Skip to content
View NaeemDosh's full-sized avatar

Block or report NaeemDosh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NaeemDosh/README.md

About Me

role:         DevOps Engineer & Full-Stack Developer
focus:        Cloud security · Compliance automation · Auditable SaaS
stack:        AWS · Terraform · Node.js · Next.js · PostgreSQL
specialty:    WORM ledgers · Hash chains · Row-Level Security · RBAC
frameworks:   Essential Eight (L1/L2/L3) · CIS Benchmarks
approach:     Secure-by-default · Audit-first · Tenant-isolated
availability: Open for freelance / contract work


Tech Stack

Cloud Providers

Containers & Orchestration

Infrastructure as Code & Config Management

CI / CD

Monitoring, Logging & Observability

Security, Scanning & Secrets

Web Servers, Proxies & Networking

Email Infrastructure & Deliverability

Messaging, Streaming & Queues

Shell, OS & Scripting

Backend

Databases & Caching

Frontend

Testing, Tooling & Dev


What I Build

Cloud & Security Platforms

  • Multi-tenant SaaS on AWS
  • ECS Fargate, RDS Multi-AZ, S3 Object Lock (WORM)
  • KMS-encrypted pipelines, WAF-protected edge
  • Terraform-managed landing zones
  • Region-scoped data residency

Forensic-Grade Evidence Systems

  • SHA-256 hash chains, genesis-block enforcement
  • WORM commit order: S3 → hash → event → ledger
  • Per-tenant chain isolation
  • Immutable audit trails, verification endpoints
  • PII classification and redaction pipelines

Compliance Automation

  • Essential Eight L1/L2/L3 (all 8 strategies)
  • CIS Benchmarks (M365, Chrome, Win11, Server 2022)
  • Control-state engine (PASS / FAIL / UNKNOWN / NOT_ASSESSED / EXCEPTION)
  • Framework mapping engine (E8 ↔ CIS ↔ ISO/NIST awareness)
  • Risk acceptance workflows with expiry and review

Secure API Design

  • Deny-by-default RBAC on every endpoint
  • JWT with tenant context from token only
  • TOTP MFA, MFA re-check for sensitive actions
  • 3-layer idempotency (Redis NX + DB constraint + SQS dedup)
  • Injection and tenant-isolation test suites

Core Skills

Cloud (AWS)

  • ECS Fargate · ECR
  • RDS PostgreSQL Multi-AZ
  • S3 Object Lock / WORM
  • KMS CMK · SecretsManager
  • SQS FIFO · EventBridge
  • Security Hub · Config · CloudTrail
  • WAF · IAM · VPC · Route 53
  • CloudWatch · SES

Backend & Data

  • Node.js · Express · TypeScript
  • REST and GraphQL APIs
  • PostgreSQL (RLS, indexing, migrations)
  • Redis (idempotency, caching)
  • Queue design (FIFO, dedup)
  • Puppeteer server-side PDFs
  • Zod validation · Jest testing

Security & Compliance

  • Essential Eight · CIS Benchmarks
  • OAuth 2.0 · JWT · RBAC
  • TOTP MFA · WebAuthn / FIDO2
  • KMS SSE-KMS · TLS 1.3
  • Immutable hash-chain ledgers
  • Audit trails, verification APIs
  • PII classification & redaction

DevOps & Infra

  • Terraform (modular IaC)
  • Docker · Docker Compose
  • LocalStack for local AWS
  • GitHub Actions CI/CD
  • Nginx · Linux admin
  • Bash scripting · automation

Frontend

  • React · Next.js 14 (App Router)
  • TypeScript · Tailwind CSS
  • Server-side rendering
  • Responsive dashboards
  • REST / GraphQL consumption

Integrations

  • Microsoft Graph (M365, OAuth)
  • Active Directory / LDAP
  • CIS-CAT Pro · Tenable · Qualys
  • AWS Security Hub posture
  • Generic webhook / REST intake

Email Infrastructure & Deliverability

  • Transactional & bulk senders: AWS SES · Azure Communication Services (ACS Email) · SendGrid · Mailgun · Postmark · Amazon Pinpoint · Mailchimp
  • Self-hosted mail stacks: Mailcow · Postfix · Dovecot · OpenDKIM · Rspamd · SOGo · Zimbra
  • Microsoft mail: Microsoft 365 · Exchange Online · ACS SMTP relay · domain verification and consent flows
  • Bulk mail operations: domain + mailbox provisioning at scale · warm-up strategies · rate-limit / throttle tuning · bounce and complaint handling · suppression lists
  • Authentication & deliverability: SPF · DKIM · DMARC (p=reject rollout) · MTA-STS · BIMI · ARC · TLS-RPT · reverse DNS · DNSBL / blocklist remediation
  • DNS providers: Cloudflare · Route 53 · Azure DNS (bulk record automation via APIs)
  • Automation: Python scripts for mailbox creation, DNS record batching, domain verification (Azure/Mailcow/Cloudflare APIs)

GitHub Stats

streak

Let's Work Together

Open to freelance contracts in cloud security, compliance engineering, AWS platform work, and full-stack development.

Footer

Popular repositories Loading

  1. NaeemDosh NaeemDosh Public

    Config files for my GitHub profile.

  2. restreamer restreamer Public

    Forked from datarhei/restreamer

    The Restreamer is a complete streaming server solution for self-hosting. It has a visually appealing user interface and no ongoing license costs. Upload your live stream to YouTube, Twitch, Faceboo…

    HTML

  3. application3 application3 Public

    Dockerfile

  4. application4 application4 Public

    Dockerfile

  5. helm-flux-configs helm-flux-configs Public

  6. flux-deployments flux-deployments Public