IJCIreneo John II Colet

Montréal, QC · English / Français

Ireneo John II Colet

Information Technology & Security Architect · Defence · Industrial · Financial Coporation

I design identity, infrastructure and security architectures for environments where failure is not an option: naval mission systems, industrial plants and national financial networks. My work runs from the functional System-of-Systems view down to the physical design, with governance that keeps security designed in, measured and owned.

PMP · PMI CISM · ISACA TOGAF 9.2 Foundation CCNA
Zones & conduitsISA/IEC 62443 · Purdue model
L4–5
ERP · OracleAzure ADM365ServiceNow
L3.5 DMZ
CyberArk PAMCitrix NetScalerHistorian mirror
L3
MESPlant HistorianSCADA server
L2
HMIBMSRF scanners
L0–1
PLCAGVSensors & drives

Simplified view of how I segment industrial environments: no direct IT-to-OT path, and every vendor session is brokered and recorded in the DMZ.

70%

Risk reduction across the North American region after rolling out ISA/IEC 62443, NIST and ITIL frameworks.

100+

Firewalls under incident-response management (Cisco ASA, Firepower, Palo Alto) in a national insurance environment.

15+ yrs

In IT across defence, manufacturing and financial services, from service desk leadership to enterprise and security architecture.

What I bring

Mission & enterprise architecture

System-of-Systems functional architecture, low-level physical and logical design with control traceability, reusable pattern catalogues, and architecture review boards.

OT / ICS security

Secure architectures for SCADA, BMS, historians, PLCs and AGVs, with zones and conduits, brokered vendor access, and OT tabletop exercises.

Identity, zero trust & isolation

IDAM across multi-enclave estates, authentication brokering and privileged access, zero trust for ICS and enterprise networks, and domain isolation with controlled information transfer.

Assurance & delivery

Security assessment and authorization under RMF, test and evaluation ahead of deployment, third-party risk, ITIL governance, and PMP-grade delivery.

Frameworks I work in

ISA/IEC 62443Zero TrustNIST CSFNIST 800-53NIST RMF 800-37ISO 27001CIS ControlsMITRE ATT&CKTOGAFCOBITITILIT4ITPCI DSSSOXGDPRPMBOK

Architecture portfolio

Reference architectures

Each case is written like an architecture decision record: the context, the decision, and what changed. Diagrams are simplified and sanitized, so they show patterns, not client network details.

Weir Marine Engineering · NETE2026 – presentDefence · Naval

Multi-enclave identity & domain isolation for a naval System of Systems

Context
A naval management system is being designed as a System of Systems: discrete subsystems of differing sensitivity, spread across afloat and shore capability, that must keep working in denied, disrupted, intermittent and limited-bandwidth conditions.
Decision
Allocate user, infrastructure, management and security services per operating domain, with explicit boundary demarcation and controlled information transfer between enclaves. Identity is brokered between shore and afloat, privileged access is governed separately, and a standard service catalogue gives every enclave the same repeatable patterns.
Outcome
Low-level design traces in both directions from security control narratives to the configuration baseline. It supports assessment and authorization, and it is proven in a land-based test environment before shipboard installation.
System of SystemsIDAMDomain isolationDDILRMF · SA&AT&E
SHORE CAPABILITY Identity servicesauthoritative source Privileged access Management services Monitoring · recovery AFLOAT · SYSTEM OF SYSTEMS Authentication brokerworks when disconnected Enclavehigh Enclavelow Controlled transfer Service catalogue identity sync DDIL link Land-based test environment interfaces and design proven before shipboard installation
Generic pattern only, with no program specifics. Enclaves exchange data only through the controlled transfer point, and the afloat broker keeps authenticating when the shore link drops.
IPEX Group of Companies2023 – 2026Manufacturing · OT

ICS zero trust & brokered vendor access

Context
Plants ran SCADA, BMS, Plant Historian, PLC, AGV and RF scanner systems. Vendors reached plant systems through the corporate VPN, and the paths between IT and OT were not segmented consistently.
Decision
Apply zero trust to the industrial control environment using ISA/IEC 62443 zones and conduits on the Purdue model, with an industrial DMZ at level 3.5. Vendors lose corporate VPN access; every session goes through Citrix Workspace/NetScaler and CyberArk PAM, and no direct path crosses from IT to OT. File transfers to manufacturing assets go through one centralized, secured path.
Outcome
Combined with the NIST and ITIL rollout, this delivered a 70% risk reduction across the North American region. It is validated by recurring OT cyber tabletop exercises.
ISA/IEC 62443ICS zero trustCyberArkCitrix NetScalerSCADAMES
ENTERPRISE ZONE · L4–5 Remote vendors ERP / Oracle INDUSTRIAL DMZ · L3.5 Citrix NetScaler CyberArk PAM Historian mirror CONTROL ZONES · L0–3 SCADA MES Plant Historian BMS PLC AGV RF scanners brokered, recorded session
Vendor path: NetScaler, then a PAM session, then the target zone. The historian mirror feeds ERP without opening a connection back into OT.
IPEX Group of Companies2023 – 2026Hybrid infrastructure

