Mohammad Mustaque A.
Enterprise Cloud & Infrastructure Security Architect | Zero Trust/SASE
I help enterprises design, build, and operationalize security architectures that protect critical infrastructure without slowing the business down. With deep expertise across Azure, AWS, GCP, and Oracle Cloud Infrastructure, I bring a security-by-design philosophy to every engagement โ embedding controls into the architecture itself rather than bolting them on after deployment. As a CISSP-certified Cloud and Application Security Engineer, I've delivered security outcomes for global enterprises and managed service clients across financial services, healthcare, technology, and aviation sectors. My work spans landing zone design, FortiGate Active-Passive HA deployments via Terraform, Zero Trust Network Architecture, SASE rollouts (FortiSASE, Zscaler ZIA/ZPA), PCI DSS 4.0.1 compliance, and incident response for sophisticated supply-chain and identity-based attacks. What sets my engagements apart: I treat infrastructure as code from day one โ every FortiGate cluster, Front Door hardening pattern, or hub-and-spoke topology I design is reproducible, version-controlled, and audit-ready. I diagnose root causes rather than patch symptoms, and I deliver client-ready documentation alongside the technical build so your team can operate what I hand off. Core service areas: Cloud security architecture and migration across Azure, AWS, GCP, and OCI, including secure landing zones, hub-and-spoke designs, and shared responsibility mapping. Zero Trust and SASE design and implementation using FortiGate ZTNA, FortiSASE, and Zscaler ZIA/ZPA. Enterprise SD-WAN architecture with integrated security controls. Multi-layer defense-in-depth deployments covering perimeter, application, identity, and data layers. Compliance audits and remediation aligned to PCI DSS 4.0.1, NIST CSF, and CIS Benchmarks. Threat intelligence program design, integration with SIEM/SOAR, and security data lake architecture. Disaster recovery design, implementation, and tabletop validation. Vulnerability assessment, management, and continuous posture improvement. Incident response leadership for cloud-native and supply-chain attacks. Recent enterprise engagements include: Architecting and deploying FortiGate Active-Passive HA clusters in Azure and OCI using Terraform with strict naming conventions and DR replication. Hardening Azure Front Door, Application Gateway, APIM, and Storage origins to enforce strict client-to-API and client-to-web traffic flows using Web Application Firewall. Leading incident response for Application performance due to the limitation of Microsoft Throttling the connection. Resolving Azure App Service TLS handshake throttling at 8.5M handshakes/minute through Cloudflare proxy migration. Designing privileged access monitoring and passwordless authentication strategies (Windows Hello for Business, FIDO2, CyberArk, BeyondTrust) for RFP responses. Certifications: CISSP โ Certified Information Systems Security Professional CEH โ Certified Ethical Hacker ECSA โ EC-Council Certified Security Analyst CASA โ Certified AlgoSec Security Administrator ZTCA โ Zero Trust Certified Architect MCSA โ Microsoft Certified Solutions Associate How I work: Every engagement starts with understanding your environment, business drivers, and risk appetite โ not with a templated solution. I deliver complete, ready-to-use artifacts (Terraform modules, runbooks, architecture decks, compliance evidence packages) and stay engaged through operational handoff. If you're scaling cloud workloads, preparing for an audit, responding to an active incident, or modernizing toward Zero Trust, let's talk about what success looks like for your team.