Platform · DevSecOps · Cloud · Security & Compliance
Ahsan Iqbal
For 14+ years I've built, automated, and secured mission-critical platforms — across datacenters, multi-cloud, and regulated, air-gapped environments. I pair hands-on infrastructure and DevOps engineering (IaC, CI/CD, OpenShift) with security and compliance: CIS/NIST hardening, Zero-Trust, SOX & SOC 2, and vulnerability remediation. A stalled migration, a platform to modernize, or an estate to secure and make audit-ready — that's the call I take.
Empowering Global Tech Leaders
What I bring to the table
CORE
Platform & Infra Architecture
End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.
PLATFORM
Linux, AIX/Power & OpenShift
Deep Linux and IBM Power (AIX P6–P9) operations, plus OpenShift / KubeVirt virtualization and container platforms.
DEVOPS
Platform & Infra Architecture
End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.
SECURITY
Platform & Infra Architecture
End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.
CLOUD
Platform & Infra Architecture
End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.
MIGRATE
Platform & Infra Architecture
End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.
Career Timeline
↓ Full career history, newest first — real dates, confidential employers (sector only).
Jan 2025 — Present
Nuclear Power — Sr. Systems Engineer
Architecting and securing mission-critical R&D infrastructure in a partially air-gapped, NIST/CIS, Zero-Trust environment. Replaced VMware vSphere with OpenShift Virtualization (KubeVirt) — cutting node-failure recovery from ~8 min to under 90s. Deployed OpenShift 4.21 on bare metal (F5 VIPs, full X.509 lifecycle) and OpenShift AI on a GPU cluster (NVIDIA L40/A100). Architected an Azure Government (GovCloud) landing zone for export-controlled (ITAR/EAR) data — subscriptions, VNets, NSGs, IAM — with Bicep IaC pipelines, and deployed IBM ELM (9 modules / DB2) to Azure. Lead architect for the HPC clusters (RHEL/Rocky 8) running thermal, CFD & structural simulation, with PBS Pro scheduling and batch-to-GUI so engineers launch Ansys jobs directly. Automated node imaging (SaltStack/Packer) and unified auth via SSSD/Kerberos/LDAP
Outcome: modern cloud-native engineering meeting federal-grade security and ITAR compliance on a secure, high-performance research platform.
Jun 2021 — Oct 2024
Direct-to-Consumer / Fitness — Lead SysOps Engineer (Remote)
Led a DevOps / SecOps / SRE team. Migrated the Oracle ERP estate to Oracle Cloud (OCI), provisioning all servers as code with Terraform and managing config via Ansible + GitHub pipelines. Built primary/secondary DR for business continuity, ran capacity planning with Splunk/Datadog/AppDynamics, and cut cloud cost by powering down non-peak workloads. Also executed an on-prem datacenter + storage migration (VMware clone + hardware upgrades) and moved boot-from-SAN Cisco UCS servers to Pure Storage. Standardized incident/change/problem management on ITIL
Outcome: ERP modernized to OCI as code, resilient DR in place, and cloud spend actively optimized across a remote-first estate.
Apr 2018 — May 2021
National Retailer — Manager, Storage & Compute
Ran the storage & compute team. Deployed RHEL application servers with CI/CD (Ansible, Jenkins, GitHub), built VMware estates via Terraform, and migrated on-prem Oracle RAC to Exadata Cloud (EXA-CS). Architected new IBM AIX P950 servers and LPARs, migrated mission-critical SAP and DB2, and moved Cognos/ETL from AIX 7.1 to RHEL on VMware. Ran a Hitachi HUS VM → new Hitachi SAN migration plus RHEL Pacemaker clusters with GPFS. On Azure: migrated classic→ARM, built ARM-template deployments, web/worker/VM roles, and VM backup via Recovery Services Vault. Migrated the on-prem Linux stack (ETL, Cognos, e-com, WebSphere + MQ) to AWS, and deployed Datadog for full application/log monitoring
Outcome: a legacy AIX retailer modernized across Linux, three clouds (Azure, AWS, OCI/Exadata), and full observability.
Feb 2016 — May 2018
Higher Education — Infrastructure Team Lead
Led a 4-person infrastructure team. Planned and executed a zero-downtime VM migration from old SAN to new — installed Dell Compellent SC4020 (100 TB), cut hosts from FC over to dual-port 10GbE iSCSI, and migrated all SAN-attached Linux app/DB servers live. Maintained multi-site VMware ESX 5.5/6.0 with Puppet + Red Hat Satellite, and upgraded Dell R710/R610 hardware (SSD, memory, NICs). Migrated identity from Sun Directory (Solaris) to a multi-master 389 LDAP, then on to Active Directory. Replaced Xymon with Nagios XI — imported 3,000 custom service checks, wrote custom monitoring scripts, and integrated the ticketing API for auto-created/assigned alerts
Outcome: a zero-downtime SAN migration of the estate, modern identity, and a 3,000-check monitoring platform built from scratch.
