About

I'm a cloud native security engineer working at the point where infrastructure automation meets security enforcement.

Most of my production experience is in infrastructure security at fleet scale. I built and operate an automated network access control system for a production server estate — it compiles per-host firewall policy from a central source of truth, implements a role-tiered access model, and supports time-boxed exceptions that expire automatically rather than depending on someone remembering to revoke them.

That work is policy-as-code, just at the kernel layer. Increasingly I apply the same discipline further up the stack: Kubernetes admission control, Istio authorization and mTLS, signed container supply chains, and OPA policy gating Terraform plans.

The through-line is default-deny with an explicit, reviewable allowlist — whether that's an iptables chain, a Kubernetes admission webhook, or a service mesh authorization policy.

Background

Four years in DevOps and DevSecOps, currently designing a centralised firewall automation and governance platform. Before infrastructure I taught computer science and worked in audit — an unusual route in, but it left me with two habits that turned out to matter: explaining technical things clearly, and caring whether a control can actually be evidenced.

BS Computer Science, University of Karachi. AWS Solutions Architect – Associate in progress. Based in Karachi, Pakistan, working remotely.

Currently going deeper on

Policy-as-code across IaC and Kubernetes, supply chain integrity, and cloud-to-cluster workload identity. Working toward CKA, then CKS.

Stack

Cloud
AWS (EC2, EKS, VPC, IAM, CloudTrail, Lambda, S3, MGN), Azure (AKS, VMs, Functions, Site Recovery), Alibaba Cloud
Containers
Docker, Kubernetes, Helm, Kustomize, Istio / service mesh, EKS / AKS
IaC & Config
Terraform, Ansible (roles, playbooks, inventories)
CI/CD & GitOps
GitHub Actions, GitLab CI, Jenkins, Tekton, ArgoCD
Security
iptables / IPSets automation, CIS hardening, fail2ban, WAF (Cloudflare, AWS), SSL/TLS, HashiCorp Vault, AWS Secrets Manager
Observability
Prometheus, Grafana, Loki, Alertmanager, Zabbix
Languages
Python, Bash, TypeScript; FastAPI, Flask

I write up what I build, including what didn't work. See the projects →