Platform · DevSecOps · Cloud · Security & Compliance

Ahsan Iqbal

For 14+ years I've built, automated, and secured mission-critical platforms — across datacenters, multi-cloud, and regulated, air-gapped environments. I pair hands-on infrastructure and DevOps engineering (IaC, CI/CD, OpenShift) with security and compliance: CIS/NIST hardening, Zero-Trust, SOX & SOC 2, and vulnerability remediation. A stalled migration, a platform to modernize, or an estate to secure and make audit-ready — that's the call I take.

Empowering Global Tech Leaders

What I bring to the table

CORE

Platform & Infra Architecture

End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.

PLATFORM

Linux, AIX/Power & OpenShift

Deep Linux and IBM Power (AIX P6–P9) operations, plus OpenShift / KubeVirt virtualization and container platforms.

DEVOPS

Platform & Infra Architecture

End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.

SECURITY

Platform & Infra Architecture

End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.

CLOUD

Platform & Infra Architecture

End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.

MIGRATE

Platform & Infra Architecture

End-to-end design with failure modes mapped up front. Resilience, HA and DR built into the blueprint — not patched on later.

Career Timeline

↓ Full career history, newest first — real dates, confidential employers (sector only).

Jan 2025 — Present

Nuclear Power — Sr. Systems Engineer

Architecting and securing mission-critical R&D infrastructure in a partially air-gapped, NIST/CIS, Zero-Trust environment. Replaced VMware vSphere with OpenShift Virtualization (KubeVirt) — cutting node-failure recovery from ~8 min to under 90s. Deployed OpenShift 4.21 on bare metal (F5 VIPs, full X.509 lifecycle) and OpenShift AI on a GPU cluster (NVIDIA L40/A100). Architected an Azure Government (GovCloud) landing zone for export-controlled (ITAR/EAR) data — subscriptions, VNets, NSGs, IAM — with Bicep IaC pipelines, and deployed IBM ELM (9 modules / DB2) to Azure. Lead architect for the HPC clusters (RHEL/Rocky 8) running thermal, CFD & structural simulation, with PBS Pro scheduling and batch-to-GUI so engineers launch Ansys jobs directly. Automated node imaging (SaltStack/Packer) and unified auth via SSSD/Kerberos/LDAP

Outcome: modern cloud-native engineering meeting federal-grade security and ITAR compliance on a secure, high-performance research platform.

Jun 2021 — Oct 2024

Direct-to-Consumer / Fitness — Lead SysOps Engineer (Remote)

Led a DevOps / SecOps / SRE team. Migrated the Oracle ERP estate to Oracle Cloud (OCI), provisioning all servers as code with Terraform and managing config via Ansible + GitHub pipelines. Built primary/secondary DR for business continuity, ran capacity planning with Splunk/Datadog/AppDynamics, and cut cloud cost by powering down non-peak workloads. Also executed an on-prem datacenter + storage migration (VMware clone + hardware upgrades) and moved boot-from-SAN Cisco UCS servers to Pure Storage. Standardized incident/change/problem management on ITIL

Outcome: ERP modernized to OCI as code, resilient DR in place, and cloud spend actively optimized across a remote-first estate.

Apr 2018 — May 2021

National Retailer — Manager, Storage & Compute

Ran the storage & compute team. Deployed RHEL application servers with CI/CD (Ansible, Jenkins, GitHub), built VMware estates via Terraform, and migrated on-prem Oracle RAC to Exadata Cloud (EXA-CS). Architected new IBM AIX P950 servers and LPARs, migrated mission-critical SAP and DB2, and moved Cognos/ETL from AIX 7.1 to RHEL on VMware. Ran a Hitachi HUS VM → new Hitachi SAN migration plus RHEL Pacemaker clusters with GPFS. On Azure: migrated classic→ARM, built ARM-template deployments, web/worker/VM roles, and VM backup via Recovery Services Vault. Migrated the on-prem Linux stack (ETL, Cognos, e-com, WebSphere + MQ) to AWS, and deployed Datadog for full application/log monitoring

Outcome: a legacy AIX retailer modernized across Linux, three clouds (Azure, AWS, OCI/Exadata), and full observability.

Feb 2016 — May 2018

Higher Education — Infrastructure Team Lead

Led a 4-person infrastructure team. Planned and executed a zero-downtime VM migration from old SAN to new — installed Dell Compellent SC4020 (100 TB), cut hosts from FC over to dual-port 10GbE iSCSI, and migrated all SAN-attached Linux app/DB servers live. Maintained multi-site VMware ESX 5.5/6.0 with Puppet + Red Hat Satellite, and upgraded Dell R710/R610 hardware (SSD, memory, NICs). Migrated identity from Sun Directory (Solaris) to a multi-master 389 LDAP, then on to Active Directory. Replaced Xymon with Nagios XI — imported 3,000 custom service checks, wrote custom monitoring scripts, and integrated the ticketing API for auto-created/assigned alerts

Outcome: a zero-downtime SAN migration of the estate, modern identity, and a 3,000-check monitoring platform built from scratch.