Sep 2015 — Feb 2016
Semiconductor — Systems Administrator (Implementation & Design)
In the implementation & design group, built server infrastructure on Dell M1000e/M620 blades. Upgraded the VMware estate (4.1 → 5.1, vCenter 5.5) and automated provisioning of 500+ VMs with PowerCLI. Built RHEL clustering (10 clusters of 5 nodes, RICCI/LUCI), managed Puppet master/agents, and tuned Linux performance (hugepages, NIC parameters, thread-dump analysis). Diagnosed Java memory leaks in Tomcat/JBoss and configured Active Directory / Centrify authentication across Linux
Outcome: a provisioned, clustered, performance-tuned VMware/RHEL estate with automated deployment at scale.
Jan 2015 — Aug 2015
Pharmacy / Healthcare — System Integration Engineer
Bridged business initiatives and enterprise architecture: designed technical solutions within defined architectures, estimated materials and labor, and coordinated infrastructure delivery across functional groups. Acted as liaison between business, governance, architecture, and operations, evaluated processing requirements with technical leads to finalize hardware configurations, and ran capacity/growth analysis with Splunk/Nagios dashboards
Outcome: solutions delivered to spec across teams — the architecture-and-governance discipline applied end to end.
Jul 2014 — Jan 2015
Banking — UNIX/Linux Lead (Datacenter Migration)
Datacenter-migration lead for the UNIX team, moving 100+ servers (IBM AIX, RHEL 5/6). Created VIO servers and virtual LANs on IBM P770 frames, built custom AIX LPAR profiles, and migrated AIX LPARs from Power 6 to P770 via mksysb/NIM restore with SRDF on EMC VMAX. Built 2/3/4-node AIX database clusters, migrated physical Linux servers via PlateSpin (P2V/P2P) to Cisco UCS, and moved VMware guests datacenter-to-datacenter with SRM + SRDF. Authored detailed migration runbooks and go-live patching procedures
Outcome: 100+ AIX & Linux servers migrated to a new datacenter and storage, with documented, repeatable cutover procedures.
Oct 2013 — Jul 2014
Healthcare Provider — Linux/Unix Lead & SME
Subject-matter consultant in Systems Architecture & Integration: engineered enterprise Linux systems (RHEL 5.4–6.0), designed DNS and network architecture (Cisco switches, ASA firewalls, Brocade load balancers), and tuned Apache Tomcat/JBoss against Oracle and MySQL with JMeter/AB. Ran highly available production on Xen and VMware, benchmarked and stress-tested it, and stood up monitoring with Zenoss/Nagios/SiteScope plus MRTG/Cacti for the network team
Outcome: HA enterprise systems engineered, tuned, and monitored end to end.
Apr 2012 — Sep 2013 · first role
Media & Entertainment — System Administrator
First role: responsible for 300 in-house and 500 remote virtual servers — maintenance, troubleshooting, disk management, availability, and the applications running on them. Strategized disaster recovery for IBM and Sun Solaris servers using NIM and Jumpstart, and monitored the entire Windows/Linux environment with Nagios XI
Outcome: 800 virtual servers kept available with DR and full monitoring — the foundation everything since has built on.
Selected Work
Six flagship cases, each: situation → what I did → result. Curated from 10+ projects to show range, not repetition.
CASE 01 · DATACENTER MIGRATION · BANKING
Bank datacenter migration: 100+ AIX & Linux servers, P6 → P770, EMC VMAX
The challenge
A bank had to relocate 100+ mission-critical servers — IBM AIX and RHEL — to a new datacenter, including Power 6 LPARs and physical Linux estates, with no room for data loss.
What I did
Led the UNIX team's migration: created VIO servers and virtual LANs on IBM P770 frames, migrated AIX LPARs from Power 6 to P770 via mksysb/NIM restore with SRDF replication on EMC VMAX, rebuilt 2/3/4-node AIX database clusters, and moved physical Linux servers with PlateSpin (P2V/P2P) onto Cisco UCS. Relocated VMware guests datacenter-to-datacenter using SRM + SRDF, and authored detailed runbooks for every step.
