Skip to content
Initializing infrastructure000

HADI KHAN

Security & Infrastructure Engineer — Dubai, UAE

CORENETWORKSECURITYCLOUD

CORE

The background of this page is a decorative, scroll-driven 3D visualisation of a hybrid enterprise infrastructure — a central core connected to cloud services, security gateways, network sites, identity services, virtualized compute and backup layers. It carries no information that is not also written on this page.

System onlineHybrid infrastructureDubai, UAE

HADI KHAN

Designing, securing and scaling hybrid cloud and on-premises infrastructure.

7+ years engineering resilient enterprise environments across cloud, networks, security, identity and virtualization.

Download CV
Deira, Dubai, UAE
02Professional summary

Security and infrastructure engineer with 7+ years designing, deploying and hardening hybrid environments that span Microsoft Azure and on-premises data centres.

The work sits where cloud meets the building: Azure subscriptions and Entra ID on one side, domain controllers, hypervisors, firewalls and switch fabric on the other — and a secure, measured path between them.

Delivery runs end to end. Greenfield design, migration, hardening against CIS benchmarks, backup and recovery engineering, and the documentation and SOPs that let a team actually operate what was built.

Hands-on across

  • AZURE
  • FORTINET
  • ACTIVE DIRECTORY
  • VMWARE
  • HYPER-V
  • VEEAM

Point at a platform to illuminate it in the architecture.

0+

Years experience

Enterprise infrastructure, security and cloud engineering.

0.0%

Service availability

Maintained across supported production infrastructure.

03Hybrid cloud engineering

Microsoft Azure architecture, identity, resilience and cost governance.

Cloud estates rarely fail on capability — they drift on cost and ownership. The work is deciding what actually belongs in Azure, connecting it back to the data centre deliberately, and keeping the bill matched to what the business is using.

  • Azure IaaS / PaaS
  • Microsoft Entra ID
  • Azure Backup
  • Azure Site Recovery
  • Azure Files
  • Blob Storage
  • Microsoft 365
  • Azure Cost Optimization

Right-sizing & cost governance

0%

Estimated Azure spend reduction

Right-sizing and cost governance across Azure workloads.

0%

Reduced manual operational effort

Through PowerShell automation of recurring administration.

0+

Users migrated to Microsoft 365

Full mailbox and data migration from G Suite.

Above: cloud resources reorganise as the chapter plays — oversized capacity is reclaimed and the architecture settles into a cleaner shape.

04Network security

Not a product bolted on at the end — a layer designed at the same time as the switch fabric, the domain and the cloud.

Traffic between cloud and on-premises passes through a gateway that decides, every time, whether it should. Multiple gateways report into one management plane so policy is written once and verified everywhere.

  • FortiGate
  • FortiManager
  • FortiAnalyzer
  • FortiSASE
  • FortiAuthenticator
  • FortiNAC
  • SSL VPN
  • IPsec VPN
  • SD-WAN
  • SAML SSO
  • LDAP / Active Directory Integration
  1. 01

    Inspect

    Policy evaluated at the gateway, per session.

  2. 02

    Permit

    Authorised traffic continues to its destination.

  3. 03

    Deny

    Everything else stops at the boundary.

  4. 04

    Log

    Retained centrally for analysis and compliance.

05Multi-site networking

Designing segmented, resilient and centrally managed networks across distributed environments.

A flat network is convenient once and expensive forever. Segmentation decided at design time — which traffic classes exist, what they may reach, and how each site connects back — is what keeps a distributed estate manageable as it grows.

  • Multi-VLAN segmentation
  • Aruba CX
  • FortiSwitch
  • Granular access design
  • Hub-and-spoke topology
  • Distributed networks
  • SD-WAN
  • DNS
  • DHCP

Segmentation model

  • Corporate

    User and endpoint traffic, tied to directory groups.

  • Infrastructure

    Management, hypervisors and storage, isolated from users.

  • Restricted

    Access granted explicitly, never inherited.

1 → 9Sites, connected as one estate
06Centralised management
Project 01Selected work

9-site hub-and-spoke FortiGate deployment

Nine FortiGate firewalls, each configured and maintained independently, brought under a single FortiManager control plane with a documented operating procedure behind it.

  • FortiManager
  • FortiGate
  • ADOM
  • Hub-and-Spoke
  • SOP Documentation
9

Sites

1 management plane

  1. 01Authorised and onboarded nine FortiGate devices into FortiManager.
  2. 02Structured ADOMs and shared policy objects for the estate.
  3. 03Established the retrieve/install sync workflow and change sequence used for policy deployment.
  4. 04Produced formal SOP documentation so the process is repeatable by the wider team.
07Identity

One directory, replicated where the people are — and joined to cloud identity rather than duplicated alongside it.

Building Windows Server infrastructure from scratch means designing the directory before anything depends on it: domain structure, a replication topology that matches the physical sites, and DNS and DHCP that agree with both.