Sep 2015 — Feb 2016

Semiconductor — Systems Administrator (Implementation & Design)

In the implementation & design group, built server infrastructure on Dell M1000e/M620 blades. Upgraded the VMware estate (4.1 → 5.1, vCenter 5.5) and automated provisioning of 500+ VMs with PowerCLI. Built RHEL clustering (10 clusters of 5 nodes, RICCI/LUCI), managed Puppet master/agents, and tuned Linux performance (hugepages, NIC parameters, thread-dump analysis). Diagnosed Java memory leaks in Tomcat/JBoss and configured Active Directory / Centrify authentication across Linux

Outcome: a provisioned, clustered, performance-tuned VMware/RHEL estate with automated deployment at scale.

Jan 2015 — Aug 2015

Pharmacy / Healthcare — System Integration Engineer

Bridged business initiatives and enterprise architecture: designed technical solutions within defined architectures, estimated materials and labor, and coordinated infrastructure delivery across functional groups. Acted as liaison between business, governance, architecture, and operations, evaluated processing requirements with technical leads to finalize hardware configurations, and ran capacity/growth analysis with Splunk/Nagios dashboards

Outcome: solutions delivered to spec across teams — the architecture-and-governance discipline applied end to end.

Jul 2014 — Jan 2015

Banking — UNIX/Linux Lead (Datacenter Migration)

Datacenter-migration lead for the UNIX team, moving 100+ servers (IBM AIX, RHEL 5/6). Created VIO servers and virtual LANs on IBM P770 frames, built custom AIX LPAR profiles, and migrated AIX LPARs from Power 6 to P770 via mksysb/NIM restore with SRDF on EMC VMAX. Built 2/3/4-node AIX database clusters, migrated physical Linux servers via PlateSpin (P2V/P2P) to Cisco UCS, and moved VMware guests datacenter-to-datacenter with SRM + SRDF. Authored detailed migration runbooks and go-live patching procedures

Outcome: 100+ AIX & Linux servers migrated to a new datacenter and storage, with documented, repeatable cutover procedures.

Oct 2013 — Jul 2014

Healthcare Provider — Linux/Unix Lead & SME

Subject-matter consultant in Systems Architecture & Integration: engineered enterprise Linux systems (RHEL 5.4–6.0), designed DNS and network architecture (Cisco switches, ASA firewalls, Brocade load balancers), and tuned Apache Tomcat/JBoss against Oracle and MySQL with JMeter/AB. Ran highly available production on Xen and VMware, benchmarked and stress-tested it, and stood up monitoring with Zenoss/Nagios/SiteScope plus MRTG/Cacti for the network team

Outcome: HA enterprise systems engineered, tuned, and monitored end to end.

Apr 2012 — Sep 2013 · first role

Media & Entertainment — System Administrator

First role: responsible for 300 in-house and 500 remote virtual servers — maintenance, troubleshooting, disk management, availability, and the applications running on them. Strategized disaster recovery for IBM and Sun Solaris servers using NIM and Jumpstart, and monitored the entire Windows/Linux environment with Nagios XI

Outcome: 800 virtual servers kept available with DR and full monitoring — the foundation everything since has built on.

Traget Availability (UPR SLA)
0 %
NOC & Support Options
27 /7
Global Clients
0 +
Years in Business
0 +

Selected Work

Six flagship cases, each: situation → what I did → result. Curated from 10+ projects to show range, not repetition.

CASE 01 · DATACENTER MIGRATION · BANKING

Bank datacenter migration: 100+ AIX & Linux servers, P6 → P770, EMC VMAX

The challenge

A bank had to relocate 100+ mission-critical servers — IBM AIX and RHEL — to a new datacenter, including Power 6 LPARs and physical Linux estates, with no room for data loss.

What I did

Led the UNIX team's migration: created VIO servers and virtual LANs on IBM P770 frames, migrated AIX LPARs from Power 6 to P770 via mksysb/NIM restore with SRDF replication on EMC VMAX, rebuilt 2/3/4-node AIX database clusters, and moved physical Linux servers with PlateSpin (P2V/P2P) onto Cisco UCS. Relocated VMware guests datacenter-to-datacenter using SRM + SRDF, and authored detailed runbooks for every step.

