Skip to main content

IT Operations • Cybersecurity • Infrastructure

BuildingSECURE INFRASTRUCTURE.SECURE INFRASTRUCTURE. RELIABLE OPERATIONS. AUTOMATED SYSTEMS.

Muhammad Ahmad Khan

IT Operations EngineerCybersecurity Analyst

I work across IT operations and cybersecurity, supporting production environments through monitoring, incident troubleshooting, log analysis, infrastructure operations, and automation — with a growing focus on cloud-native technologies and DevSecOps.

Islamabad, Pakistan

Portrait of Muhammad Ahmad Khan, IT Operations Engineer
Open to opportunities

System Status

LIVE VIEW

Infrastructure

Security

Certificates
Network
Policy

Observability

metricstrend

Automation

  • svc/gateway health check ok
  • node/worker-2 scheduled
  • pipeline stage: build
  • policy scan complete
01

About

Operations meets security.

My career began in cybersecurity. Working as a Cyber Security Analyst — and before that as a cybersecurity intern at Pakistan Aeronautical Complex Kamra — gave me hands-on exposure to threat analysis, vulnerability assessment, incident investigation, digital forensics, and network security.

Today I work in enterprise IT Operations at Jazz, supporting production systems. I monitor application and infrastructure health, investigate and troubleshoot incidents, analyze logs in Kibana for root cause analysis, and work with Linux environments running on Red Hat OpenShift. I write Python and Bash scripts to automate repetitive operational tasks.

That path shapes how I read a system. An outage and an intrusion are both investigated the same way: observe, correlate, isolate, remediate. Security context makes operational work sharper, and operational context makes security work practical.

SecurityOperationsAutomationInfrastructure
Organizations
4OrganizationsJazz, SquareTrade, EurosHub, PAC Kamra
In the field since
2023In the field sinceFirst cybersecurity role
Cyber Security
BSCyber SecurityAir University, 2020 — 2024
Certifications & training
6Certifications & trainingSecurity, network analysis, Linux, automation
01

Reliability

Supporting systems and services with a focus on availability and operational stability.

02

Security

Understanding vulnerabilities, security risks, investigation, and defensive practices.

03

Observability

Using monitoring and log analysis to understand system behaviour and investigate incidents.

04

Automation

Using Python, Bash, and infrastructure automation to reduce repetitive operational work.

02

Core Expertise

The work I do, and the work I have done.

Keeping services up, working out why they broke, and the systems underneath. This is where most of my time goes.

Linux & Systems

Day-to-day work in Linux-based production environments — service checks, system state, and troubleshooting.

  • Linux
  • Bash
  • GNS3

IT Operations

Supporting enterprise production systems: application health, service availability, and operational follow-through.

  • Monitoring
  • Incident Management
  • ServiceNow

Cybersecurity

Threat analysis, vulnerability assessment, incident investigation, digital forensics, and network security.

  • Nessus
  • Wireshark
  • Nmap
  • MITRE ATT&CK

Infrastructure Monitoring

Monitoring production applications and infrastructure to keep services available and detect issues early.

  • Monitoring
  • Alerting
  • Dashboards

Incident Management

Investigating and troubleshooting application and system issues, and collaborating with teams through resolution.

  • Triage
  • Root Cause Analysis
  • Escalation

Log Analysis

Analyzing logs in Kibana to support incident investigation and root cause analysis.

  • Kibana
  • Elasticsearch
  • ELK

OpenShift / Kubernetes

Working with Linux workloads on Red Hat OpenShift, with Kubernetes as an ongoing area of depth.

  • Red Hat OpenShift
  • Kubernetes
  • Containers

Python & Bash Automation

Writing scripts that remove repetitive operational work and make routine checks consistent.

  • Python
  • Bash
  • PowerShell

Vulnerability Assessment

Identifying and remediating network vulnerabilities and assessing exposure across systems.

  • Nessus
  • Nmap
  • Remediation
03

Technical Expertise

Technology ecosystem.

What I reach for day to day, and what I'm going deeper on. Grouped by the job each tool does rather than by how well I know it.