Hybrid data center & cloud resilience

Context
Workloads were split between on-premises data centers and cloud, with uneven availability and backup coverage across sites.
Decision
Redesign around Dell EMC hyperconverged clusters on-premises and Azure for burst and recovery. Environments are defined as code with Terraform, Azure ARM and GitHub, so every build is repeatable and reviewed.
Outcome
A high-availability hybrid platform with consistent backup and recovery paths, and infrastructure changes that go through version control instead of manual builds.
AzureTerraformARMDell EMC HCIGitHub
Infrastructure as code GitHub · Terraform · ARM ON-PREMISES DATA CENTER Dell EMC HCI cluster A Dell EMC HCI cluster B Local backup tier MICROSOFT AZURE Recovery workloads Cloud-native services Offsite backup vault replicate backup
Two HCI clusters give local high availability, and Azure holds recovery capacity and the offsite backup copy.
Phoenix-Loureiroi Imports2021 – 2023Identity · Cloud

Identity & access management framework

Context
An international import/export business with users, devices and hosting facilities in several geographies, and no single control point for access.
Decision
Make identity the perimeter. Azure AD is the source of truth, and Conditional Access, MFA and SSO sit in front of Exchange and Office 365. Intune gates access on device compliance, and a separate privileged-access tier holds admin rights.
Outcome
One enforced access policy for every app and device, and hosting facilities integrated with Azure for business continuity.
Azure ADConditional AccessMFA / SSOIntunePAM
Userany location DeviceIntune check Azure AD Conditional Access MFA · SSO · risk Office 365 Exchange Business apps Privileged access tier separate admin accounts · just-in-time rights
Each request is evaluated on user, device and risk before a token is issued. Admin rights live only in the separate privileged tier.
Intact Financial Corporation2016 – 2021Network security · Insurance

Zero-trust perimeter & global remote access

Context
A national insurer running a mix of Cisco ASA, Firepower, Juniper, Check Point and Palo Alto firewalls. It needed consistent inspection and secure remote access across several internet points of presence (iPOPs).
Decision
Consolidate on Palo Alto NGFW with zero-trust policy, SSL decryption, Advanced Threat Prevention, URL filtering and policy-based forwarding. Remote users connect through GlobalProtect gateways centralized at each iPOP, authenticating with RADIUS, LDAP and certificates.
Outcome
One policy model managed from Panorama, with live visibility through Elasticsearch/Kibana dashboards. The team contained a Q4 2020 DDoS (DTLS exhaustion) against Citrix ADC and Gateway during an incident I directed. A four-year DLP programme tied into Cisco ISE, Palo Alto and the WAF, mapping server classifications to data classifications.
Palo Alto NGFWGlobalProtectPanoramaArbor DDoSCisco ISEDLPElastic
Remote users Arbor DDoSscrubbing iPOP 1 · GP gateway iPOP 2 · GP gateway iPOP n · GP gateway Core NGFW SSL decryption Threat prevention URL filtering · PBF Panoramacentral policy Elastic · Kibanalive monitoring policy push logs
Authentication: RADIUS, LDAP and certificates. Every gateway runs the same Panorama-managed policy.
OTY Armoires et Comptoirs de Cuisine2021 – 2023Security operations · IoT

Continuous monitoring & secure connected products

Context
Monitoring was periodic and manual, and the company was bringing IoT technology into its smart furniture line.
Decision
Rebuild continuous monitoring on ACAS, SCAP and STIG baselines, and deploy host-based security (policy auditing, data loss prevention and rogue system detection) enterprise-wide. IoT features follow the same secure-by-design standards.
Outcome
Vulnerabilities are found, tracked and fixed across the SDLC against advisory alerts, with one security standard for both IT and connected products.
ACASSCAPSTIGDLPIoT
BaselineSCAP · STIG ScanACAS · agents Analyzeadvisories Remediatepatch · verify continuous · every change re-baselined Host-based security · DLP · rogue detection
The monitoring loop runs continuously instead of on a quarterly schedule.

Project portfolio

Programs I've led and delivered

Each entry shows the scope, my role, the delivery approach and the result. Where I don't have a verified figure, the result is described rather than quantified.

