I design, build and secure the platforms that keep high-traffic businesses online — from multi-account AWS architectures and CI/CD pipelines to hardened Linux fleets, SIEM-driven security operations and audit-ready compliance.
I'm a certified System & Cloud Engineer, currently working as a Senior Linux System Administrator with Constellation Software Inc. (Canada, remote), after more than five years leading systems, network and cloud engineering at Simplex Technology Solutions. My work sits at the intersection of infrastructure and reliability: I architect AWS environments that carry the e-commerce, mobile-app and CMS workloads of some of the busiest food-service brands in Pakistan and the Gulf — platforms where a slow page or an outage translates directly into lost orders.
My career started on the wire. For my first three years I was a network engineer at eConceptions, a vendor serving Pakistan's telecom sector — Telenor, Jazz, Zong, Ufone and Warid — installing and deploying servers in data centers and engineering the connectivity between client data centers, our facilities and offices. That telco-grade networking discipline still shapes how I design everything today.
From there the stack kept growing: Linux system administration, VMware virtualization, media streaming platforms, banking infrastructure, AWS cloud architecture and DevOps — and in recent years security engineering and GRC: remediating full security audits, building SIEM-driven monitoring, tuning WAFs and designing encrypted, compliance-ready backup and disaster-recovery strategies. I like problems that span the whole stack, and I document everything I build so teams can run it without me.
SIEM engineering and security operations for a global software group: architected a production Wazuh 4.x platform with a custom Python alert-notification framework (Slack, Teams, PagerDuty, HTML email with dashboard deep links), administered the OpenSearch cluster behind it, upgraded Zabbix to 7.4, deployed CrowdStrike Falcon and New Relic fleet-wide via Ansible, and built AWS site-to-site VPN infrastructure with Terraform — across RHEL, AlmaLinux, Oracle Linux and Windows Server estates.
Architected and operated the AWS platforms behind KFC, Domino's, Pizza Hut and other high-traffic brands — cloud architecture, CI/CD, security engineering, GRC audit remediation and team leadership.
Enterprise Linux estates (LVM, KVM, SELinux), Nginx/FFmpeg live-streaming stacks (HLS/RTMP, multi-bitrate, DVR), VMware HA clusters, and multi-vendor networks: Juniper SRX, Cisco ASA, F5 BIG-IP, MikroTik and pfSense with BGP/OSPF routing.
Wowza streaming platform operations — live transcoding, adaptive bitrates, GEO blocking — plus Docker/Kubernetes for live-stream workloads, VMware primary + DR site design, and SolarWinds/Zabbix monitoring.
Production infrastructure in a regulated banking environment — Linux servers, Sybase applications, Oracle Exadata monitoring, hardened production security with iptables/SELinux, and DR instance management.
Server installation and deployment in data centers, and network connectivity engineering between client and provider facilities for Pakistan's major telecom operators: Telenor, Jazz, Zong, Ufone and Warid.
Company-wide LAN/WAN, SAP/Oracle ERP server support, RHEL/CentOS, pfSense firewall and mail server administration.
I architect and operate production AWS environments end-to-end for high-traffic e-commerce and food-tech platforms: VPC design with public/private subnet tiers, Application Load Balancers, Auto Scaling Groups, RDS, CloudFront, Route 53, ACM and WAF — engineered for availability during peak ordering hours and promotion spikes.
I've built centralized governance across a multi-account AWS Organization — organization-wide CloudTrail, IAM Identity Center (SSO) with Active Directory integration, service control policies, and cross-account, cross-region S3 replication pipelines (Singapore ⇄ Ireland) with custom KMS encryption architectures for durability and disaster recovery.
Cloud spend is an architecture signal. I've investigated and remediated real cost anomalies — tracing them from billing dashboards down to uncompressed asset delivery and misconfigured caching at the web tier — and turned the findings into permanent platform improvements.
I design infrastructure that spans cloud and on-premises cleanly: VMware vSphere/ESXi estates with HA/DRS and snapshot policies running alongside AWS workloads, connected through VPNs and consistent identity, monitoring and backup layers so operations feel like one platform.
RHEL, CentOS and Ubuntu fleets — provisioned, hardened, tuned and patched at scale. From kernel and storage-level fixes (like resolving boot failures caused by device-path fstab entries on NVMe instance reboots) to database server care for MariaDB and PostgreSQL, including disk-bloat reclamation on production systems.
Every design starts from the question "what happens when this dies?" — redundant tiers, tested restore procedures, RTO/RPO-aligned backup strategies and disaster-recovery drills, not just diagrams that look good in a slide deck.
