Skip to content
Open to new rolesIslamabad, Pakistan

Ali Raza

Network and Security Engineer

I design, deploy and defend enterprise network infrastructure. I hold overall responsibility for the network across 31 IMARAT facilities nationwide, from large offices carrying 600 concurrent users down to small sites of 50, built on FortiGate, Palo Alto, Cisco and Huawei with Zabbix and Wazuh for monitoring and threat detection. I also build the systems I support: my visitor management platform runs at reception every day.

Ali Raza, Network and Security Engineer
IMARAT · IslamabadACTIVE

Facilities nationwide

31

Network infrastructure I own

Peak concurrent users

600

At the largest sites

Availability

99.9%

Sustained across sites

Mean time to resolve

45 min

Reduced from 4 hours

Targeting

  • Network Engineer
  • Network and Security Engineer
  • Infrastructure Engineer
  • Systems Engineer
  • IT Engineer
  • Security Engineer
  • NOC Engineer
  • SOC Analyst
  • IT Operations
01About

Infrastructure engineer with a builder background

I work where the network, the servers and the application meet. That is why an outage rarely stays a mystery for long.

Networks I operate, not networks I have read about

Overall responsibility for the estate across 31 IMARAT facilities: FortiGate and Palo Alto perimeter policy, Cisco and Huawei switching and routing, VLAN segmentation, and site to site VPN interconnect with QoS shaped links.

FortiGatePalo AltoCiscoIPsec VPN

Detection before escalation

A Zabbix NMS polling SNMP and syslog across the estate, alerting into Microsoft Teams, with Wazuh providing centralised security monitoring. Mean time to resolution fell from 4 hours to 45 minutes.

ZabbixWazuhSNMPsyslog

I build the systems I operate

When an infrastructure problem needs software, I write it. The visitor platform running at reception is mine end to end: schema, API, front ends, hardening, deployment and tests.

Node.jsPostgreSQLnginxsystemd

Certifications

  • Microsoft Certified: Azure Administrator Associate

    MicrosoftSeptember 2023

  • Google Cybersecurity Professional Certificate

    GoogleDecember 2024

  • Google IT Support Professional Certificate

    GoogleNovember 2024

  • Fortinet Network Security Expert (NSE 1, 2, 3)

    FortinetAugust 2023

Education

Bachelor of Science, Computer Science

University of Agriculture

Peshawar, KPK · Nov 2021 to Jun 2025

Specialist training

  • Cyber Security

    Network Security, Ethical Hacking, Threat Detection, Risk Management

    Mar 2024 to Jun 2024

  • Cloud Computing

    AWS, Azure, Windows Server Administration, VMware vSphere

    May 2023 to Dec 2023

  • Networking

    CCNA, CCNP Routing and Switching

    May 2023 to Sep 2023

02Experience

Where the work happened

The current role in full. Earlier roles open if you want them.

Current

Network Support Engineer

IMARAT · Islamabad, ICT

Sep 2025 — Present

Hold overall responsibility for the network across 31 IMARAT facilities nationwide, from firewall policy and routing through monitoring, virtualisation and identity.

  • Hold overall responsibility for network infrastructure across 31 IMARAT facilities nationwide, ranging from large offices carrying 600 concurrent users to small sites of 50, sustained at 99.9% availability.
  • Deployed and integrated a Zabbix NMS with Microsoft Teams alerting, cutting incident detection and response time significantly.
  • Deployed Wazuh for centralised security monitoring and threat detection, strengthening the organisation security posture.
  • Configured FortiGate, Palo Alto, Huawei and Cisco infrastructure, achieving a 35% improvement in network scalability.
  • Implemented site to site IPsec and SSL VPNs, cutting inter site data transfer latency by 20%.
  • Tuned QoS policies across the network for optimal bandwidth allocation and consistent performance under load.
  • Reduced mean time to resolution from 4 hours to 45 minutes through a proactive SNMP and syslog monitoring framework.
  • Cut security incidents by 25% through advanced firewall, ACL and IPS hardening.
  • Administered Ubuntu Server and Windows Server environments, including Hyper V and Proxmox virtualisation for internal infrastructure.
  • Managed Microsoft 365 including Exchange Online, SharePoint and Entra ID for organisation wide collaboration and identity management.
FortiGatePalo AltoCiscoHuaweiZabbixWazuhIPsec VPNProxmoxMicrosoft 365

Earlier

03Work

Things I built and still run

Four products in production and the infrastructure programmes behind them. Open any card for the stack and the detail.

01In daily production use at reception

Visitor Management System

Self hosted visitor sign in, pre registration and reporting for 31 office locations

A visitor platform covering desk sign in and sign out, pre registration with emailed QR passes, post visit feedback and management reporting. Built end to end on Node.js and Express over PostgreSQL, deployed to Ubuntu as a systemd service behind nginx with TLS.