  • Active Directory Domain Services
  • Multi-site AD replication
  • DNS
  • DHCP
  • Group Policy
  • Entra ID
  • SAML SSO
  • LDAP
  • Group-based access

Replication topology

Site A · Primary domain controller
  • Site B · replica controller
  • Site C · replica controller
  • Site D · replica controller

On-premises identity

Cloud identity · Microsoft Entra ID

Directory groups drive access on both sides of the boundary, and SAML federation carries that identity out to cloud-delivered services.

08Security hardening

Configuration drifts quietly. Benchmarks give you something to measure against, and a defensible reason for every control you apply.

The sequence is always the same: establish the baseline, find where the estate has moved away from it, apply controls in an order that does not break the services people use, then verify what actually landed.

  • CIS Benchmarks
  • Active Directory hardening
  • Firewall security audits
  • Infrastructure remediation
  • Security recommendations
Project 03

Multi-Site AD Domain Hardening

Regional hospitality group operating in four UAE emirates

CIS Benchmark controls applied across infrastructure servers, and Active Directory domain hardening carried out across the hotel sites of a regional hospitality group operating in four UAE emirates.

  • 01Assessed existing server and domain configuration against CIS Benchmark controls.
  • 02Applied CIS Benchmark controls across infrastructure servers.
  • 03Performed Active Directory domain hardening across multiple hotel sites.
  • 04Verified control application and remediated deviations.
Read the full case
09Firewall security audit

Project 04

Firewall configurations assessed across the multiple sites of a government entity, with findings turned into a structured set of hardening recommendations.

Client: Multi-site government entity

  • FortiGate
  • Security Audit
  • Firewall Hardening
  • Security Recommendations
  1. 01

    Assess

    Review firewall configuration across every site.

  2. 02

    Identify

    Surface deviations from hardening guidance.

  3. 03

    Prioritise

    Rank findings by security impact and operational risk.

  4. 04

    Harden

    Hand over a structured remediation path.

10Virtualization

Consolidating physical hosts onto hypervisor clusters with shared storage — fewer machines to power, patch and replace, and far more room to move workloads.

At Mace Engineering Technologies a VMware virtualization initiative reduced the physical server footprint by 77%, turning a rack of single-purpose machines into a cluster that could be maintained without taking services down.

  • VMware vSphere
  • Hyper-V
  • Failover Clustering
  • High Availability
  • iSCSI
  • SAN Storage
0%

Reduction in physical server footprint

VMware virtualization initiative consolidating physical hosts.

Before

Physical infrastructure

After

Virtualized infrastructure

Same workloads, a fraction of the hardware — and a platform where high availability finally becomes possible.

11High availability & recovery

Availability is a design decision made long before the outage — and a recovery path is only real once someone has actually walked it.

Protection is layered so that no single failure removes every copy: clustering handles host loss, Veeam handles the data, and Azure keeps a copy somewhere the building cannot affect.

  1. 01

    Primary infrastructure

    The workloads the business runs on.

  2. 02

    High availability

    Failover clustering and VMware HA inside the site.

  3. 03

    On-premises backup

    Veeam Backup & Replication against local storage.

  4. 04

    Cloud backup

    Azure Backup, Azure Files and Blob Storage off-site.

  5. 05

    Recovery

    Site Recovery and a rehearsed restore procedure.

  • Hyper-V Failover Clustering
  • VMware High Availability
  • Veeam Backup & Replication
  • Azure Backup
  • Azure Files
  • Blob Storage
  • Site Recovery
  • iSCSI / SAN
0.0%

Service availability

Maintained across supported production infrastructure.

Disaster recovery time

48h

Before

5h

After

Redesigned backup and recovery processes at Mace Engineering Technologies reduced disaster recovery time from 48 hours to five.

12Core competencies

Each pillar maps to a part of the estate behind this text. Point at one to see which systems it touches.

  • 01

    Cloud & Identity

    Azure architecture, hybrid identity, resilience and cost governance across subscriptions.

    • Microsoft Azure
    • Azure IaaS / PaaS
    • Microsoft Entra ID
    • Azure Backup
    • Azure Site Recovery
    • Azure Files
    • Blob Storage
    • Microsoft 365
    • Cost Optimization
  • 02

    Network Security

    Fortinet security fabric — perimeter, secure access, centralised management and analytics.

    • FortiGate
    • FortiManager
    • FortiAnalyzer
    • FortiSASE
    • FortiAuthenticator
    • FortiNAC
    • SSL VPN
    • IPsec VPN
    • SD-WAN
    • SAML SSO
    • LDAP / AD
  • 03

    Virtualization & High Availability

    Hypervisor clusters, shared storage and failover design that survives host loss.

    • VMware vSphere
    • Hyper-V
    • Failover Clustering
    • Veeam
    • iSCSI
    • SAN
  • 04

    Windows & Directory

    Windows Server estates, multi-site directory replication and core network services.

    • Windows Server
    • Active Directory Domain Services
    • Multi-Site Replication
    • DNS
    • DHCP
    • Group Policy
  • 05

    Network Infrastructure

    Segmented, centrally managed switching and routing across distributed sites.

    • VLAN Segmentation
    • Aruba CX
    • FortiSwitch
    • Distributed Networks
    • Granular Access Design
  • 06

    Security Hardening

    Benchmark-driven configuration control, audit and prioritised remediation.

