Reliability
Supporting systems and services with a focus on availability and operational stability.
IT Operations • Cybersecurity • Infrastructure
Muhammad Ahmad Khan
IT Operations EngineerCybersecurity Analyst
I work across IT operations and cybersecurity, supporting production environments through monitoring, incident troubleshooting, log analysis, infrastructure operations, and automation — with a growing focus on cloud-native technologies and DevSecOps.
Islamabad, Pakistan

System Status
Infrastructure
Security
Observability
Automation
About
My career began in cybersecurity. Working as a Cyber Security Analyst — and before that as a cybersecurity intern at Pakistan Aeronautical Complex Kamra — gave me hands-on exposure to threat analysis, vulnerability assessment, incident investigation, digital forensics, and network security.
Today I work in enterprise IT Operations at Jazz, supporting production systems. I monitor application and infrastructure health, investigate and troubleshoot incidents, analyze logs in Kibana for root cause analysis, and work with Linux environments running on Red Hat OpenShift. I write Python and Bash scripts to automate repetitive operational tasks.
That path shapes how I read a system. An outage and an intrusion are both investigated the same way: observe, correlate, isolate, remediate. Security context makes operational work sharper, and operational context makes security work practical.
Supporting systems and services with a focus on availability and operational stability.
Understanding vulnerabilities, security risks, investigation, and defensive practices.
Using monitoring and log analysis to understand system behaviour and investigate incidents.
Using Python, Bash, and infrastructure automation to reduce repetitive operational work.
Core Expertise
Keeping services up, working out why they broke, and the systems underneath. This is where most of my time goes.
Day-to-day work in Linux-based production environments — service checks, system state, and troubleshooting.
Supporting enterprise production systems: application health, service availability, and operational follow-through.
Threat analysis, vulnerability assessment, incident investigation, digital forensics, and network security.
Monitoring production applications and infrastructure to keep services available and detect issues early.
Investigating and troubleshooting application and system issues, and collaborating with teams through resolution.
Analyzing logs in Kibana to support incident investigation and root cause analysis.
Working with Linux workloads on Red Hat OpenShift, with Kubernetes as an ongoing area of depth.
Writing scripts that remove repetitive operational work and make routine checks consistent.
Identifying and remediating network vulnerabilities and assessing exposure across systems.
Technical Expertise
What I reach for day to day, and what I'm going deeper on. Grouped by the job each tool does rather than by how well I know it.
Linux
Systems & infrastructure
Windows Server
Server administration
PowerShell
Windows scripting
Bash
Shell & operational scripting
Python
Automation & scripting
Git
Version control
GitHub
Source hosting
GitLab
Source hosting & pipelines
Ansible
Configuration management
Terraform
Infrastructure as code
Docker
Containerisation
Kubernetes
Container orchestration
OpenShift
Enterprise Kubernetes platform
Helm
Kubernetes packaging
Jenkins
Continuous integration
Argo CD
GitOps delivery
AWS
Cloud infrastructure
Microsoft Azure
Cloud infrastructure
Wireshark
Packet analysis
Nmap
Network discovery
Nessus
Vulnerability assessment
MITRE ATT&CK
Adversary technique framework
Splunk
Security analytics
Microsoft Sentinel
Cloud-native SIEM
Microsoft Defender
Endpoint & threat protection
Elasticsearch
Search & log storage
Logstash
Log ingestion pipeline
Kibana
Log analysis & visualisation
Datadog
Monitoring platform
Prometheus
Metrics & alerting
Grafana
Metrics visualisation
OpenTelemetry
Telemetry instrumentation
ServiceNow
IT service management
Experience
A cybersecurity start, operational and technical roles in between, and enterprise IT Operations today.
May 2026 — Present
Islamabad, Pakistan
Jazz
Supporting enterprise production systems by monitoring application health, troubleshooting incidents, and helping maintain service reliability.
October 2025 — May 2026
Islamabad, Pakistan
SquareTrade
The last of three roles across a year at SquareTrade, after moving up from customer service into technical support.
August 2025 — October 2025
Islamabad, Pakistan
SquareTrade
Troubleshooting customer issues directly — the first role where the work was properly technical.
