programs fail the day the program ends. The controls that survive are the ones engineers reach for because they're the paved road — guardrails in the landing zone, security in the pipeline, and nobody filling in a spreadsheet.
Enterprises agonise over which model to trust, then wire it to data flows nobody has mapped. Frontier AI adoption is won at the boundaries: what goes in, what comes out, who can see it, and what it's allowed to act on.
You can't perimeter your way across two clouds and a data centre. Identity is the only control plane that spans all of them — get workload and human identity right first, and the network conversation gets dramatically shorter.
// published thinking
Zero-Trust for regulated multi-cloud estates — and why most uplift programs don't survive their own closure report. Guardrails over gates, identity as the first control plane, and the five metrics that stay honest.
A security architecture for frontier AI in the enterprise — because the model was never the risk you had to own. Four boundaries, the AI gateway pattern, retrieval as an authorisation problem, and blast-radius design for agents.
Architecture governance for billion-dollar cloud transformations — lessons from programs that could not afford to fail. Wave design by risk, pattern libraries as throughput, and FinOps from wave one.
// engagement models
Assess the estate, design the guardrails, and leave behind an operating model — not a findings report. Zero-Trust, Essential Eight, ISO 27001 and CPS 234 alignment built into the platform.
Start the conversation →Landing zones, migration-wave design and architecture governance for programs that can't afford to fail — from first account to final data-centre exit.
Start the conversation →Secure-adoption architecture for generative and agentic AI: gateway patterns, entitlement-aware retrieval, blast-radius design and the evidence trail your regulator will ask for.
Start the conversation →// open channel
Cloud strategy, security uplift, or frontier AI adoption — I've probably architected it before. Let's talk.
// this site practices what it preaches