Infrastructure · Cloud · Security · GRC

Muhammad Qasim

Linux System & Cloud Engineer — Infrastructure Design & Cloud Architecture

I design, build and secure the platforms that keep high-traffic businesses online — from multi-account AWS architectures and CI/CD pipelines to hardened Linux fleets, SIEM-driven security operations and audit-ready compliance.

14+
Years experience
12+
Enterprise brands served
99.9%
Uptime-focused design
7
Industry certifications
454/689 0011011 101101
// About

Fourteen years keeping critical platforms fast, secure and online

Muhammad Qasim
muhammad qasim · linux · cloud · security

I'm a certified System & Cloud Engineer, currently working as a Senior Linux System Administrator with Constellation Software Inc. (Canada, remote), after more than five years leading systems, network and cloud engineering at Simplex Technology Solutions. My work sits at the intersection of infrastructure and reliability: I architect AWS environments that carry the e-commerce, mobile-app and CMS workloads of some of the busiest food-service brands in Pakistan and the Gulf — platforms where a slow page or an outage translates directly into lost orders.

My career started on the wire. For my first three years I was a network engineer at eConceptions, a vendor serving Pakistan's telecom sector — Telenor, Jazz, Zong, Ufone and Warid — installing and deploying servers in data centers and engineering the connectivity between client data centers, our facilities and offices. That telco-grade networking discipline still shapes how I design everything today.

From there the stack kept growing: Linux system administration, VMware virtualization, media streaming platforms, banking infrastructure, AWS cloud architecture and DevOps — and in recent years security engineering and GRC: remediating full security audits, building SIEM-driven monitoring, tuning WAFs and designing encrypted, compliance-ready backup and disaster-recovery strategies. I like problems that span the whole stack, and I document everything I build so teams can run it without me.

// Career

Fourteen years, seven organizations, one trajectory

DEC 2021 — PRESENT · REMOTE (CANADA)

Senior Linux System Administrator

Constellation Software Inc. — Greater Toronto Area

SIEM engineering and security operations for a global software group: architected a production Wazuh 4.x platform with a custom Python alert-notification framework (Slack, Teams, PagerDuty, HTML email with dashboard deep links), administered the OpenSearch cluster behind it, upgraded Zabbix to 7.4, deployed CrowdStrike Falcon and New Relic fleet-wide via Ansible, and built AWS site-to-site VPN infrastructure with Terraform — across RHEL, AlmaLinux, Oracle Linux and Windows Server estates.

BashAnsiblePythonTerraformWazuhOpenSearchZabbixCrowdStrikeNew RelicPagerDutyVMware / VeeamActive Directory / GPONginx / ApacheMariaDB / MySQLiptables / UFW
OCT 2020 — MAY 2026 · ISLAMABAD

Linux System & Cloud Lead → System Lead

Simplex Technology Solutions

Architected and operated the AWS platforms behind KFC, Domino's, Pizza Hut and other high-traffic brands — cloud architecture, CI/CD, security engineering, GRC audit remediation and team leadership.

AWS (EC2 / S3 / RDS / VPC)ALB / Auto ScalingWAF / CloudFrontIAM / SSOJenkins / SonarQubeAnsibleDocker / KubernetesNginxMariaDBWazuh / GuardDutyVMwareZabbix / New RelicGRC complianceTeam leadership
MAR 2018 — JUL 2021 · ISLAMABAD

System & Network Manager

Zaryans Consulting (Pvt.) Ltd.

Enterprise Linux estates (LVM, KVM, SELinux), Nginx/FFmpeg live-streaming stacks (HLS/RTMP, multi-bitrate, DVR), VMware HA clusters, and multi-vendor networks: Juniper SRX, Cisco ASA, F5 BIG-IP, MikroTik and pfSense with BGP/OSPF routing.

