About

I'm a cloud native DevOps / DevSecOps engineer working where infrastructure automation meets security enforcement.

For 4+ years I've built and run cloud and Linux infrastructure across AWS and Azure — Terraform and Ansible, CI/CD pipelines, Kubernetes, monitoring. My work has since narrowed to the security end of that: controls at fleet scale that enforce themselves rather than living in a wiki.

My belief is simple: default-deny with an explicit, reviewable allowlist — whether that's an iptables chain, a Kubernetes admission webhook, or a service mesh authorization policy. Same discipline, different layer of the stack. I care about controls that can be verified, not just asserted, which is why the systems I build carry their own backups, validation and rollback.

In production today

I lead a centralised Firewall Automation & Governance platform that compiles per-host firewall policy from a single source of truth, applies it safely, and revokes it automatically — cutting large-scale deployment time by . One-off access grants carry an expiry timestamp and simply stop being emitted, rather than depending on somebody remembering to revoke them.

A lot of the job, though, is keeping existing production alive: diagnosing fleet-wide outages down to their true root cause, and replacing silent failures with fail-loud deployment tooling — checksum-verified installs and smoke tests that break at install time instead of in front of a user.

Further up the stack

That firewall work is policy-as-code at the kernel layer. Increasingly I apply the same discipline higher up: Kubernetes admission control, Istio authorization and mTLS, signed container supply chains, and OPA policy gating Terraform plans.

Background

I came into this deliberately. Before DevOps I taught computer science and worked in audit — backgrounds that shaped how I work: I explain systems simply, and I don't trust a change until it's proven.

My hands-on path into the field started in 2021 on a freelance project team, where I owned Git-based version control and worked with AWS and Linux alongside that audit role. I've been in full-time DevOps roles since 2023.

BS Computer Science, University of Karachi. AWS Solutions Architect – Associate in progress. Based in Karachi, Pakistan, working remotely.

Currently going deeper on

Policy-as-code across IaC and Kubernetes, supply chain integrity, and cloud-to-cluster workload identity. Working toward CKA, then CKS.

Stack

Cloud
AWS (EC2, EKS, VPC, IAM, CloudTrail, Lambda, S3, MGN), Azure (AKS, VMs, Functions, Site Recovery), Alibaba Cloud
Containers
Docker, Kubernetes, Helm, Kustomize, Istio / service mesh, EKS / AKS
IaC & Config
Terraform, Ansible (roles, playbooks, inventories)
CI/CD & GitOps
GitHub Actions, GitLab CI, Jenkins, Tekton, ArgoCD
Security
iptables / IPSets automation, CIS hardening, fail2ban, WAF (Cloudflare, AWS), SSL/TLS, ACME / Let's Encrypt (certbot) and certificate lifecycle, HashiCorp Vault, AWS Secrets Manager
Networking
Load balancing (ALB / NLB, Nginx / HAProxy), reverse proxy, BIND / authoritative DNS and zone management, VPC, TCP/IP, subnetting
Databases
MySQL (GTID replication, backup and verified restore), PostgreSQL
Observability
Prometheus, Grafana, Loki, Alertmanager, Zabbix
Languages
Python, Bash, TypeScript; FastAPI, Flask

If you need someone who can automate security across a Linux fleet or a Kubernetes cluster — and prove it holds — let's talk.

I write up what I build, including what didn't work. See the projects →

⬇ Download résumé (PDF)