Result
100+ AIX and Linux servers migrated to new hardware, datacenter and storage — fully documented, with go-live patching to production standards and zero data loss.
CASE 02 · PLATFORM MODERNIZATION · NATIONAL RETAILER
AIX → Linux transformation: ~800 VMs, SAP HANA, automation & SOC 2
The challenge
~800 VMs and ~40 TB of mission-critical apps were running on platform-locked Power 6/7 (AIX). Rather than pour budget into P8/P9, the business needed to modernize onto Linux — without disrupting SAP, Oracle, analytics, and warehouse systems.
What I did
Re-platformed the estate from AIX to Linux: migrated SAP to SAP HANA on Linux, moved Oracle databases (RAC/Exadata), and rehosted the app tiers — Apache Tomcat, Cognos, ETL, and the Manhattan WMS. Introduced Ansible Tower — the company's first automation — for server & user provisioning, service integration, and config-drift detection. Then led the build-out toward SOC 2 compliance.
Result
Mission-critical workloads modernized off locked Power hardware onto Linux, SAP running on HANA, the org's first automation framework in place, and the business prepared for SOC 2 audit.
CASE 03 · MONITORING PLATFORM · HIGHER EDUCATION
Replaced legacy monitoring with a 3,000-check Nagios XI platform
The challenge
A university's monitoring ran on aging Xymon — limited visibility across a multi-site estate of servers, applications, databases, and network gear, with no automated alerting into the ticketing system.
What I did
Migrated all monitored systems from Xymon to Nagios XI, importing 3,000 custom service checks spanning server health, applications, databases, firewalls and switches. Wrote custom scripts to monitor home-grown identity applications, configured multi-level escalations and paging, and integrated the ticketing API so alerts auto-create and assign tickets.
Result
A from-scratch monitoring platform with 3,000 checks and closed-loop alerting — full visibility across servers, apps, databases and network, with incidents raised automatically.
CASE 04 · VMWARE / STORAGE · ZERO DOWNTIME
Live SAN migration of ~500 VMs — zero downtime, delivered solo
The challenge
A ~400–500-VM VMware estate needed its entire storage platform migrated off a legacy Dell SAN onto Dell Compellent, plus a 10GbE network upgrade — with no acceptable downtime for staff or students.
What I did
Certified as a Dell Compellent administrator for the project, added dual-port 10GbE NICs and cabled in the new SAN myself, built new datastores, and live-migrated every VM with Storage vMotion — then decommissioned and returned the old array once clear.
Result
~400–500 VMs moved fully online with zero downtime and no user impact — delivered end to end, single-handed, cabling included.
CASE 05 · MULTI-CLOUD · AZURE + OCI
Multi-cloud delivery: Azure platform & identity, plus an OCI lift-and-shift
The challenge
Two enterprises, two clouds: one needed a governed, secure Azure platform with central identity and protected workloads; the other needed its Oracle EBS / Exadata estate migrated into Oracle Cloud (OCI) — both with cost and compliance under control.
On Azure
Designed the management-group & subscription governance and prod/non-prod landing zones, integrated Entra ID (Azure AD) SSO, and built Bicep IaC pipelines that deploy VMs repeatably with Key Vault secrets and NSGs — nothing hardcoded. Engineered Azure Backup (Recovery Services Vault) with full file-level and whole-VM restore runbooks.
On OCI
Lift-and-shifted Exadata (prod & non-prod) and EBS apps onto Oracle Linux, provisioned via Terraform, centralized access with Okta SSO and PCI-compliant bastions, and automated cost shutdown of idle/non-prod systems.
Result
Production workloads delivered, governed and protected across both Azure and OCI — migration, identity, infrastructure-as-code, and backup/restore proven on each.
CASE 06 · HPC & ENGINEERING
GPU-accelerated HPC cluster for CFD — remote 3D visualization that finally worked
The challenge
Engineers needed to run CFD jobs on a ~24-node HPC cluster from Linux workstations — but couldn't get GPU-accelerated 3D graphics to display remotely, since standard remote-desktop tools don't drive the GPU.
What I did
Designed the full cluster topology and architecture — a PBS Pro scheduler distributing jobs across the nodes — and solved the visualization problem with NVIDIA GPU-accelerated remote sessions over Linux. Automated file transfer, built the end-to-end user workflow, and integrated Active Directory so AD logins map straight to cluster accounts.
Result
Engineers could submit CFD jobs and see GPU-rendered 3D results remotely, with seamless AD-based access — a working visualization pipeline where remote GPU graphics had simply failed before.