Result

100+ AIX and Linux servers migrated to new hardware, datacenter and storage — fully documented, with go-live patching to production standards and zero data loss.

CASE 02 · PLATFORM MODERNIZATION · NATIONAL RETAILER

AIX → Linux transformation: ~800 VMs, SAP HANA, automation & SOC 2

The challenge

~800 VMs and ~40 TB of mission-critical apps were running on platform-locked Power 6/7 (AIX). Rather than pour budget into P8/P9, the business needed to modernize onto Linux — without disrupting SAP, Oracle, analytics, and warehouse systems.

What I did

Re-platformed the estate from AIX to Linux: migrated SAP to SAP HANA on Linux, moved Oracle databases (RAC/Exadata), and rehosted the app tiers — Apache Tomcat, Cognos, ETL, and the Manhattan WMS. Introduced Ansible Tower — the company's first automation — for server & user provisioning, service integration, and config-drift detection. Then led the build-out toward SOC 2 compliance.

Result

Mission-critical workloads modernized off locked Power hardware onto Linux, SAP running on HANA, the org's first automation framework in place, and the business prepared for SOC 2 audit.

CASE 03 · MONITORING PLATFORM · HIGHER EDUCATION

Replaced legacy monitoring with a 3,000-check Nagios XI platform

The challenge

A university's monitoring ran on aging Xymon — limited visibility across a multi-site estate of servers, applications, databases, and network gear, with no automated alerting into the ticketing system.

What I did

Migrated all monitored systems from Xymon to Nagios XI, importing 3,000 custom service checks spanning server health, applications, databases, firewalls and switches. Wrote custom scripts to monitor home-grown identity applications, configured multi-level escalations and paging, and integrated the ticketing API so alerts auto-create and assign tickets.

Result

A from-scratch monitoring platform with 3,000 checks and closed-loop alerting — full visibility across servers, apps, databases and network, with incidents raised automatically.

CASE 04 · VMWARE / STORAGE · ZERO DOWNTIME

Live SAN migration of ~500 VMs — zero downtime, delivered solo

The challenge

A ~400–500-VM VMware estate needed its entire storage platform migrated off a legacy Dell SAN onto Dell Compellent, plus a 10GbE network upgrade — with no acceptable downtime for staff or students.

What I did

Certified as a Dell Compellent administrator for the project, added dual-port 10GbE NICs and cabled in the new SAN myself, built new datastores, and live-migrated every VM with Storage vMotion — then decommissioned and returned the old array once clear.

Result

~400–500 VMs moved fully online with zero downtime and no user impact — delivered end to end, single-handed, cabling included.

CASE 05 · MULTI-CLOUD · AZURE + OCI

Multi-cloud delivery: Azure platform & identity, plus an OCI lift-and-shift

The challenge

Two enterprises, two clouds: one needed a governed, secure Azure platform with central identity and protected workloads; the other needed its Oracle EBS / Exadata estate migrated into Oracle Cloud (OCI) — both with cost and compliance under control.

On Azure

Designed the management-group & subscription governance and prod/non-prod landing zones, integrated Entra ID (Azure AD) SSO, and built Bicep IaC pipelines that deploy VMs repeatably with Key Vault secrets and NSGs — nothing hardcoded. Engineered Azure Backup (Recovery Services Vault) with full file-level and whole-VM restore runbooks.

On OCI

Lift-and-shifted Exadata (prod & non-prod) and EBS apps onto Oracle Linux, provisioned via Terraform, centralized access with Okta SSO and PCI-compliant bastions, and automated cost shutdown of idle/non-prod systems.

Result

Production workloads delivered, governed and protected across both Azure and OCI — migration, identity, infrastructure-as-code, and backup/restore proven on each.

CASE 06 · HPC & ENGINEERING

GPU-accelerated HPC cluster for CFD — remote 3D visualization that finally worked

The challenge

Engineers needed to run CFD jobs on a ~24-node HPC cluster from Linux workstations — but couldn't get GPU-accelerated 3D graphics to display remotely, since standard remote-desktop tools don't drive the GPU.

What I did

Designed the full cluster topology and architecture — a PBS Pro scheduler distributing jobs across the nodes — and solved the visualization problem with NVIDIA GPU-accelerated remote sessions over Linux. Automated file transfer, built the end-to-end user workflow, and integrated Active Directory so AD logins map straight to cluster accounts.

Result

Engineers could submit CFD jobs and see GPU-rendered 3D results remotely, with seamless AD-based access — a working visualization pipeline where remote GPU graphics had simply failed before.

WHY CHOOSE TUWA

Ready to Transform Your Digital Future?