RHEL / CentOSLVM / KVMSELinux / firewalldApache / Tomcat / NginxFFmpeg / HLS / RTMPVMware ESXi / vCenterHA / vMotionJuniper SRXCisco ASAF5 BIG-IPMikroTik / pfSenseBGP / OSPF / STPiSCSI / HP SAN
JUL 2016 — MAR 2018 · ISLAMABAD

System & Network Engineer

Digital Media Distribution Max

Wowza streaming platform operations — live transcoding, adaptive bitrates, GEO blocking — plus Docker/Kubernetes for live-stream workloads, VMware primary + DR site design, and SolarWinds/Zabbix monitoring.

WowzaLive transcodingAdaptive bitrateGEO blockingDocker / KubernetesVMware HA / DRSDR site designSolarWindsZabbixSAN securityProject leadership
DEC 2015 — JUL 2016 · ISLAMABAD

Senior Officer IT Infrastructure

U Microfinance Bank Limited

Production infrastructure in a regulated banking environment — Linux servers, Sybase applications, Oracle Exadata monitoring, hardened production security with iptables/SELinux, and DR instance management.

Linux serversSybaseOracle ExadataLAMPNFS / Sambaiptables / SELinuxBackup verificationDR managementVendor coordination
JAN 2013 — NOV 2015 · ISLAMABAD

Systems & Network Engineer

eConceptions — telecom sector vendor

Server installation and deployment in data centers, and network connectivity engineering between client and provider facilities for Pakistan's major telecom operators: Telenor, Jazz, Zong, Ufone and Warid.

Linux administrationLAN / WAN designNetwork securityData-center deploymentVMwareAWS (early adoption)Bash scriptingBackup / DRDocumentation
DEC 2012 — MAY 2013 · RAWALPINDI

System Administrator

Dawn Bread

Company-wide LAN/WAN, SAP/Oracle ERP server support, RHEL/CentOS, pfSense firewall and mail server administration.

LAN / WANSAP / Oracle ERP supportRHEL 5-6 / CentOS 5pfSenseMail serverCCTV systemsEnd-user support
01 / EXPERTISE Cloud Design & Management aws · multi-account · multi-region · high availability · cost engineering

Architecture that carries real traffic

I architect and operate production AWS environments end-to-end for high-traffic e-commerce and food-tech platforms: VPC design with public/private subnet tiers, Application Load Balancers, Auto Scaling Groups, RDS, CloudFront, Route 53, ACM and WAF — engineered for availability during peak ordering hours and promotion spikes.

Cloud · Reference Architecture
Layer 3 Architecture — WAF, ELB & Auto Scaling
A real production pattern: WAF → ALB (80/443) → auto-scaling app tier (443) → MariaDB (3306), with S3, monitoring and alerting. Every tier boundary is a security group.
See the full architecture & Terraform in my Knowledge Base
Explore the full AWS architecture & service-by-service reference in my Knowledge Base See this exact architecture built as validated, modular Terraform — VPC, app tier & database
Cloud · Visual Explainer
Public vs Private vs Hybrid Subnets
The servers are identical — only the route table makes a subnet public, private, or hybrid.
View the breakdown in my Knowledge Base

Multi-account & multi-region by design

I've built centralized governance across a multi-account AWS Organization — organization-wide CloudTrail, IAM Identity Center (SSO) with Active Directory integration, service control policies, and cross-account, cross-region S3 replication pipelines (Singapore ⇄ Ireland) with custom KMS encryption architectures for durability and disaster recovery.

Cloud · Visual Explainer
S3 Storage Classes & Lifecycle
Data has a temperature — how lifecycle policies move it from hot to cold as it ages, and the cost trade-off behind each tier.
View the breakdown in my Knowledge Base

Cost as an engineering discipline

Cloud spend is an architecture signal. I've investigated and remediated real cost anomalies — tracing them from billing dashboards down to uncompressed asset delivery and misconfigured caching at the web tier — and turned the findings into permanent platform improvements.

