45 viewsTalent
Amir H. — Senior Infrastructure Engineer from Malaysia

Amir H.

Senior Infrastructure Engineer

Malaysia 6+ years
Open to offersNew to Platform
Languages
English
Video Introduction
No video introduction yet
The candidate has not added a video.
Contact information and social networks are private. Connect to unlock.
Hidden

About

Amir H. is a seasoned Senior Infrastructure Engineer based in Cyberjaya, Malaysia, with over six years of expertise in network automation, security hardening, virtualization, and hybrid-cloud integration. Utilizing tools such as Ansible, GitHub, FortiGate, and VMware vSphere, he has excelled across global enterprise environments, automating workflows and achieving high efficiency. Amir has driven initiatives leading to a 99.5% security configuration score, managing complex 802.1X NAC deployments, and using Infrastructure-as-Code to accelerate deployment cycles. In his current role at Deriv, he has optimized firewall operations, strengthened security postures, and implemented AWS Transfer Family integrations. He continues to lead by designing and enforcing VLAN segmentation and mentoring junior engineers. Amir's work is characterized by a commitment to reducing manual interventions and enhancing network reliability and compliance. His efforts have significantly reduced unauthorized access risks, standardized global network deployments, and optimized internet utilization for large user bases.

Experience

  • Senior Infrastructure Engineer

    Deriv · 2023 — Present
    Automated global firewall operations by developing Ansible playbooks and GitHub workflows, which halved policy deployment time across over 20 FortiGates while reducing configuration errors. Worked alongside the Security team to enhance FortiGate configurations, achieving a 99.5% Security Configuration Assessment score (Qualys) and applied IaC principles to harden switches. Deployed AWS Transfer Family with S3 and Security Groups, facilitating secure automated file exchange and decreasing manual workload. Managed Zero-Trust network access through the integration of 802.1X wired authentication (Cisco IBNS 2.0 & Portnox Cloud NAC) and VLAN segmentation into an Ansible automation pipeline, ensuring 100% endpoint compliance across sensitive assets while minimizing unauthorized access risks. Set up FortiGate admin users integrated with Portnox NAC using RADIUS, to enhance control of access through role-based grouping and custom attributes. Developed high- and low-level network designs and enforced VLAN segmentation for sensitive systems, bolstering compliance and isolating critical assets across global offices. Centralized management of FortiGates was facilitated via FortiManager utilizing Jinja2 CLI templates, global policies, and Local-in policies to eliminate configuration drift and improve security and audit readiness. Designed and executed a FortiGate SD-WAN solution across global WAN links, ensuring internet utilization for over 500 users and maintaining service continuity during disaster recovery drills. Integrated Hamina Wireless design with Aruba Central for enhanced wireless visibility and performance across corporate sites. Introduced workflow automation using N8N for streamlined CI/CD workflow and team collaboration through Slack and GitHub notifications. Engineered a centralized CI/CD pipeline with Ansible playbooks and GitHub Runners, automating configuration management, firmware upgrades, and security patching across a diverse environment of Cisco Catalyst and Aruba CX switches, thereby reducing manual intervention significantly across 20+ international sites. Managed GitHub Secrets for securing Ansible credentials and enhancing automation security in production. Provided mentorship to junior engineers in automation, security best practices, and troubleshooting, contributing to a stronger infrastructure team. Led Root Cause Analysis for complex network incidents, implementing long-term remedies which minimized occurrences of downtime.
  • Information Technology Administrator

    Deriv · 2023 — 2023
    Enhanced efficiency by optimizing FortiGate firewall policies and mitigating misconfiguration risks across various offices. Deployed dot1Q tunneling on Cisco switches to handle multi external same-VLAN traffic efficiently. Executed SSO and MDM integrations for Apple and Linux devices to strengthen access control and improve endpoint management.
  • Information Technology Administrator

    First Source Arya Solutions · 2022 — 2023
    Implemented PfSense OpenVPN tunnels using advanced tunneling combinations, which bolstered redundancy and resiliency in connectivity. Introduced Proxmox for cost-effective virtualization environments.
  • Information Technology Administrator

    Samaneh Electronic · 2021 — 2022
    Designed IPv4/VLAN segmentation for clients and virtualization, enhancing security and reducing broadcast traffic. Standardized network designs and enforced VLAN segmentation for improved security and isolation of critical assets. Upgraded VMware clusters via vSphere Update Manager, reducing patch downtime by 30%. Managed Kerio and PfSense firewalls to reduce unauthorized traffic and enhance compliance. Oversaw Active Directory for over 300 users, ensuring secure authentication and efficient access control. Deployed ESET for endpoint protection, reducing malware incidents and compliance risks by 25%. Directed physical server lifecycle management, standardizing systems and improving asset health.
  • Network Engineer

    Jahan Aria Saman (Contract Projects) · 2014 — 2018
    Served as a Senior Network & Virtualization Engineer for the Ministry of ICT, where the management of high-availability VMware vSphere clusters was carried out for a user environment exceeding 1,000, ensuring a 99.9% uptime for critical government services. As a Data Center Architect for the Forest Range Watershed Management Organization of Golestan, designed and deployed VMware and vCenter clusters with features like HA, DRS, and redundant vMotion, achieving above 99.5% uptime. Integrated EMC VNX 5200 storage with VMware for scalable and resilient data services. Automated virtualization tasks, leading to a 70% reduction in manual intervention and near-zero downtime. In a role as Network Administrator for Behban Shimi Pharmaceutical Co., upgraded VMware ESXi and vCenter from versions 6.0 to 6.7, enabling HA/DRS for around-the-clock availability in pharmaceutical production. Deployed OpenVPN over PfSense firewall, facilitating secure remote access for staff and CCTV monitoring, while implementing HA operations that maintained compliance with pharmaceutical IT standards.

Skills & Expertise

Education

  • Bachelor of Science (B.Sc.) of Computer Software Engineering
    University of Science and Culture · 2009 — 2014

Interested in this professional?

Sign in as an employer to save this profile or invite Amir H. to a job.

Sign in as an employer