About
I'm a cloud native DevOps / DevSecOps engineer working where infrastructure automation meets security enforcement.
For 4+ years I've built and run cloud and Linux infrastructure across AWS and Azure — Terraform and Ansible, CI/CD pipelines, Kubernetes, monitoring. My work has since narrowed to the security end of that: controls at fleet scale that enforce themselves rather than living in a wiki.
My belief is simple: default-deny with an explicit, reviewable allowlist — whether that's an iptables chain, a Kubernetes admission webhook, or a service mesh authorization policy. Same discipline, different layer of the stack. I care about controls that can be verified, not just asserted, which is why the systems I build carry their own backups, validation and rollback.
In production today
I lead a centralised Firewall Automation & Governance platform that compiles per-host firewall policy from a single source of truth, applies it safely, and revokes it automatically — cutting large-scale deployment time by 3×. One-off access grants carry an expiry timestamp and simply stop being emitted, rather than depending on somebody remembering to revoke them.
A lot of the job, though, is keeping existing production alive: diagnosing fleet-wide outages down to their true root cause, and replacing silent failures with fail-loud deployment tooling — checksum-verified installs and smoke tests that break at install time instead of in front of a user.
Further up the stack
That firewall work is policy-as-code at the kernel layer. Increasingly I apply the same discipline higher up: Kubernetes admission control, Istio authorization and mTLS, signed container supply chains, and OPA policy gating Terraform plans.
Background
I came into this deliberately. Before DevOps I taught computer science and worked in audit — backgrounds that shaped how I work: I explain systems simply, and I don't trust a change until it's proven.
My hands-on path into the field started in 2021 on a freelance project team, where I owned Git-based version control and worked with AWS and Linux alongside that audit role. I've been in full-time DevOps roles since 2023.
BS Computer Science, University of Karachi. AWS Solutions Architect – Associate in progress. Based in Karachi, Pakistan, working remotely.
Currently going deeper on
Policy-as-code across IaC and Kubernetes, supply chain integrity, and cloud-to-cluster workload identity. Working toward CKA, then CKS.
Stack
- Cloud
- AWS (EC2, EKS, VPC, IAM, CloudTrail, Lambda, S3, MGN), Azure (AKS, VMs, Functions, Site Recovery), Alibaba Cloud
- Containers
- Docker, Kubernetes, Helm, Kustomize, Istio / service mesh, EKS / AKS
- IaC & Config
- Terraform, Ansible (roles, playbooks, inventories)
- CI/CD & GitOps
- GitHub Actions, GitLab CI, Jenkins, Tekton, ArgoCD
- Security
- iptables / IPSets automation, CIS hardening, fail2ban, WAF (Cloudflare, AWS), SSL/TLS, ACME / Let's Encrypt (certbot) and certificate lifecycle, HashiCorp Vault, AWS Secrets Manager
- Networking
- Load balancing (ALB / NLB, Nginx / HAProxy), reverse proxy, BIND / authoritative DNS and zone management, VPC, TCP/IP, subnetting
- Databases
- MySQL (GTID replication, backup and verified restore), PostgreSQL
- Observability
- Prometheus, Grafana, Loki, Alertmanager, Zabbix
- Languages
- Python, Bash, TypeScript; FastAPI, Flask
If you need someone who can automate security across a Linux fleet or a Kubernetes cluster — and prove it holds — let's talk.
I write up what I build, including what didn't work. See the projects →
- Email syed.amjad.hashmi@gmail.com
- LinkedIn Connect on LinkedIn
- GitHub View my repositories
- Location Karachi, Pakistan — working remotely, usually replying within a day