IT that just works.

IT manager & identity specialist · Kitchener, Ontario

I build the systems behind employee identity, devices, and SaaS. About ten years in IT so far, split between startups, enterprise, and healthcare, with a specialty in identity and access: Okta, SSO, and the lifecycle automation that gets a new hire working in minutes instead of hours.

Right now I run IT for a denture clinic group with eight locations across Ontario. Small team, a lot of ground to cover: identity and access, ITSM, infrastructure, and the documentation that keeps it all workable. On the side I build things: an AI assistant's LLM layer, a threat-monitoring lab, and the platforms behind a nonprofit I founded.

Identity Okta/SAML & OIDC/SCIM/MFA & YubiKey/RBAC/conditional access & network zones/lifecycle automation
Platforms Google Workspace/Active Directory/Microsoft 365/Slack/Notion/Jira/Asana/Salesforce/HiBob
Endpoints & assets Miradore/Mosyle/Snipe-IT/Kaseya RMM/macOS, Windows, iOS & Android/BitLocker & FileVault/procurement
Operations ITSM/Jira/Zendesk/monitoring/backups & DR/vendor management
Systems Linux (RHEL, Debian)/shell scripting/Docker/Proxmox/UniFi & Ubiquiti/CrowdSec/Cloudflare Zero Trust
AI & automation LLM pipelines/retrieval & embeddings/role-scoped assistants/self-hosted LLM for regulated data/TTS & STT/Python (project work)/Zapier (personal)
~10years in IT
35+apps behind Okta SSO
80%provisioning time cut
250+onboardings automated
4,000+assets in Snipe-IT
15,000+assets at a dealership group
40+sites networked
8,000+youth reached

Work

2024 — now

Zanib Malik Denturist Professional Corporation

IT Manager · Ontario

Sole IT lead for an 8-location denturist clinic group (Christie Implant Denture Clinic and affiliated clinics), with patient health information in play under Ontario's PHIPA.

Hide the detail
  • Run the IT and operations systems behind everything: communications, patient administration, staff collaboration, documentation, and day-to-day clinic workflows
  • Own identity and access for every clinic system: user provisioning, role-based access, SaaS permissions, and security rules
  • Took over an operation of 25 staff running on paper files and post-it notes. Digitised the filing system and had the paper shredded, put BitLocker on every machine, and automated the daily, weekly, and monthly reminders people kept losing
  • Built a knowledge base with role-based access, so an answer that took a day, or weeks if the one person who knew was on vacation, now takes seconds
  • Automated payment tracking so we know who still owes for their dentures and how long it has been, plus reporting on top of DOMx because its own tracking wasn't good enough
  • Built DentureFlow, the production system the labs run on. A patient's impressions open a case, barcodes follow it through every stage, and the work is routed with time estimates based on what the assignee already has on their bench. It syncs with the 3D hardware that prints the dentures, and reception can see where any case is and who has it
  • Gave referring dental offices their own accounts on it, so they send us a patient's details before the first visit. The information is there when the patient arrives
  • Moved the group off basic phone lines onto a VoIP system with one number and department routing, so a caller reaches the right clinic's reception
  • Integrated Slack with the phone system so missed calls and voicemails reach the right people and actually get followed up
  • Built the Notion knowledge base holding IT documentation, clinic procedures, onboarding guides, troubleshooting steps, and access rules
  • Handle the patient-data privacy obligations that come with healthcare IT in Ontario

Stack: Google Workspace, Slack, Notion, Quo/OpenPhone, DOMx, BitLocker

2021 — 2024

Aiven

Senior IT Engineer · led IT for North America · remote · Toronto

Scope: six-person global IT team · US$200k annual budget for North America · one direct report

Handover: a colleague shadowed the role to move out of hiring and into IT, and took it over when I left

Global open-source data-platform company (managed Kafka, PostgreSQL, and more), scaling fast across Europe and North America. LinkedIn's algorithm gets the credit for this one. It found me the job.

