About
I'm a cloud native security engineer working at the point where infrastructure automation meets security enforcement.
Most of my production experience is in infrastructure security at fleet scale. I built and operate an automated network access control system for a production server estate — it compiles per-host firewall policy from a central source of truth, implements a role-tiered access model, and supports time-boxed exceptions that expire automatically rather than depending on someone remembering to revoke them.
That work is policy-as-code, just at the kernel layer. Increasingly I apply the same discipline further up the stack: Kubernetes admission control, Istio authorization and mTLS, signed container supply chains, and OPA policy gating Terraform plans.
The through-line is default-deny with an explicit, reviewable allowlist — whether that's an iptables chain, a Kubernetes admission webhook, or a service mesh authorization policy.
Background
Four years in DevOps and DevSecOps, currently designing a centralised firewall automation and governance platform. Before infrastructure I taught computer science and worked in audit — an unusual route in, but it left me with two habits that turned out to matter: explaining technical things clearly, and caring whether a control can actually be evidenced.
BS Computer Science, University of Karachi. AWS Solutions Architect – Associate in progress. Based in Karachi, Pakistan, working remotely.
Currently going deeper on
Policy-as-code across IaC and Kubernetes, supply chain integrity, and cloud-to-cluster workload identity. Working toward CKA, then CKS.
Stack
- Cloud
- AWS (EC2, EKS, VPC, IAM, CloudTrail, Lambda, S3, MGN), Azure (AKS, VMs, Functions, Site Recovery), Alibaba Cloud
- Containers
- Docker, Kubernetes, Helm, Kustomize, Istio / service mesh, EKS / AKS
- IaC & Config
- Terraform, Ansible (roles, playbooks, inventories)
- CI/CD & GitOps
- GitHub Actions, GitLab CI, Jenkins, Tekton, ArgoCD
- Security
- iptables / IPSets automation, CIS hardening, fail2ban, WAF (Cloudflare, AWS), SSL/TLS, HashiCorp Vault, AWS Secrets Manager
- Observability
- Prometheus, Grafana, Loki, Alertmanager, Zabbix
- Languages
- Python, Bash, TypeScript; FastAPI, Flask
I write up what I build, including what didn't work. See the projects →