Cloud · Visual Explainer
How Auto Scaling Actually Works
The five-link chain from a CPU spike to a new healthy server — and where 'auto' scaling silently stops being automatic.
View the breakdown in my Knowledge Base
02 / EXPERTISE Infrastructure Design hybrid cloud · virtualization · linux fleets · high availability · DR

Hybrid, not either/or

I design infrastructure that spans cloud and on-premises cleanly: VMware vSphere/ESXi estates with HA/DRS and snapshot policies running alongside AWS workloads, connected through VPNs and consistent identity, monitoring and backup layers so operations feel like one platform.

Infrastructure · Visual Explainer
Bare Metal vs VM vs Container
Three ways to run the same application, defined by what gets shared — hardware, OS, or kernel.
View the breakdown in my Knowledge Base

Linux at the core

RHEL, CentOS and Ubuntu fleets — provisioned, hardened, tuned and patched at scale. From kernel and storage-level fixes (like resolving boot failures caused by device-path fstab entries on NVMe instance reboots) to database server care for MariaDB and PostgreSQL, including disk-bloat reclamation on production systems.

Built to survive failure

Every design starts from the question "what happens when this dies?" — redundant tiers, tested restore procedures, RTO/RPO-aligned backup strategies and disaster-recovery drills, not just diagrams that look good in a slide deck.

03 / EXPERTISE Network Design routing · segmentation · VPN · DNS · edge & CDN

Roots in telecom-grade networking

I spent the first three years of my career as a network engineer serving Pakistan's telecom sector — Telenor, Jazz, Zong, Ufone and Warid — deploying servers into data centers and engineering the connectivity between client data centers, provider facilities and offices. When the network is carrier infrastructure, "mostly working" isn't a state that exists.

From switch port to cloud edge

That foundation runs deep: multi-vendor routing and switching across Cisco ASA, Juniper SRX, F5 BIG-IP, MikroTik and pfSense, with BGP, OSPF, HSRP/VRRP, VLANs, trunking and IPSec — extended into cloud-native constructs: VPC topologies, security groups and NACLs, Transit Gateway patterns for cross-account connectivity, and Client VPN for secure operator access.

Networking · Visual Explainer
TCP vs UDP
Reliable delivery or raw speed — the classic transport-layer trade-off, and why HTTP/3 flipped it.
View the breakdown in my Knowledge Base

DNS and the delivery edge

I've executed production DNS migrations and operate Route 53 and Cloudflare at the edge — including solving real-world ISP routing failures for production subdomains by re-architecting proxy and DNS behaviour, and pairing CloudFront with tuned origin caching for global delivery.

Networking · Visual Explainer
How DNS Resolution Works
The five hops behind every website visit — and the real reason DNS changes 'take time to propagate'.
View the breakdown in my Knowledge Base

Segmentation as security

Network design is the first security control. I design tiered, least-privilege network paths where databases, admin planes and public workloads live in deliberately separate zones with auditable traffic flows.

Networking · Visual Explainer
Latency vs Throughput vs Bandwidth
The three network performance terms people mix up most — and why 'more bandwidth' often doesn't fix 'slow'.
View the breakdown in my Knowledge Base
Networking · Visual Explainer
NAT vs PAT vs Proxy
Three 'middlemen' with very different jobs — address translation versus speaking the protocol itself.
View the breakdown in my Knowledge Base
webappdata 04 / EXPERTISE Application Architecture & Delivery web platforms · APIs · payment integrations · performance

Platforms people order dinner on

I run the infrastructure behind e-commerce storefronts, CMS/CRM systems, mobile-app backends, call-center integrations and secure banking/SMS gateway interfaces — NestJS and React/Next.js stacks alongside classic LAMP/LEMP, with per-client isolation on shared staging environments.

Performance at the web tier

Nginx is my instrument: reverse proxying, TLS termination, compression, caching, security headers and structured logging. I've measurably improved asset delivery for national-scale ordering platforms by fixing compression and cache behaviour at the origin.