I spent the first three years of my career as a network engineer serving Pakistan's telecom sector — Telenor, Jazz, Zong, Ufone and Warid — deploying servers into data centers and engineering the connectivity between client data centers, provider facilities and offices. When the network is carrier infrastructure, "mostly working" isn't a state that exists.
That foundation runs deep: multi-vendor routing and switching across Cisco ASA, Juniper SRX, F5 BIG-IP, MikroTik and pfSense, with BGP, OSPF, HSRP/VRRP, VLANs, trunking and IPSec — extended into cloud-native constructs: VPC topologies, security groups and NACLs, Transit Gateway patterns for cross-account connectivity, and Client VPN for secure operator access.
I've executed production DNS migrations and operate Route 53 and Cloudflare at the edge — including solving real-world ISP routing failures for production subdomains by re-architecting proxy and DNS behaviour, and pairing CloudFront with tuned origin caching for global delivery.
Network design is the first security control. I design tiered, least-privilege network paths where databases, admin planes and public workloads live in deliberately separate zones with auditable traffic flows.
I run the infrastructure behind e-commerce storefronts, CMS/CRM systems, mobile-app backends, call-center integrations and secure banking/SMS gateway interfaces — NestJS and React/Next.js stacks alongside classic LAMP/LEMP, with per-client isolation on shared staging environments.
Nginx is my instrument: reverse proxying, TLS termination, compression, caching, security headers and structured logging. I've measurably improved asset delivery for national-scale ordering platforms by fixing compression and cache behaviour at the origin.
Earlier in my career I ran video streaming platforms end-to-end: Wowza and Nginx/FFmpeg pipelines delivering HLS and RTMP with multi-bitrate transcoding, live DVR rewind, GEO blocking and API-driven feed monitoring — infrastructure where a dropped frame is immediately visible to thousands of viewers.
Payment callbacks, SMS gateways and third-party APIs fail in subtle ways. I debug them at the protocol level — logs, headers, TLS, upstream behaviour — and design logging so the next failure is diagnosed in minutes, not days.
I've built production Jenkins CI/CD platforms from bare metal up — integrated with SonarQube quality gates and Bitbucket Cloud for NestJS and React/Next.js applications, deploying through dev, staging and production with per-client isolation and rollback paths.
▸ Read the full build log — 7-part CI/CD pipeline series in my Knowledge BaseAnsible playbooks (certified EX294) and reusable Terraform modules for repeatable provisioning across accounts and regions — including a complete AWS site-to-site IPSec VPN (Customer Gateway, Virtual Private Gateway, routing) built entirely as code, and fleet-wide agent rollouts (Wazuh, Zabbix, New Relic, CrowdStrike) across Linux and Windows Server environments. This discipline has cut manual provisioning effort by more than 60% and eliminated configuration drift as a class of incident.
The best automation removes both toil and human error: automated AMI baking for Auto Scaling fleets, scheduled encrypted backups, alert-driven remediation and self-documenting deployment workflows.
My Bash tooling is written for the 3 a.m. failure case: strict error handling, locking, logging, alerting on failure and idempotent re-runs. Example: a backup system streaming zstd-compressed, AES-256-encrypted MariaDB backups directly to S3 — hardened iteratively through real restore failures on 100 GB+ production-scale datasets until restores were boring.
Beyond Bash, I build production Python tooling: a custom SIEM alert-notification framework with REST API integrations (Wazuh, OpenSearch), severity-based routing, duplicate suppression, structured logging and dynamically generated dashboard deep links — turning raw security events into one-click investigations.
Cron orchestration, log parsing and rotation, certificate automation, health checks, AWS CLI workflows, database maintenance jobs — the connective tissue that makes a platform self-operating.
When a recurring Zabbix flush-latency alert hit a production 8-node Elasticsearch cluster, I turned the manual investigation into a reusable, version-adaptive Bash/jq tool — it auto-discovers topology, detects the ES version live, classifies nodes from real-time data, and generates a single readable incident report. That same investigation later root-caused a JVM heap OOM outage and drove a zero-data-loss, one-node-at-a-time remediation across the whole cluster.
▸ Read the full incident series — 6-part Elasticsearch troubleshooting log in my Knowledge BaseA backup script that has never restored anything is a hypothesis. Every recovery tool I ship is validated against real production clones before it's trusted.
