Skip to content
ali.naseem_
CV
Solutions Architect · AWS DevOps · AzureRemote · Open to roles

Cloudinfrastructure,automated,securedandbuilttolast.

Four years designing, shipping and running production platforms on AWS and Azure. Terraform, containers, CI/CD and Microsoft 365 security, across healthcare and SaaS.

17
Projects delivered
4+
Years in DevOps
83.7%
Microsoft Secure Score
3
Cloud certifications

01

Idesigncloudplatformsthatarerepeatable,secureandboringtooperate.

My work sits where infrastructure, delivery and security meet: Terraform-defined AWS and Azure environments, dynamic CI/CD pipelines with OIDC and vulnerability scanning, and the monitoring that tells you something is wrong before your users do.

I also run the Microsoft 365 side end to end: Entra ID, Intune, Defender, Exchange and Purview, plus tenant migrations and compliance work (Cyber Essentials, CE+, NHS DSPT, ISO 27001 alignment). Cloud, identity and security in one engineer.

Cyber EssentialsCyber Essentials PlusNHS DSPTISO 27001 alignmentHSCN connectivityLeast-privilege IAMOIDC workload identityVulnerability scanning

02

Numbersfromrealenvironments.

83.7%

Microsoft Secure Score

Raised through systematic identity, endpoint and compliance controls, applied by business need rather than blindly.

100%

Intune compliance

Across 60+ managed devices.

99.99%

Availability

Healthcare analytics platform with monitoring and backup automation.

95%

Less credential exposure

Secrets moved from S3 env files to Secrets Manager with OIDC.

80%

Faster downtime detection

Route 53 health checks and Lambda alerts into Teams.

150

Users on a VoIP system I built

Business VoIP and dialler platform, integrated directly with the company's web app.

10+

Microservices migrated

AWS Lambda to Amazon EKS, plus 100+ metrics in Grafana.

0

Long-lived AWS keys in CI/CD

Bitbucket to AWS via OIDC.

03

WhereI'vebuiltit.

DevOps Engineer · 31G Ltd

Dec 2024 – Present

United Kingdom / Pakistan

  • Design and run multi-environment infrastructure (Dev, QA, UAT, Prod) across a portfolio of healthcare and SaaS platforms on AWS, Azure and Microsoft 365.
  • Terraform as the standard: reusable VPC, ECS/Fargate, ALB, RDS, Redis, IAM and Route 53 patterns with isolated state per environment.
  • Dynamic Bitbucket pipelines with Trivy scanning, OIDC to AWS, environment-aware deploys and post-deployment health validation.
  • Own production troubleshooting across ECS, ALB, CloudFront, RDS, DNS and CI/CD, then fix root causes, not just restart services.
  • Lead Microsoft 365 security and compliance work: Cyber Essentials and CE+, NHS DSPT, ISO 27001 alignment.

DevOps Engineer · Stelle Cloud

Sep 2022 – Nov 2024

Remote

  • Built and maintained AWS infrastructure with Terraform, ECS, EC2, RDS, VPC and IAM, and CI/CD on GitHub Actions and Bitbucket.
  • Cut operational costs by 20% and deployment times by 30%, and reduced manual configuration errors by 40% through Infrastructure as Code.
  • Set up Grafana and Prometheus monitoring, cutting incident response time by 25%.

2021 – 2022

United KingdomCardiff Metropolitan University

BA (Hons) Accounting and Finance

2018 – 2021

United KingdomUniversity of Gloucestershire

BA (Hons) Accounting and Finance with Foundation (transferred)

04

17 projects across AWS, Azure and Microsoft 365.

Client names are kept private. Open any project for its architecture. Keep scrolling to swipe through them.

01
17

scroll to swipe · click a card for its case study

05

Apipelinethatsaysno.

The dynamic Bitbucket pipeline I build for multiple apps and environments. Every release takes the same road, and two gates decide where it ends up: a scan that refuses vulnerable images before anything is built, and a health check that rolls a bad deploy back on its own. Production only ever runs a version that has proven healthy.

Flowchart of the delivery pipeline. A commit on Bitbucket is scanned by Trivy. If the scan finds a critical vulnerability the release is rejected, nothing is built, and Microsoft Teams is notified. If the scan passes, a Docker image is built, published to Amazon ECR and deployed to ECS Fargate with Terraform. A health check then decides: if the service is healthy the release goes live in production; if it returns 503 the deploy is rolled back to the previous task definition, so production stays on the last good version. Every outcome ends with a Teams notification. The animation shows illustrative releases flowing through all three paths at once.
  • OIDC between Bitbucket and AWS, no long-lived keys
  • Separate state and config per environment
  • Reusable scripts instead of copy-pasted shell
  • Rollback checks and health validation

How I work

Zero long-lived keys.

Least privilege by default.

Scanned before it ships.

Everything as code.

  • Zero long-lived keys.
  • Least privilege by default.
  • Scanned before it ships.
  • Everything as code.

07

ToolsIshipwitheveryweek.

fig.07 / toolchain

33 tools

hover a tool

drag to spin

01Cloud & compute05

02IaC & delivery06

03Microsoft 365 & identity05

04Data & observability07

05Also08

AWS services used in production29

VPCECSFargateEKSECREC2LambdaRDSElastiCacheS3CloudFrontRoute 53ACMIAMIdentity CenterSecrets ManagerCloudWatchCloudTrailALBNATDirect ConnectSite-to-Site VPNSESSNSMQEBSDynamoDBTextractWorkSpaces
AWSAzureKubernetesDockerLinuxTerraformBitbucketGitHub ActionsTrivyBashPowerShellEntra IDIntuneDefenderPurviewExchangePostgreSQLRedisSQL ServerGrafanaPrometheusSupersetPower BIVaultCloudflareTwilioWordPressDigitalOceanPythonDBeaverCyberduckMicrosoft 365Microsoft Teams
EC2ECSFargateEKSLambdaRDSElastiCacheDynamoDBS3CloudFrontRoute 53ACMIAMSecrets ManagerCloudWatchCloudTrailVPCALBSESSNSAmazon MQ

08

Experienceacrossdiverse,multiculturalteams.

Across different companies and projects I've worked with people from 14 countries, each bringing their own culture and way of thinking. Every team has sharpened how I communicate, document and solve problems, and the best engineering decisions I've seen came from the most diverse rooms.

14
countries
4
continents

09 — Contact

Let'sbuildsomething reliable.

Open to remote DevOps, cloud and solutions architecture roles. The fastest way to reach me is WhatsApp or email.