Haider Mirza — Cloud Native Security Engineer

Cloud Native Security Engineer · Seattle

Haider
Mirza

I work at the intersection of cloud infrastructure, systems, and source code — keeping them confidential, integral, and available.

F5
Doctor Now
IMA Financial
Boeing

About

Systems thinker.
Security practitioner.

I don't optimise for writing fast code or chasing language features. I reason about systems — how they connect, where they break, and what happens when they're under pressure.

My work spans cloud providers, Kubernetes control and data planes, reverse proxies, API automation, and the security boundaries between all of them. Across financial services, healthcare, aerospace, and enterprise networking.

If it's complex, distributed, and needs to stay up — that's where I do my best work.

Capabilities

Infrastructure & Cloud

  • AWS
  • GCP
  • Azure
  • Linux
  • Docker
  • Git

Kubernetes & Service Mesh

  • Kubernetes
  • Envoy
  • Control Plane
  • Data Plane
  • Admission Controllers
  • Istio
  • Cilium

Networking

  • DNS
  • TCP/UDP
  • IPv4/IPv6
  • BGP
  • Reverse Proxies
  • Load Balancing

Security

  • Zero Trust
  • mTLS
  • WAF
  • SSO
  • OAuth
  • IAM
  • RBAC

Automation & Dev

  • API Design
  • CI/CD
  • GitOps
  • Terraform

Case Studies

Large Enterprise · 2026

Certificate Lifecycle Management as a Reliability Problem — Automated TLS Renewal, Silent Failure Modes, and the Case for Redundancy

A system design discussion examining how automated TLS certificate renewal pipelines fail silently, the DNS and CA configuration conditions that block renewal without observable signals, and why treating certificate lifecycle as a reliability concern rather than a configuration task is the only durable protection against expiry-driven production outages.

TLSCertificate ManagementACMELet's EncryptDNS-01CAADNSSECmTLSReliability EngineeringProduction Outage
Security Research · 2026

HTTP Request Smuggling via Transfer_Encoding Header Bypass — Envoy Header Normalization Gap

Identified an uninspected HTTP request smuggling vector on an Envoy based cloud reverse proxy where the Transfer_Encoding underscore variant bypasses dedicated CL+TE smuggling prevention controls that block 42+ other obfuscation variants, with a working proof of concept demonstrating end to end bypass.

HTTP SmugglingCL+TETransfer-EncodingEnvoyWAFHTTP/1.1Security Research
Large Enterprise · 2026

HTTP/2 Connection Pool Race Condition — Root Cause Identification and Resolution

Identified and resolved intermittent 503 upstream reset errors affecting external users on a cloud virtual appliance reverse proxy deployment through deep packet capture analysis, Envoy source code review, and HTTP/2 protocol specification research.

HTTP/2Cloud Reverse ProxyConnection PoolingPacket AnalysisEnvoyTCPRFC 7540

Contact

Let's talk.

If you're dealing with a hard systems or security problem and need someone who can reason about it end-to-end, reach out.