  • Linux
  • Windows Server
  • PowerShell
  • Bash
  • Python
  • Git
  • GitHub
  • GitLab
  • Ansible
  • Terraform
  • Docker
  • Kubernetes
  • OpenShift
  • Helm
  • Jenkins
  • Argo CD
  • AWS
  • Microsoft Azure
  • Wireshark
  • Nmap
  • Nessus
  • MITRE ATT&CK
  • Splunk
  • Microsoft Sentinel
  • Microsoft Defender
  • Elasticsearch
  • Logstash
  • Kibana
  • Datadog
  • Prometheus
  • Grafana
  • OpenTelemetry
  • ServiceNow
01

Systems & Administration

04
  • Linux

    Systems & infrastructure

  • Windows Server

    Server administration

  • PowerShell

    Windows scripting

  • Bash

    Shell & operational scripting

02

Programming & Version Control

04
  • Python

    Automation & scripting

  • Git

    Version control

  • GitHub

    Source hosting

  • GitLab

    Source hosting & pipelines

03

Automation & IaC

02
  • Ansible

    Configuration management

  • Terraform

    Infrastructure as code

04

Containers & Orchestration

04
  • Docker

    Containerisation

  • Kubernetes

    Container orchestration

  • OpenShift

    Enterprise Kubernetes platform

  • Helm

    Kubernetes packaging

05

CI/CD & GitOps

02
  • Jenkins

    Continuous integration

  • Argo CD

    GitOps delivery

06

Cloud

02
  • AWS

    Cloud infrastructure

  • Microsoft Azure

    Cloud infrastructure

07

Security & Network Analysis

04
  • Wireshark

    Packet analysis

  • Nmap

    Network discovery

  • Nessus

    Vulnerability assessment

  • MITRE ATT&CK

    Adversary technique framework

08

Security Operations

03
  • Splunk

    Security analytics

  • Microsoft Sentinel

    Cloud-native SIEM

  • Microsoft Defender

    Endpoint & threat protection

09

Logging & Observability

07
  • Elasticsearch

    Search & log storage

  • Logstash

    Log ingestion pipeline

  • Kibana

    Log analysis & visualisation

  • Datadog

    Monitoring platform

  • Prometheus

    Metrics & alerting

  • Grafana

    Metrics visualisation

  • OpenTelemetry

    Telemetry instrumentation

10

IT Operations / ITSM

01
  • ServiceNow

    IT service management

04

Experience

Professional experience.

A cybersecurity start, operational and technical roles in between, and enterprise IT Operations today.

  1. May 2026 — Present

    Current

    Islamabad, Pakistan

    IT Operations Engineer

    Jazz

    Supporting enterprise production systems by monitoring application health, troubleshooting incidents, and helping maintain service reliability.

    • Monitor production applications and infrastructure to ensure service availability.
    • Investigate and troubleshoot application and system issues.
    • Analyze logs using Kibana to support incident investigation and root cause analysis.
    • Work with Linux-based environments and Red Hat OpenShift.
    • Develop Python and Bash scripts to automate operational tasks.
    • Collaborate with development and infrastructure teams during incident resolution.
    • Linux
    • Red Hat OpenShift
    • Kibana
    • Python
    • Bash
    • Monitoring
    • Incident Management
  2. October 2025 — May 2026

    Islamabad, Pakistan

    Supply Chain Specialist

    SquareTrade

    The last of three roles across a year at SquareTrade, after moving up from customer service into technical support.

  3. August 2025 — October 2025

    Islamabad, Pakistan

    Technical Support Specialist

    SquareTrade

    Troubleshooting customer issues directly — the first role where the work was properly technical.

  4. June 2025 — August 2025

    Islamabad, Pakistan

    Customer Service Specialist

    SquareTrade

    Where I started at SquareTrade, working with customers day to day.

  5. February 2024 — April 2025

    Rawalpindi, Punjab, Pakistan

    Cyber Security Analyst

    EurosHub

    My first security role — threat analysis, vulnerability assessment, incident investigation, and digital forensics.

    • Threat Analysis
    • Vulnerability Assessment
    • Incident Investigation
    • Digital Forensics
  6. July 2023 — August 2023

    Pakistan

    Cybersecurity Intern

    Pakistan Aeronautical Complex Kamra

    A summer internship where the security work was hands-on rather than theoretical.

    • Assisted in securing digital certificates and implementing encryption mechanisms.
    • Identified and remediated network vulnerabilities, improving overall security posture.
    • Digital Certificates
    • Encryption
    • Network Security

Career journey

Security first, then the systems around it.

Cybersecurity was the starting point, not a detour. Everything since has added operational depth on top of it.

  1. 012020 — 2023

    Cybersecurity foundation

    BS Cyber Security, Air University — and a cybersecurity internship at PAC Kamra.

  2. 022024 — 2025

    Cyber Security Analyst

    Threat analysis, vulnerability assessment, incident investigation, digital forensics.