Show what I did (18 points)
  • Built the automated onboarding/offboarding framework connecting HiBob, Okta, and Google Workspace. Provisioning went from about two and a half hours to about thirty minutes, an 80% cut
  • Set up zero-touch device deployment and ran it for 250+ new hires. Hiring triggered an automation that told me who was joining and in what role, so I ordered the right Apple hardware and Miradore had it enrolled before it shipped. The machine arrived ready and the new hire just signed in
  • Ran the Miradore MDM estate across macOS, Windows, iOS, and Android, including iPads provisioned for the marketing team, with FileVault and BitLocker encryption enforced
  • Issued YubiKeys to every employee and provisioned them through Okta, so phishing-resistant hardware keys were the default way people logged in
  • Designed the conditional access rules: sign-in only from managed devices, sessions capped at 24 hours before re-authenticating with a YubiKey, and geographic restrictions that stopped a device authenticating from a country outside our approved list
  • For high-privilege accounts, device, country, and IP all had to match or the sign-in failed. Travel outside the approved list went through a review against the person's role and the data they handled, which either approved it or granted a time-boxed window. How strict it was depended on what the person could reach
  • Built an assistant over the internal wiki that answered questions scoped to the asker's role, so people saw what they were entitled to see and nothing else
  • Rolled out Okta SSO with role-based access control across 35+ enterprise services
  • Led a multi-year Digital Workplace Infrastructure roadmap: standardised identity, access, and integration patterns with centralised governance
  • Tracked 4,000+ assets in Snipe-IT: laptops, monitors, phones, iPads, keyboards, mice, docks, cameras, headphones, and the Logitech conference-room kit, with documentation solid enough to pass compliance audits without scrambling
  • Ran IT procurement and vendor relationships with Lenovo, Apple, Microsoft, Adobe, and Google
  • Looked after UniFi networking in offices around the world, each with a backup 5G modem so a local internet outage didn't stop the office working
  • Ran the logistics behind all of it: ordering, shipping, and working around Apple supply delays when the world made that hard. A leaving employee's laptop went either to a new joiner or into storage and back out again, matched to whoever needed it by role, with the IT closet kept reconciled against Snipe-IT
  • Built role-based ordering lists so peripherals went out without anyone deciding again each time. Pick the list for the role, and the mouse, display, keyboard, and camera ship to the new hire
  • Set up Google Meet at the admin level and got the Logitech room hardware working with it
  • Wrote the device buy-out policy and the instructions that went with it. Reach three years and the laptop, monitor, or phone is yours to keep. Leave before that anniversary and you have the option to buy it out at a calculated price, or return it. That meant fewer awkward conversations and fewer devices quietly disappearing
  • Deployed KnowBe4's Phish Alert Button so anyone could flag a suspicious email in one click and send it to security to analyse
  • Worked day to day with Security and HR on identity, access, and automation tied to compliance and the employee lifecycle

Stack: Okta (SSO, SCIM, lifecycle, YubiKey, conditional access and network zones), Miradore MDM, Google Workspace, HiBob, Snipe-IT, Jira, 1Password, Slack, SAML/OIDC across 35+ vendors · SOC 2

2019 — 2021

Performance Auto Group

Senior IT Technician · Brampton, Ontario

Auto dealership group with 1,500+ employees across 40+ dealerships.

Show what I did (8 points)
  • Provided IT support across all dealership locations through Zendesk, covering 1,500+ employees
  • Administered Active Directory, VoIP phones, printers, cameras, and Windows endpoints; looked after 15,000+ IT assets across the branches
  • Owned the UniFi networking across 40+ dealerships, each of which needed its own build, managed mostly remotely through the UniFi controller
  • Ran UPS units on the equipment that couldn't afford to drop, like cameras, so a power cut didn't take them offline
  • Migrated roughly 1,500 machines across 40+ dealerships from Windows 7 to 10 with Kaseya, rolling it out by geographic cluster so that if something broke, the affected sites were close together and reachable rather than scattered across the province
  • Some machines had to stay on Windows XP because the software they ran wouldn't work on anything newer, so I segmented those off the rest of the network while keeping management access through Kaseya
  • Set up proactive monitoring and remote support tools that cut downtime and sped up incident response across all sites, including custom alerts on top of what Kaseya gave us out of the box
  • Handled ordering and asset logistics across the branches, keeping the physical stock and the asset records telling the same story

Stack: Active Directory, Kaseya RMM, Zendesk, Windows fleet, UniFi across 40+ sites, 3CX VoIP, UPS

2018 — 2021

CarBe

Senior IT Technician · remote, part-time · New Orleans

Show what I did (4 points)
  • Oversaw the daily performance of computer systems and provided technical support for hardware and software issues
  • Entered and monitored system commands to catch errors early, before users felt them
  • Developed training materials and guided users on systems and applications
  • Used diagnostics, technical manuals, and user feedback to investigate issues and keep IT operations stable
2017 — 2018