Experience

Career path

From service desk leadership in the Philippines to defence, industrial and financial-services architecture in Canada.

Aug 2026 – Present

Information Technology Architect

Weir Marine Engineering · Naval Engineering Test Establishment (NETE)
  • Functional System-of-Systems architecture for a naval management system, down to low-level physical and logical design
  • Owner of the IDAM architecture: afloat/shore identity flows, authentication brokering, privileged access
  • Domain isolation and controlled transfer; security assessment & authorization; land-based test and validation
Apr 2023 – Jul 2026

Systems & IT Infrastructure Architect

IPEX Group of Companies Inc.
  • ICS and enterprise zero trust architecture; identity, access and control architecture model
  • ISA/IEC 62443, NIST and ITIL framework with a 70% risk reduction in North America
  • Chaired the Architectural Review Board; secure vendor access, MES and hybrid data-centre redesign
Mar 2021 – Apr 2023 · Contract

Infrastructure Security & Cloud Computing Director

Phoenix-Loureiroi Imports
  • Led a team of Security, DevOps and Cloud engineers
  • Designed the Azure AD identity and access framework and the Azure hosting integration
  • ITSM/ITIL process governance on ServiceNow
Oct 2021 – Apr 2023 · Contract

Director of Cloud Computing Security Architecture

OTY Armoires et Comptoirs de Cuisine Inc.
  • On-premises and cloud architecture, and IoT integration for smart furniture
  • Rebuilt continuous monitoring on ACAS, SCAP and STIG
Jul 2016 – Sep 2021

Enterprise Architecture Board · Senior Security Advisor · Security Analyst II

Intact Financial Corporation
  • Enterprise Architecture Board (2018–2021): security standards and principles, founded the ECBR committee
  • Senior Security Advisor (2017–2021): DLP programme, honeypot, Palo Alto zero trust and GlobalProtect, Q4 2020 DDoS response
  • Security Analyst II (2016–2017): 100+ firewalls, 800–900+ changes a year, Cisco ISE, IronPort, WAF and SSL certificate SME
Jun 2014 – Dec 2018

Support Network Technician

Gestion Crepaldi Inc.
Feb 2014 – Apr 2016

Customer Service & first-line IT support

The UPS Store · Copies Concordia, Montréal
Jun 2009 – Sep 2011

Service Desk Manager · Team Coordinator

Fujitsu, Philippines
Mar 2007 – Jun 2009

Technical IT Manager · Technician Team Leader

PC Express, Philippines

Certifications

  • Project Management Professional (PMP)PMI · 2026
  • Certified Information Security Manager (CISM)ISACA · 2024
  • TOGAF Enterprise Architecture Foundation 9.2LinkedIn Learning
  • Cisco Certified Network Associate (CCNA)2016
  • Cyber Security of Computer NetworksPolytechnique Montréal · 2021
  • Certified Web Application Security Tester (C-WAST)2022
  • Expert Malware Analysis & Reverse Engineering2022
  • Computer Forensics ExpertE-Hacking · 2022
  • Securing Networks with Cisco Firepower NGFWCisco · 2017
  • Defending Against & Deploying Arbor Networks APSArbor · 2017
  • Troubleshooting TCP/IP Networks with Wireshark2016
  • Information Technology Programming NC IVSTI · 2010

Toolkit

Security platforms

Palo Alto NGFWPrisma AccessCortex XDRCyberArkCisco FTD / ASACisco ISEIronPortUmbrellaCheck PointJuniper SRXArborBarracuda WAFForcepoint

Assessment & testing

Kali LinuxMetasploitBurp SuiteNmapWiresharkOpenVASNexpose

Cloud & infrastructure

AzureAzure ADIntuneM365Dell EMC HCIVMware ESXiHyper-VRHEL / LinuxCitrixNAS / SAN

Automation & observability

TerraformAzure ARMGitHubElastic / KibanaPythonServiceNow

OT applications

Studio 5000Siemens TIA PortalFANUCMESSCADA

Methods

Agile / ScrumWaterfallHybridLeanThreat modelingProcess mapping

Languages

English · fluentFrançais · courant

Contact

Let's talk architecture

Reach me about IT and security architecture, speaking and advisory work, in English or French.

Email john@colet.ca
Open mail app
Phone (438) 521-6418

Based in Montréal, QC

Available for on-site, hybrid or remote work across Canada and North America.

Cybersecurity resources

Reference library

555 links in 54 categories: the standards, frameworks, controls, threat intelligence and training material I use for architecture and security work. Every link opens the original source in a new tab. ★ marks a key reference.

Collection adapted from the public “Cybersecurity Resources” start page by Alexandre Bélanger, CISSP.