Senior DevOps Engineer - Daiovaux (Ascend Solution) - Lahore, Pakistan
(2024-10)
- Led the deployment of production grade LMS applications on Google Kubernetes Engine (GKE) to improve scalability and deployment reliability. Designed a production-ready Kubernetes platform using MongoDB StatefulSets, Istio Service Mesh, HPA, ArgoCD GitOps, and Prometheus monitoring, reducing manual deployment effort by 80% and improving operational efficiency by 70%.
- Led the migration of the organization's source code management platform from GitHub to a self-hosted GitLab environment to strengthen security and standardize development workflows. Migrated repositories, users, branches, permissions, and CI/CD pipelines while preserving repository history, enabling a seamless transition with minimal impact on development teams.
- Designed and implemented a Site-to-Site IPSec VPN using StrongSwan to establish secure connectivity between Huawei Cloud and a government-managed on-premises network. Configured IKEv2, routing, firewall policies, and encrypted tunnels to enable secure database communication over private infrastructure while maintaining reliable network connectivity.
- Architected a centralized HAProxy-based database proxy to securely expose multiple production MongoDB instances through a single access layer.
Implemented
Mutual TLS (mTLS) with certificate-based authentication using an internal PKI, strengthening database security and centralizing access management without exposing backend databases directly.
- Led the migration of production applications, databases, and storage from a multi-cloud environment to Huawei Cloud to simplify infrastructure management and improve disaster recovery capabilities. Planned the migration strategy, automated backups, and centralized cloud resources while achieving near-zero downtime and reducing infrastructure costs by 60%.
- Designed and standardized CI/CD pipelines across production applications using Jenkins to automate build, testing, security scanning, and deployments.
Integrated
SonarQube, Trivy, OWASP ZAP, and Snyk into the delivery pipeline, reducing deployment time by 60% while improving application quality and security.
- Built a centralized monitoring and observability platform using Prometheus, Grafana, Loki, and Promtail to improve visibility across production environments. Implemented dashboards, alerting rules, and log aggregation that enabled proactive incident detection, reducing infrastructure downtime by 90%.
- Containerized over 45 production applications built with Laravel, React, Go, and .NET to standardize deployments across development, staging, and production environments.
Optimized
Docker images, resolved dependency conflicts, and established reusable containerization practices that simplified deployments and improved platform consistency.
- Configured Apache Airflow to orchestrate ETL workflows for the Data Science team and automated DAG deployments through Jenkins. Streamlined workflow management by standardizing deployment processes, reducing manual effort, and improving reliability for data engineering operations.
- Designed and automated a Disaster Recovery solution for the Hajj 2025 and 2026 mission to ensure uninterrupted service availability during critical operations. Implemented DNS failover, continuous database replication, automated backups, and recovery procedures, maintaining 98% service availability throughout the mission.
DevOps Engineer - Shark Innovation Lab - Lahore, Pakistan
(2024-04 - 2024-10)
- Automated AWS infrastructure provisioning using Terraform to support cloud migration and infrastructure standardization initiatives. Developed reusable Infrastructure as Code modules for EC2, VPC, IAM, RDS, and Amazon EKS, improving deployment consistency while significantly reducing manual provisioning effort.
- Strengthened Kubernetes platform resilience by implementing Velero and Kasten K10 for automated backup and disaster recovery. Developed backup policies, recovery procedures, and validation processes to improve workload protection and ensure business continuity during infrastructure failures.
- Integrated SigNoz Application Performance Monitoring (APM) into Spring Boot microservices to enhance application observability and troubleshooting capabilities. Configured distributed tracing, metrics, and dashboards that enabled developers to identify bottlenecks, optimize APIs, and improve application performance.
- Hardened Linux servers by implementing security controls aligned with NIST best practices following a production WordPress security incident. Performed vulnerability assessments, remediated security findings, and strengthened server configurations to improve infrastructure security and reduce future attack risks.
DevOps & Cloud Engineer - Nearpeer Pvt Ltd - Lahore, Pakistan
(2023-03 - 2024-05)
- Developed an internal Flask-based SaaS platform to automate cloud infrastructure provisioning across Microsoft Azure and Google Cloud Platform.
Integrated
Terraform, Docker, and Jenkins to provision virtual machines, DNS, projects, and databases through a self-service portal, reducing environment setup time from 40 minutes to under 10 minutes.
- Designed, deployed, and managed an enterprise-grade Zimbra Mail Server to provide secure organizational email services while eliminating dependency on third-party providers. Implemented backup, monitoring, and user management processes that improved reliability, security, and operational efficiency.
- Implemented an OpenVPN-based remote access solution to provide secure connectivity for internal teams and external collaborators. Configured role-based access controls, authentication policies, and encrypted communication channels to strengthen network security while ensuring reliable remote access to company infrastructure.