    • CIS Benchmarks
    • Active Directory Hardening
    • FortiGate Security Audits
    • Remediation
    • Security Recommendations
13Selected projects

Ten engagements across security, cloud, networking, identity, virtualization and resilience. Open a module for the challenge, the approach and what it produced.

Scroll the rail — 10 modules

All projects
14Experience

From supporting infrastructure to owning it — each role covering more of the stack than the last.

  1. Aug 2018 – Nov 2021

    Pakistan

    Mace Engineering Technologies

    IT Support Specialist

    Infrastructure support and modernisation — virtualization, cloud migration and a rebuilt backup and recovery process.

    • Led a VMware virtualization initiative that reduced the physical server footprint by 77%.
    • Migrated 100+ users from G Suite to Microsoft 365.
    • Redesigned backup and recovery processes, reducing disaster recovery time from 48 hours to five hours.
    • Provided infrastructure and end-user support across the organisation.
    • VMware
    • Microsoft 365
    • Backup & Recovery
    • Windows Server
  2. Jan 2022 – Jun 2022

    Dubai, UAE

    Luxury Property

    IT Support Engineer

    End-user and infrastructure support across Microsoft 365, endpoint services and network services for a Dubai real estate business.

    • Delivered end-user and infrastructure support across the business.
    • Administered Microsoft 365 services, accounts and licensing.
    • Managed endpoint services, device provisioning and configuration.
    • Supported network services and day-to-day connectivity issues.
    • Microsoft 365
    • Endpoint Services
    • Network Services
    • Windows
  3. Jul 2022 – Present

    Dubai, UAE

    CADD Emirates

    Azure Cloud & Network Administrator

    Operating and extending a hybrid estate across Microsoft Azure and on-premises data centre infrastructure, with security, identity and resilience owned end to end.

    • Administer Azure infrastructure across IaaS and PaaS workloads, including compute, storage, networking, backup and site recovery.
    • Achieved an estimated 20% reduction in Azure spend through right-sizing and cost governance.
    • Onboarded nine FortiGate sites under centralised FortiManager control with device authorization, ADOM management and documented sync workflow.
    • Deployed FortiSASE with SAML SSO integrated to Microsoft Entra ID for cloud-delivered secure access.
    • Designed and delivered greenfield multi-VLAN network infrastructure using Aruba CX and FortiSwitch.
    • Built Windows Server environments from scratch with AD DS, multi-site replication, DNS and DHCP.
    • Microsoft Azure
    • Entra ID
    • FortiGate
    • FortiManager
    • FortiAnalyzer
    • FortiSASE
    • Windows Server
    • Active Directory
15Certifications

10 certifications across Microsoft Azure, security, networking and cloud architecture, with 2 currently in progress.

  • AZ-104Certified

    Microsoft Azure Administrator

    Microsoft · Cloud administration

    Compute, storage, networking, identity and governance across Azure subscriptions.

  • AZ-700Certified

    Azure Network Engineer Associate

    Microsoft · Cloud networking

    Hybrid connectivity, routing, private access and network security in Azure.

  • AZ-140Certified

    Azure Virtual Desktop Specialty

    Microsoft · End-user compute

    Planning, delivering and managing virtualized desktop infrastructure on Azure.

  • SC-300Certified

    Identity and Access Administrator

    Microsoft · Identity

    Entra ID, authentication, access governance and identity lifecycle.

  • AI-102Certified

    Azure AI Engineer Associate

    Microsoft · AI platform

    Designing and deploying Azure AI solutions and services.

  • AI-900Certified

    Azure AI Fundamentals

    Microsoft · AI fundamentals

    Core AI workloads and services on the Azure platform.

  • FCPCertified

    Fortinet Certified Professional

    Security · Network security

    Fortinet security fabric — firewall policy, secure access and management.

  • CCCertified

    ISC2 Certified in Cybersecurity

    Security · Cybersecurity

    Security principles, access control, network security and operations.

  • CCNACertified

    Cisco Certified Network Associate

    Networking · Enterprise networking

    Routing, switching, IP services, security fundamentals and automation.

  • SAA-C03Certified

    AWS Solutions Architect – Associate

    Cloud · Cloud architecture

    Designing resilient, cost-aware architectures on AWS.

Currently in progress

  • AZ-500In progress

    Azure Security Engineer Associate

    In Progress · Cloud security

    Identity protection, platform protection, security operations and data security.

  • SC-200In progress

    Security Operations Analyst

    In Progress · Security operations

    Threat mitigation using Microsoft Defender and Microsoft Sentinel.

Education

B.S. Computer Science

Lahore Garrison University · Lahore, Pakistan · 2017

All certifications

16 — One connected system

  • Cloud
  • Security
  • Network
  • Identity
  • Compute
  • Backup
  • Multi-site

Hadi Khan

Security & Infrastructure Engineer

Dubai, UAE

17Contact

Available for conversations around cloud, security, infrastructure, networking and enterprise technology.

LinkedIn

Or write directly to hadi.khan.alizai1@gmail.com