  3. 032025 — 2026

    Technical & operational experience

    Technical support and operations roles at SquareTrade.

  4. 042026 — Present

    IT Operations Engineer

    Enterprise production support at Jazz — monitoring, incidents, logs, Linux, OpenShift.

  5. 05Current focus

    Infrastructure + security + automation

    Combining operational discipline with a security lens and Python/Bash automation.

  6. 06Direction

    Cloud & DevSecOps direction

    Ongoing development toward cloud infrastructure, Kubernetes, IaC, CI/CD, and DevSecOps.

Cloud and DevSecOps are stated here as a direction of professional development, not as current job titles or years of production experience.

05

Cybersecurity

Security is part of the foundation.

My career started in cybersecurity, and that grounding still shapes how I approach infrastructure. I look at systems the way an analyst does — what is exposed, what changed, and what the evidence actually shows.

Threat analysis

Understanding how attackers operate and what that means for system exposure.

Vulnerability assessment

Identifying weaknesses across networks and systems, and following through on remediation.

Incident investigation

Working from symptom to cause using evidence rather than assumption.

Digital forensics

Hands-on exposure to forensic analysis as part of security work.

Network security

Traffic and network-level analysis, and identifying network vulnerabilities.

Certificates & encryption

Assisted in securing digital certificates and implementing encryption mechanisms during the PAC Kamra internship.

Security tooling in my stack

  • Wireshark
  • Nmap
  • Nessus
  • MITRE ATT&CK
  • Splunk
  • Microsoft Sentinel
  • Microsoft Defender
  • ELK / Kibana

Operations ↔ Security loop

  1. 01

    Monitor

    Watch service and infrastructure health.

  2. 02

    Detect

    Notice deviation, alert, or anomaly.

  3. 03

    Investigate

    Correlate logs, metrics, and context.

  4. 04

    Troubleshoot

    Isolate the failing component.

  5. 05

    Remediate

    Restore service and close the gap.

  6. 06

    Automate

    Script what repeats.

  7. 07

    Improve

    Feed findings back into operations.

The same investigative sequence applies whether the trigger is an outage or a security finding.

Observability

Observability & operational visibility

You cannot fix what you cannot see. Most of my incident work starts in Kibana, reading logs until the timeline makes sense. Metrics and traces are the other half of the same job.

Logs

Search, filter, and correlate application and system logs during an investigation.

  • Elasticsearch
  • Logstash
  • Kibana
  • ELK

Metrics

Track system and service behaviour over time to spot deviation from normal.

  • Prometheus
  • Grafana
  • Datadog

Instrumentation

Standardised telemetry across services as a foundation for visibility.

  • OpenTelemetry

Automation

Automation as an engineering practice

If I do something twice by hand, I start thinking about scripting it. That is Python and Bash today, and Ansible and Terraform as I move further into infrastructure.

  • Repetitive operational tasks
  • Infrastructure consistency
  • Operational efficiency
  • Deployment workflows
  • System administration
  • Infrastructure provisioning

Toolchain

  • 01Python
    Operational scripting and network programming
  • 02Bash
    System and operational automation on Linux
  • 03PowerShell
    Windows-side scripting
  • 04Ansible
    Configuration management
  • 05Terraform
    Infrastructure as code

Python and Bash are part of the day job. Ansible and Terraform are what I'm building next.

06

Direction

Building toward DevSecOps

My long-term goal is to specialise in DevSecOps — combining cybersecurity with cloud infrastructure, Kubernetes, automation, and CI/CD to build secure, scalable platforms.

Where I work today

  • Enterprise IT Operations at Jazz
  • Production monitoring & incident investigation
  • Log analysis with Kibana
  • Linux environments and Red Hat OpenShift
  • Python & Bash operational automation
  • Cybersecurity analysis and vulnerability assessment

Where I'm heading

  • Cloud infrastructure — AWS and Azure
  • Kubernetes beyond managed OpenShift workloads
  • Infrastructure as Code — Terraform and Ansible
  • CI/CD and GitOps — Jenkins and Argo CD
  • Security integration across delivery pipelines
  • DevSecOps practices end to end
07

Projects

Projects & technical labs.

Where I go to try things properly — vulnerability assessment, packet analysis, threat investigation, automation, and incident response, all built out in my own lab.

01Vulnerability Assessment & Security Hardening

Vulnerability Assessment & Security Hardening Lab

Completed

Identify security weaknesses in a controlled lab environment, assess their severity, and develop practical remediation recommendations.