Live media at scale

Earlier in my career I ran video streaming platforms end-to-end: Wowza and Nginx/FFmpeg pipelines delivering HLS and RTMP with multi-bitrate transcoding, live DVR rewind, GEO blocking and API-driven feed monitoring — infrastructure where a dropped frame is immediately visible to thousands of viewers.

Integrations that can't fail quietly

Payment callbacks, SMS gateways and third-party APIs fail in subtle ways. I debug them at the protocol level — logs, headers, TLS, upstream behaviour — and design logging so the next failure is diagnosed in minutes, not days.

commitdeploy 05 / EXPERTISE Automation & CI/CD jenkins · sonarqube · ansible · pipelines · infrastructure as code

Pipelines teams actually trust

I've built production Jenkins CI/CD platforms from bare metal up — integrated with SonarQube quality gates and Bitbucket Cloud for NestJS and React/Next.js applications, deploying through dev, staging and production with per-client isolation and rollback paths.

Read the full build log — 7-part CI/CD pipeline series in my Knowledge Base
CI/CD · Visual Explainer
CI vs CD vs CD
Continuous Integration, Delivery, and Deployment — three terms, and the single approval button between the last two.
View the breakdown in my Knowledge Base

Configuration as code

Ansible playbooks (certified EX294) and reusable Terraform modules for repeatable provisioning across accounts and regions — including a complete AWS site-to-site IPSec VPN (Customer Gateway, Virtual Private Gateway, routing) built entirely as code, and fleet-wide agent rollouts (Wazuh, Zabbix, New Relic, CrowdStrike) across Linux and Windows Server environments. This discipline has cut manual provisioning effort by more than 60% and eliminated configuration drift as a class of incident.

Automating the boring and the dangerous

The best automation removes both toil and human error: automated AMI baking for Auto Scaling fleets, scheduled encrypted backups, alert-driven remediation and self-documenting deployment workflows.

CI/CD · Visual Explainer
Anatomy of a Real Pipeline
Six stages from git push to production — each one a reason to say no before code ships.
View the breakdown in my Knowledge Base
$ ./backup.sh --incremental → zstd | aes-256 | s3:// $ ansible-playbook harden.yml → ok=48 changed=12 failed=0 $ ▊ 06 / EXPERTISE Scripting & Tooling bash · production-grade scripts · cron · restore-tested tooling

Scripts that run in production, not demos

My Bash tooling is written for the 3 a.m. failure case: strict error handling, locking, logging, alerting on failure and idempotent re-runs. Example: a backup system streaming zstd-compressed, AES-256-encrypted MariaDB backups directly to S3 — hardened iteratively through real restore failures on 100 GB+ production-scale datasets until restores were boring.

Python where structure matters

Beyond Bash, I build production Python tooling: a custom SIEM alert-notification framework with REST API integrations (Wazuh, OpenSearch), severity-based routing, duplicate suppression, structured logging and dynamically generated dashboard deep links — turning raw security events into one-click investigations.

Glue for everything

Cron orchestration, log parsing and rotation, certificate automation, health checks, AWS CLI workflows, database maintenance jobs — the connective tissue that makes a platform self-operating.

Diagnostics that adapt to the cluster

When a recurring Zabbix flush-latency alert hit a production 8-node Elasticsearch cluster, I turned the manual investigation into a reusable, version-adaptive Bash/jq tool — it auto-discovers topology, detects the ES version live, classifies nodes from real-time data, and generates a single readable incident report. That same investigation later root-caused a JVM heap OOM outage and drove a zero-data-loss, one-node-at-a-time remediation across the whole cluster.

Read the full incident series — 6-part Elasticsearch troubleshooting log in my Knowledge Base

Tested means restore-tested

A backup script that has never restored anything is a hypothesis. Every recovery tool I ship is validated against real production clones before it's trusted.