  • 47 API endpoints over an 11 table relational schema
  • One codebase running unmodified on both SQLite and PostgreSQL
02Live in production

LeadGen

Sales leads that name a decision maker, with a source behind every field

A B2B lead platform that returns the named owner behind a real business together with their role, their company and the business contact that company publishes. Every field links to where it came from, and a value that was never published stays an empty cell rather than becoming a guess. Findings carry a confidence label and a relevance score out of 100.

  • Source attribution recorded for every individual field
  • Confidence labelling that separates published, inferred and unavailable
03Live in production

Nodeworks

Independent network, infrastructure and security engineering practice

The service practice I run directly: network design, monitoring, segmentation, disaster recovery and the deep dive troubleshooting that other tiers could not close. One engineer end to end, remote worldwide, attending in person when the fault is physical. Vendor neutral, with no hardware resale and no referral arrangements.

  • Single point of contact with no handover between support tiers
  • Remote first delivery scheduled around the client change window
04Live in production

OSINT Platform

Open source intelligence lookups where every finding carries its provenance

An investigation tool that accepts an email address, username, domain, IP address, URL, autonomous system number, certificate fingerprint or cryptocurrency address, and returns what public sources actually say about it. Every finding states its source and how far it can be trusted, using four fixed confidence labels rather than presenting everything as equally certain.

  • Eight input types accepted across one investigation interface
  • Four confidence labels applied consistently to every finding
05Production

Multi Site Enterprise Network

Routed and segmented network across 31 IMARAT facilities nationwide

Overall responsibility for the network estate across 31 facilities nationwide, from large offices carrying 600 concurrent users to small sites of 50: FortiGate and Palo Alto perimeter policy, Cisco and Huawei switching and routing, VLAN segmentation, and site to site IPsec and SSL VPN interconnect with QoS shaped links.

  • 31 facilities nationwide under a single operating standard
  • 99.9% availability sustained across sites

Also delivered

Monitoring and Threat Detection Stack

Zabbix NMS with Teams alerting, plus Wazuh for centralised security monitoring

Built the observability layer for the IMARAT network. Zabbix polls SNMP and ingests syslog across the estate and pushes actionable alerts into Microsoft Teams. Wazuh provides centralised host level security monitoring, log analysis and threat detection.

ZabbixWazuhSNMPsyslog

Internal Virtualisation and Identity Platform

Proxmox and Hyper V workloads with Microsoft 365 identity management

Run internal server workloads on Proxmox and Hyper V across Ubuntu Server and Windows Server guests, and administer organisation wide identity and collaboration through Exchange Online, SharePoint and Entra ID.

ProxmoxHyper VUbuntu ServerWindows Server

NADRA Facility Network Build

Greenfield network deployment for a new national registration facility

Deployed and configured the network infrastructure for a new NADRA facility from empty racks to full connectivity, then held it at target uptime through proactive testing and troubleshooting.

Structured Cabling (TIA/EIA-568)SwitchingRack and patch managementNOC monitoring
04Case Study

Visitor Management System

A visitor platform for 31 offices, built and run single handed. Sign in at the desk, pre registration by emailed QR pass, and management reporting.

API endpoints
47
Database tables
11
Office locations
31
Test assertions
92

What it does

  • 1Reception deskCheck visitors in and out, capture a photo, issue a badge number, and admit a pre registered guest by scanning their QR pass.
  • 2Pre registrationRegister a visitor before arrival. They receive a QR pass by email that checks them in at the desk in a single scan.
  • 3Admin dashboardUsers, roles and site assignments, the visitor register, an audit log, and reporting with charts and a signed off PDF export.
  • 4Post visit feedbackA one tap star rating emailed on check out, recorded against the visit and summarised in the management report.

By the numbers

Lines of code
~14,900
Runtime dependencies
12
Cross engine checks
19 of 19
Server side lines
4,276
05Technical Skills

Grouped by discipline, not by keyword

Eight areas covering the network, the systems beneath it, the tooling that watches it, and the people work that surrounds it. Everything listed comes from work actually done.

Perimeter and edge policy on next generation firewalls, plus the detection layer behind it.

  • FortiGate
  • Palo Alto
  • Ubiquiti USG Pro 4
  • Cisco ASA
  • IPsec and SSL VPN
  • IDS and IPS
  • SIEM
  • MFA
  • ACLs
  • Vulnerability Assessment
  • Threat Detection
  • Incident Response
06Contact

Get in touch

If you are hiring for network, infrastructure or security engineering, I would be glad to talk through what I have built.

Messages are stored on my own server and emailed to me. No third party form service is involved.