  • Tenable Nessus
  • Nmap
  • Linux
  • CVE/CVSS
  • Vulnerability Management

Work performed

  • Performed vulnerability scanning against authorized lab systems.
  • Identified exposed services and potentially vulnerable configurations.
  • Used Nmap to enumerate hosts, ports, and services.
  • Used Nessus to identify known vulnerabilities.
  • Reviewed vulnerability severity and potential impact.
  • Mapped findings to affected systems and services.
  • Prioritized remediation based on risk.
  • Validated remediation through follow-up scanning.

Process

  1. Discover
  2. Assess
  3. Prioritize
  4. Remediate
  5. Validate

Outcome

Developed practical experience in the vulnerability-management lifecycle.

  • Vulnerability Management
  • Nessus
  • Nmap
  • Linux
02Network Analysis

Network Traffic Analysis & Threat Investigation Lab

Completed

Analyze network traffic to identify suspicious communication patterns and understand how network evidence can support security investigations.

  • Wireshark
  • TCP/IP
  • DNS
  • HTTP/HTTPS
  • Network Analysis

Work performed

  • Captured and analyzed network traffic in a controlled environment.
  • Investigated TCP/IP communication.
  • Examined DNS requests and responses.
  • Analyzed HTTP/HTTPS traffic where appropriate.
  • Investigated unusual communication patterns.
  • Applied Wireshark filters to isolate relevant traffic.
  • Examined packet-level indicators during simulated security scenarios.
  • Documented observations and investigation findings.

Process

  1. Detection
  2. Investigation
  3. Analysis
  4. Reporting

Outcome

Built practical experience in using packet-level network evidence to support investigations.

  • Wireshark
  • Network Security
  • Packet Analysis
03Threat Investigation

MITRE ATT&CK-Based Threat Investigation Lab

Completed

Use the MITRE ATT&CK framework to structure the analysis of simulated adversary behavior.

  • MITRE ATT&CK
  • Linux
  • ELK / Kibana
  • Security Logs
04Automation

Python Network Security Automation Lab

Completed

Use Python to automate repetitive network and security-analysis tasks.

  • Python
  • Networking
  • Linux
  • APIs
05Incident Response

Security Incident Response Simulation

Completed

Simulate a security incident and practice a structured investigation and response workflow.

  • Linux
  • Wireshark
  • ELK / Kibana
  • Nessus
  • MITRE ATT&CK

Work performed

  • Investigated simulated suspicious activity.
  • Collected available evidence.
  • Analyzed network and system information.
  • Identified potential indicators.
  • Established an incident timeline.
  • Assessed potential impact.
  • Documented containment and remediation recommendations.
  • Produced an incident summary.

Process

  1. Preparation
  2. Detection
  3. Triage
  4. Investigation
  5. Containment
  6. Remediation
  7. Validation
  8. Lessons Learned

Outcome

Demonstrated a structured approach to security incident investigation and response.

  • Incident Response
  • Digital Forensics
  • Wireshark
  • ELK
  • MITRE ATT&CK

What I'm building next

06Cloud-Native Security

Container & Kubernetes Security Lab

In progress

Explore security considerations in containerized and Kubernetes-based environments.

  • Docker
  • Kubernetes
  • OpenShift
  • Helm
  • Linux
07Infrastructure Automation

Infrastructure Security Automation Lab

In progress

Explore how infrastructure automation can improve consistency and security.

  • Ansible
  • Terraform
  • Linux
  • Git
08

Education & training

Formal grounding, and the training that followed.

September 2020 — September 2024

Air University

Bachelor's degree, Cyber Security

Certifications & professional learning

  • 01Cybersecurity Fundamentals
    Security
  • 02Security Principles
    Security
  • 03Wireshark: Packet Analysis
    Network analysis
  • 04Ethical Hacking: Core Skills
    Security
  • 05Python Network Programming for Network Engineers (Python 3)
    Automation
  • 06Linux for Network Engineers: Practical Linux with GNS3
    Linux

Reliabilityandsecurityshouldnotbeseparateconcerns.

Modern infrastructure has to be available, observable, secure, and automated at the same time. Treating those as separate workstreams is how gaps appear — an unmonitored service is a blind spot, an unpatched host is an incident waiting to be triaged, and a manual process is a consistency problem. Operational discipline is what holds them together.

09

Contact

Let's connect.

Interested in infrastructure, cybersecurity, automation, or cloud-native engineering? Let's connect.

A short note about the role, project, or question is enough.

This opens the message in your own email app — I'd rather you had my address than a form in the middle.