I run Wazuh as a centralized SIEM across Linux and Windows fleets — and I engineer it: custom detection rules tuned against false positives, File Integrity Monitoring, vulnerability detection and Security Configuration Assessment, MITRE ATT&CK-aligned reporting, and a custom Python alert framework with team-based routing, deduplication and HTML notifications that deep-link straight to the exact alert in the dashboard. I also administer the OpenSearch clusters underneath — index templates, shard allocation and cluster-health recovery included.
The SIEM layer sits alongside cloud-native detection — GuardDuty, organization-wide CloudTrail, CloudWatch metric filters and EventBridge/SNS alerting — plus endpoint protection with CrowdStrike Falcon deployed fleet-wide through Ansible, and deep-dive analysis of external vulnerability-scan traffic (QualysGuard) to keep defenses ahead of what attackers actually probe.
SSH and PAM hardening, Fail2Ban, auditd, SELinux/AppArmor, TLS configuration and Nginx access controls — applied systematically across production fleets and verified against penetration-test findings, not just checklists.
▸ Read my method for hardening live production servers to audit standard — without taking them downManaged WAF rules block attackers and, badly tuned, legitimate users. I've run false-positive investigations on production AWS WAF deployments, isolating the exact managed rule responsible and designing scoped, label-matched overrides so protection stays on where it matters. I also work with Nuclei for template-driven vulnerability scanning and deployed a self-hosted Passbolt password manager for team credential security.
I've taken a full third-party security audit — thirteen findings across SSH, PAM, Fail2Ban, auditd, TLS permissions and web-server access controls — and systematically remediated every one on production infrastructure, with evidence the auditor could verify. I work directly with GRC auditors and translate their requirements into engineering.
Organization-wide CloudTrail, service control policies, IAM role-based access with SSO, KMS-encrypted data at rest and lifecycle-governed retention: controls that are enforced by architecture rather than by policy documents alone. My banking-sector background (regulated environment administration, DR drills) shaped this discipline early.
I produce team-ready documentation — architecture wikis, runbooks, security training. I built and delivered an internal OWASP Top 10 training program complete with hands-on vulnerable-application labs for developer teams.
A sample of recent engagements across the platforms I operate. Client specifics available on request.
Traced a sudden cloud-spend spike to uncompressed, uncached asset delivery at the web tier. Re-engineered Nginx compression, caching and security headers across multiple client platforms and fixed the root cause in the scaling pipeline.
Replaced daily full database dumps with a weekly-full + daily-incremental strategy: zstd-compressed, AES-256-encrypted streams direct to S3 with tag-filtered lifecycle policies — validated by full restores on a 100 GB+ production clone. Also replaced a dangerous pre-existing S3 lifecycle rule before it could destroy data.
Designed and deployed a production Jenkins platform integrated with SonarQube quality gates and Bitbucket Cloud for NestJS and React/Next.js stacks, plus a multi-tenant staging environment with per-client Linux user isolation. Full 7-part build log →
Built an organization-wide detection stack — CloudTrail, CloudWatch metric filters, EventBridge, SNS alerting and GuardDuty — centralizing security events from a multi-account, multi-region AWS organization into one operational view.
Systematically closed all thirteen findings from a third-party penetration-test/GRC audit — SSH, PAM, Fail2Ban, auditd, TLS and web-server access controls — across production infrastructure, with auditor-verifiable evidence.
Engineered a production Wazuh 4.x deployment into a full alerting platform: a custom Python notification framework with team-based routing, deduplication, and HTML emails deep-linking to the exact dashboard alert — integrated with Slack, Teams and PagerDuty. Also resolved OpenSearch shard-limit exhaustion to restore reliable alert indexing.
Designed and deployed a route-based IPSec site-to-site VPN between AWS VPC networks and physical corporate firewalls — Customer Gateways, Virtual Private Gateways and routing built entirely as reusable Terraform modules. Paired with a cross-account, cross-region S3 replication pipeline (Singapore ⇄ Ireland) using custom KMS encryption. I also codified a complete Layer 3 application architecture — VPC, WAF, ALB, Auto Scaling and MariaDB — as a validated, modular Terraform project. See the full Layer 3 Terraform build →
Production WAF was blocking legitimate CMS operations. Isolated the exact managed rule responsible, applied a safe interim override and designed a label-matched rule to scope the exception to admin paths only — keeping protection fully active for public traffic.
Infrastructure and platform engineering delivered for leading food-service and retail brands across Pakistan, the Gulf and Africa.
Delivered through Zaryans and DMD Max. Brand names are used descriptively to indicate the platforms supported; no endorsement or official affiliation is implied.