Cloud Native Security Engineer · Seattle
Haider
Mirza
I work at the intersection of cloud infrastructure, systems, and source code — keeping them confidential, integral, and available.
About
Systems thinker.
Security practitioner.
I don't optimise for writing fast code or chasing language features. I reason about systems — how they connect, where they break, and what happens when they're under pressure.
My work spans cloud providers, Kubernetes control and data planes, reverse proxies, API automation, and the security boundaries between all of them. Across financial services, healthcare, aerospace, and enterprise networking.
If it's complex, distributed, and needs to stay up — that's where I do my best work.
Capabilities
Infrastructure & Cloud
- AWS
- GCP
- Azure
- Linux
- Docker
- Git
Kubernetes & Service Mesh
- Kubernetes
- Envoy
- Control Plane
- Data Plane
- Admission Controllers
- Istio
- Cilium
Networking
- DNS
- TCP/UDP
- IPv4/IPv6
- BGP
- Reverse Proxies
- Load Balancing
Security
- Zero Trust
- mTLS
- WAF
- SSO
- OAuth
- IAM
- RBAC
Automation & Dev
- API Design
- CI/CD
- GitOps
- Terraform
Case Studies
Certificate Lifecycle Management as a Reliability Problem — Automated TLS Renewal, Silent Failure Modes, and the Case for Redundancy
A system design discussion examining how automated TLS certificate renewal pipelines fail silently, the DNS and CA configuration conditions that block renewal without observable signals, and why treating certificate lifecycle as a reliability concern rather than a configuration task is the only durable protection against expiry-driven production outages.
HTTP Request Smuggling via Transfer_Encoding Header Bypass — Envoy Header Normalization Gap
Identified an uninspected HTTP request smuggling vector on an Envoy based cloud reverse proxy where the Transfer_Encoding underscore variant bypasses dedicated CL+TE smuggling prevention controls that block 42+ other obfuscation variants, with a working proof of concept demonstrating end to end bypass.
HTTP/2 Connection Pool Race Condition — Root Cause Identification and Resolution
Identified and resolved intermittent 503 upstream reset errors affecting external users on a cloud virtual appliance reverse proxy deployment through deep packet capture analysis, Envoy source code review, and HTTP/2 protocol specification research.
Contact
Let's talk.
If you're dealing with a hard systems or security problem and need someone who can reason about it end-to-end, reach out.