to be honest I do not see "problem" in a first place.
Good network design consist usually of many moving parts and question-answer steps.
Like are those HQ and overseas locations supposed to interact? If so then how? Are those overseas locations just few branches or road-warrior employees everyone with his own NTB? How they are supposed to authenticate to corporate resources, is it single domain, AD perhaps? If so how they will be authorized, some FSSO, SSOMA or ZTNA applied?
Split those EMS is good also for possible redundancy. But how they sync?
Therefore it seems to me more like brainstorming project, than anything which could be solved by one answer on some forum.
Tom xSilver, planet Earth, over and out!