Data Protection · Visual Explainer
Full vs Incremental vs Differential Backups
Three backup strategies — and what restore day actually looks like for each.
View the breakdown in my Knowledge Base
07 / EXPERTISE Security Engineering SIEM · hardening · WAF · threat detection · vulnerability management

SIEM engineering, not just administration

I run Wazuh as a centralized SIEM across Linux and Windows fleets — and I engineer it: custom detection rules tuned against false positives, File Integrity Monitoring, vulnerability detection and Security Configuration Assessment, MITRE ATT&CK-aligned reporting, and a custom Python alert framework with team-based routing, deduplication and HTML notifications that deep-link straight to the exact alert in the dashboard. I also administer the OpenSearch clusters underneath — index templates, shard allocation and cluster-health recovery included.

Security · Visual Explainer
The SIEM Pipeline
How raw events become actionable alerts — agents, manager, indexer, dashboard, and the routing stage most teams neglect.
View the breakdown in my Knowledge Base

Defense in depth, in practice

The SIEM layer sits alongside cloud-native detection — GuardDuty, organization-wide CloudTrail, CloudWatch metric filters and EventBridge/SNS alerting — plus endpoint protection with CrowdStrike Falcon deployed fleet-wide through Ansible, and deep-dive analysis of external vulnerability-scan traffic (QualysGuard) to keep defenses ahead of what attackers actually probe.

Security · Visual Explainer
IDS vs IPS vs SIEM vs XDR
Four security tools constantly confused — what each one actually does, and why they're layers rather than rivals.
View the breakdown in my Knowledge Base

Hardening that survives audits

SSH and PAM hardening, Fail2Ban, auditd, SELinux/AppArmor, TLS configuration and Nginx access controls — applied systematically across production fleets and verified against penetration-test findings, not just checklists.

Read my method for hardening live production servers to audit standard — without taking them down
Security · SIEM Engineering
Wazuh SIEM — Automation & Alerting
From single-node deployments to full SIEM engineering: agent fleets, rule tuning, the OpenSearch cluster underneath, and a custom Python alert-routing framework.
Read the Wazuh deep-dive in my Knowledge Base

WAF tuning without breaking the business

Managed WAF rules block attackers and, badly tuned, legitimate users. I've run false-positive investigations on production AWS WAF deployments, isolating the exact managed rule responsible and designing scoped, label-matched overrides so protection stays on where it matters. I also work with Nuclei for template-driven vulnerability scanning and deployed a self-hosted Passbolt password manager for team credential security.

Security · Visual Explainer
How a WAF Decides to Block
The journey of an HTTP request through a Web Application Firewall — and the professional way to fix a false positive.
View the breakdown in my Knowledge Base
AUDIT.LOG ssh hardeningaccess controlaudit trailencryptionbackup & DR 08 / EXPERTISE GRC & Compliance audit remediation · governance · data protection · documentation

From audit finding to closed control

I've taken a full third-party security audit — thirteen findings across SSH, PAM, Fail2Ban, auditd, TLS permissions and web-server access controls — and systematically remediated every one on production infrastructure, with evidence the auditor could verify. I work directly with GRC auditors and translate their requirements into engineering.

Security & GRC · Visual Explainer
Vulnerability vs Threat vs Risk
The three words security teams mix up most — explained with a house, an open window, and a burglar.
View the breakdown in my Knowledge Base

Governance built into the platform

Organization-wide CloudTrail, service control policies, IAM role-based access with SSO, KMS-encrypted data at rest and lifecycle-governed retention: controls that are enforced by architecture rather than by policy documents alone. My banking-sector background (regulated environment administration, DR drills) shaped this discipline early.

Security & GRC · Visual Explainer
AAA — Authentication, Authorization, Accounting
Three questions every secure system must answer: who are you, what may you do, and what did you do?
View the breakdown in my Knowledge Base

Knowledge that outlives the engineer

I produce team-ready documentation — architecture wikis, runbooks, security training. I built and delivered an internal OWASP Top 10 training program complete with hands-on vulnerable-application labs for developer teams.

// Selected work

Problems solved in production

A sample of recent engagements across the platforms I operate. Client specifics available on request.