June 2025 — August 2025
Islamabad, Pakistan
SquareTrade
Where I started at SquareTrade, working with customers day to day.
February 2024 — April 2025
Rawalpindi, Punjab, Pakistan
EurosHub
My first security role — threat analysis, vulnerability assessment, incident investigation, and digital forensics.
July 2023 — August 2023
Pakistan
Pakistan Aeronautical Complex Kamra
A summer internship where the security work was hands-on rather than theoretical.
Career journey
Cybersecurity was the starting point, not a detour. Everything since has added operational depth on top of it.
BS Cyber Security, Air University — and a cybersecurity internship at PAC Kamra.
Threat analysis, vulnerability assessment, incident investigation, digital forensics.
Technical support and operations roles at SquareTrade.
Enterprise production support at Jazz — monitoring, incidents, logs, Linux, OpenShift.
Combining operational discipline with a security lens and Python/Bash automation.
Ongoing development toward cloud infrastructure, Kubernetes, IaC, CI/CD, and DevSecOps.
Cloud and DevSecOps are stated here as a direction of professional development, not as current job titles or years of production experience.
Cybersecurity
My career started in cybersecurity, and that grounding still shapes how I approach infrastructure. I look at systems the way an analyst does — what is exposed, what changed, and what the evidence actually shows.
Understanding how attackers operate and what that means for system exposure.
Identifying weaknesses across networks and systems, and following through on remediation.
Working from symptom to cause using evidence rather than assumption.
Hands-on exposure to forensic analysis as part of security work.
Traffic and network-level analysis, and identifying network vulnerabilities.
Assisted in securing digital certificates and implementing encryption mechanisms during the PAC Kamra internship.
Security tooling in my stack
Operations ↔ Security loop
Monitor
Watch service and infrastructure health.
Detect
Notice deviation, alert, or anomaly.
Investigate
Correlate logs, metrics, and context.
Troubleshoot
Isolate the failing component.
Remediate
Restore service and close the gap.
Automate
Script what repeats.
Improve
Feed findings back into operations.
The same investigative sequence applies whether the trigger is an outage or a security finding.
Observability
You cannot fix what you cannot see. Most of my incident work starts in Kibana, reading logs until the timeline makes sense. Metrics and traces are the other half of the same job.
Search, filter, and correlate application and system logs during an investigation.
Track system and service behaviour over time to spot deviation from normal.
Standardised telemetry across services as a foundation for visibility.
Automation
If I do something twice by hand, I start thinking about scripting it. That is Python and Bash today, and Ansible and Terraform as I move further into infrastructure.
Toolchain
Python and Bash are part of the day job. Ansible and Terraform are what I'm building next.
Direction
My long-term goal is to specialise in DevSecOps — combining cybersecurity with cloud infrastructure, Kubernetes, automation, and CI/CD to build secure, scalable platforms.
Projects
Where I go to try things properly — vulnerability assessment, packet analysis, threat investigation, automation, and incident response, all built out in my own lab.
Identify security weaknesses in a controlled lab environment, assess their severity, and develop practical remediation recommendations.
Work performed
Process
Outcome
Developed practical experience in the vulnerability-management lifecycle.
Analyze network traffic to identify suspicious communication patterns and understand how network evidence can support security investigations.
Work performed
Process
Outcome
Built practical experience in using packet-level network evidence to support investigations.
Use the MITRE ATT&CK framework to structure the analysis of simulated adversary behavior.
Use Python to automate repetitive network and security-analysis tasks.
Simulate a security incident and practice a structured investigation and response workflow.
Work performed
Process
Outcome
Demonstrated a structured approach to security incident investigation and response.
What I'm building next
Explore security considerations in containerized and Kubernetes-based environments.
Explore how infrastructure automation can improve consistency and security.
Education & training
September 2020 — September 2024
Bachelor's degree, Cyber Security
Certifications & professional learning
Modern infrastructure has to be available, observable, secure, and automated at the same time. Treating those as separate workstreams is how gaps appear — an unmonitored service is a blind spot, an unpatched host is an incident waiting to be triaged, and a manual process is a consistency problem. Operational discipline is what holds them together.
Contact
Interested in infrastructure, cybersecurity, automation, or cloud-native engineering? Let's connect.