Available for opportunities · Lahore, PK & Remote

Muhammad Saim Ali

$ whoami → DevSecOps Engineer

Building secure, scalable, cloud-native platforms through automation, security, and infrastructure engineering. AWS Certified · Kubernetes · Terraform · GitOps.

Lahore, Pakistan
Muhammad Saim Ali
aws · kubernetes
cluster: healthy
trivy scan
0 critical · 0 high
saim@devsecops:~
$ kubectl get pods -A | wc -l
→ 142 pods running
$ terraform plan -out tfplan
→ Plan: 24 to add, 0 to destroy
About

Engineer at the intersection of cloud, security & automation.

I'm a DevSecOps Engineer who lives at the intersection of cloud, security, and automation. Currently shipping production infrastructure at WaxonIT Solutions while finishing my BS in Software Engineering.

My playground is AWS, Kubernetes, Terraform, ArgoCD, Prometheus, and Trivy — designing pipelines where security isn't an afterthought, it's the default.

The next chapter: AI/ML DevSecOps. The same discipline of securing distributed systems, applied to model pipelines, inference platforms, and AI infrastructure.

3.68
CGPA
4+
Certifications
10+
Projects
2022
BS Software Engineering
University of Lahore · CGPA 3.68
2024
Security Research & Bug Bounty
NADRA disclosures · Responsible vulnerability research
Sept 2025
DevSecOps Engineer @ WaxonIT Solutions
AWS · Terraform · Kubernetes · GitOps · Security
Next
AI/ML DevSecOps Engineer
Platform security → MLOps → AI infrastructure
Stack

The toolbox I ship production with.

Cloud-native infrastructure, GitOps delivery, deep security tooling, and observability that actually pages on real signal.

Cloud & Infrastructure

AWSEC2VPCRDSS3IAMRoute53ALBTerraform

DevOps & CI/CD

GitGitHub ActionsCI/CD PipelinesLinuxNginxBash

Containers & Kubernetes

DockerKubernetesHelmArgoCDGitOps

Monitoring & Observability

PrometheusGrafanaLokiNode ExportercAdvisor

Security

Burp SuiteNmapSQLMapTrivySonarQubeNucleiMetasploitWireshark

Programming

PythonBashSQL
AWS & Cloud Architecture88%
Kubernetes & Helm85%
Terraform / IaC90%
CI/CD & GitOps87%
Security & Pentesting82%
Observability Stack80%
Experience

Shipping real infrastructure, today.

Current Role

DevSecOps Engineer

WaxonIT Solutions
Sept 2025 — Present
Provisioned multi-tier AWS infrastructure (EC2, VPC, RDS, ALB, Route53) using Terraform IaC
Built end-to-end CI/CD pipelines with GitHub Actions and ArgoCD GitOps deployments
Deployed and operated Kubernetes workloads with Helm charts across staging & prod
Implemented security scanning (Trivy, SonarQube, Nuclei) in pipelines — shift-left security
Built monitoring stack: Prometheus, Grafana, Loki, Node Exporter, cAdvisor
Performed penetration testing & vulnerability assessments on production systems
Certifications

Credentialed across cloud, containers & security.

AWS Certified Solutions Architect

Amazon Web Services
Verified
Associate

Docker Certified Associate

Docker Inc.
Verified
DCA

IBM Certified Penetration Tester

IBM
Verified
Cybersecurity

AWS Certified Cloud Practitioner

Amazon Web Services
In Progress
Foundational
Selected Work

Projects with teeth.

Production-style platforms and security work that demonstrate real engineering, not just slideware.

VPC
EKS
RDS
ALB
S3
IAM

Enterprise DevSecOps Platform

End-to-end secure delivery platform on AWS with IaC, GitOps, security scanning, and observability baked in.

AWSTerraformGitHub ActionsArgoCDTrivySonarQube
  • Multi-env IaC
  • Policy as Code
  • Shift-left scanning
  • Zero-touch deploys
VPC
EKS
RDS
ALB
S3
IAM

Kubernetes Multi-Tier Deployment

Production-grade Kubernetes deployment with Helm-templated services, autoscaling, and full observability.

KubernetesHelmPrometheusGrafana
  • HPA + PDB
  • Ingress + TLS
  • RBAC hardening
  • Service mesh ready
VPC
EKS
RDS
ALB
S3
IAM

Monitoring & Observability Platform

Unified metrics + logs platform with dashboards, alerting, and node-level container telemetry.

PrometheusGrafanaLokiNode ExportercAdvisor
  • Custom dashboards
  • Alertmanager
  • Log aggregation
  • SLO tracking
VPC
EKS
RDS
ALB
S3
IAM

Web App Penetration Testing

Responsible disclosure engagements uncovering critical production vulnerabilities across multiple platforms.

Burp SuiteNmapSQLMapMetasploitWireshark
  • NADRA bug bounty
  • Critical CVEs
  • Detailed PoCs
  • Remediation reports
VPC
EKS
RDS
ALB
S3
IAM

Automated Web Security Scanner

Final Year Project — a modular scanner orchestrating OSS security tools into a single CI-friendly pipeline.

PythonNucleiNmapDocker
  • Plugin architecture
  • JSON & HTML reports
  • CI integration
  • Severity scoring
Achievements

Recognized for finding what others miss.

3rd Place — University Coding Competition

Top-3 finish among university-wide teams.

NADRA Bug Bounty Participant

Responsibly disclosed vulnerabilities to a national identity platform.

Critical Production Vulnerability Discoveries

Identified high-severity issues in live production systems.

Responsible Vulnerability Disclosures

Multiple coordinated disclosures with vendor remediation.

University Admission Portal Security Finding

Reported security gap impacting student data on a university portal.

Career Roadmap

From DevSecOps to AI Infrastructure.

A deliberate trajectory: secure cloud platforms today, AI/ML infrastructure tomorrow.

01
Associate DevSecOps Engineer
Foundations · Past
02
DevSecOps Engineer
Current — WaxonIT Solutions
03
Senior DevSecOps Engineer
Scale · Platform leadership
04
Platform Security Engineer
Security-first platforms
05
MLOps Engineer
Model pipelines · GPU infra
06
AI/ML DevSecOps Engineer
AI Infrastructure · Future
Contact

Let's build something secure.

Open to DevSecOps, Cloud Security, Platform, and AI Infrastructure roles. Let's build something secure.