Cost + Performance

AWS cost anomaly remediation for a national ordering platform

Traced a sudden cloud-spend spike to uncompressed, uncached asset delivery at the web tier. Re-engineered Nginx compression, caching and security headers across multiple client platforms and fixed the root cause in the scaling pipeline.

→ Cost anomaly eliminated; delivery hardened fleet-wide
Data Protection

Encrypted backup modernization

Replaced daily full database dumps with a weekly-full + daily-incremental strategy: zstd-compressed, AES-256-encrypted streams direct to S3 with tag-filtered lifecycle policies — validated by full restores on a 100 GB+ production clone. Also replaced a dangerous pre-existing S3 lifecycle rule before it could destroy data.

→ Faster backups, verified restores, lower storage cost
DevOps Platform

CI/CD platform buildout

Designed and deployed a production Jenkins platform integrated with SonarQube quality gates and Bitbucket Cloud for NestJS and React/Next.js stacks, plus a multi-tenant staging environment with per-client Linux user isolation. Full 7-part build log →

→ Automated, quality-gated releases across environments
Security Operations

Centralized multi-account security monitoring

Built an organization-wide detection stack — CloudTrail, CloudWatch metric filters, EventBridge, SNS alerting and GuardDuty — centralizing security events from a multi-account, multi-region AWS organization into one operational view.

→ Single pane of glass for security events org-wide
GRC

Full security-audit remediation

Systematically closed all thirteen findings from a third-party penetration-test/GRC audit — SSH, PAM, Fail2Ban, auditd, TLS and web-server access controls — across production infrastructure, with auditor-verifiable evidence.

→ 13/13 findings remediated and verified
SIEM Engineering

Wazuh SIEM automation & alerting platform

Engineered a production Wazuh 4.x deployment into a full alerting platform: a custom Python notification framework with team-based routing, deduplication, and HTML emails deep-linking to the exact dashboard alert — integrated with Slack, Teams and PagerDuty. Also resolved OpenSearch shard-limit exhaustion to restore reliable alert indexing.

→ One-click investigations; faster detection and response
Infrastructure as Code

Hybrid cloud connectivity with Terraform

Designed and deployed a route-based IPSec site-to-site VPN between AWS VPC networks and physical corporate firewalls — Customer Gateways, Virtual Private Gateways and routing built entirely as reusable Terraform modules. Paired with a cross-account, cross-region S3 replication pipeline (Singapore ⇄ Ireland) using custom KMS encryption. I also codified a complete Layer 3 application architecture — VPC, WAF, ALB, Auto Scaling and MariaDB — as a validated, modular Terraform project. See the full Layer 3 Terraform build →

→ Hybrid connectivity and DR replication, fully codified
Security Engineering

WAF false-positive investigation

Production WAF was blocking legitimate CMS operations. Isolated the exact managed rule responsible, applied a safe interim override and designed a label-matched rule to scope the exception to admin paths only — keeping protection fully active for public traffic.

→ Business unblocked without weakening the security posture
// Brands served

Trusted with high-traffic, customer-facing platforms

Infrastructure and platform engineering delivered for leading food-service and retail brands across Pakistan, the Gulf and Africa.

KFC
KFC
Pakistan
D
Domino's
Pakistan
PH
Pizza Hut
PK · QA · ZA · MA
BR
Baskin
Robbins
P
Popeyes
KC
KyoChon
Middle East
HF
Hilal
Foods
O
OPTP
CC
Crust
Culture
HS
Halla Shawarma
Middle East

Delivered through Zaryans and DMD Max. Brand names are used descriptively to indicate the platforms supported; no endorsement or official affiliation is implied.

// Credentials

Certifications & education

AWS Certified
Cloud Practitioner (CLF-C01)
Red Hat EX294
Ansible Automation
CKA
Certified Kubernetes Administrator
RHCSA & RHCE
Red Hat Certified Engineer
CCNA
Cisco Certified Network Associate
MCITP
Microsoft Certified IT Professional
BSc Computer Science
Islamia University, Bahawalpur — 2013