Forex Plus

Senior Network Technician · Brampton, Ontario

Show what I did (5 points)
  • Maintained and administered computer networks for 800+ clients and a 10-person office: hardware, systems software, applications, and configurations
  • Ran regular data backups and disaster recovery drills
  • Diagnosed hardware, software, and network issues day to day
  • Planned and implemented security measures for data, systems, and infrastructure
  • Monitored performance from master consoles, coordinated network access, and tuned systems as needed
2017 — 2017

Elucent Enterprises

Data Center Technician · Contract · Herndon, Virginia

Show what I did (4 points)
  • Designed and maintained the databases behind business applications, with a focus on scalability, security, and reliability
  • Planned and ran software upgrades, configured clusters, and set up backup and recovery
  • Improved database performance with load balancing and monitoring
  • Documented schemas and architectures in standard notation so other teams could work from them

Case studies

Eight pieces of work written up properly: what the problem was, what I did, and what I would say about it. One of them is the thing I built that broke.

Read the case studies →

Documentation

The runbooks behind the work above, generalised so they carry nothing confidential.

Five runbooks I have written and run, generalised so they carry nothing confidential: employee onboarding, offboarding and rehire, user access review, phishing response, and device lifecycle including the buy-out terms. Alongside them a fifteen-page guide to VoiceMeeter I wrote for a community rather than for work.

Read the documentation →

How I work

Documentation first. Every place I've worked, the thing that outlives me is the knowledge base: the Notion wiki the clinics run on, the asset records at Aiven that made audits boring, the docs site I hosted from my basement for years just to share what I'd learned. If it isn't written down, it isn't a system. It's a person with a single point of failure.

Automate the second time. The first time a task shows up I do it by hand to understand it. The second time, it gets a script or a workflow. That's how onboarding at Aiven went from two and a half hours of clicking to half an hour of mostly waiting.

And most of my users are denturists, therapy centre staff, or volunteers who have better things to do than learn IT, so I build for the person who will never read the manual. If the secure path isn't also the easy path, people route around it, and then you have neither security nor a system.

Where this started

My dad was a civil engineer in Pakistan, and partly because of that we were one of the first houses around us with the internet wired in. We had two phone lines, which felt like an enormous luxury at the time: one for the internet and one so people could still call the house. I learned the English alphabet on an Apple II.

I've been pointed at computers ever since. Most of what I know in any depth came from hosting game servers, first for friends and family and then for whoever turned up. That is a good way to learn what happens when something breaks at two in the morning and other people are waiting on you.

I still host things for people. When someone asks, I set it up. For years that ran on a Dell PowerEdge R720, which drank power but taught me enterprise server management properly. After that came Proxmox, with a mix of virtual machines and containers. These days I've gone simpler: a UGREEN NAS running Docker. Docker still means a fair amount of manual work depending on what I'm running, but it's easier to live with than the rack was. My firewall went the same way, from pfSense to OPNsense to just using UniFi's own. I learned what I needed to learn from running the complicated version. Now I'd rather have the simple one and the quiet mind.

Projects

Things I build because I want them to exist. Some became products, some are infrastructure for people I care about, one is a decade-old media server that refuses to die.

in development
Pathway to Hope

BrightPath

Encrypted clinic software for autism-therapy (ABA) teams, in development under Pathway to Hope. Native SwiftUI iOS app covering the children roster, session tracking, scheduling, secure messaging, and billing visibility, with parents and staff seeing exactly what their role allows. A child's name, notes, and history are encrypted on the device before they reach the database, under separate clinic and caregiver keys, which makes key recovery the hardest problem in the build rather than an afterthought. PHIPA drives the architecture. The code is private because of what it holds; there's a public write-up on GitHub.

2025 — now
BinaryForge

BudBud

A desktop AI assistant for gamers, built with a small team. I own the LLM layer: prompt design and context handling, model tuning on game knowledge with an embedding pipeline for retrieval, TTS and STT for hands-free voice, and automatic game detection using screenshot recognition so answers reflect what's actually on screen. The hard part was generic answers — a stock model will happily explain what a health bar is. Grounding replies in the current screenshot and retrieved game docs fixed most of that. We tested with real players throughout.

2025 — now
Security lab

Network threat monitoring with AI

CrowdSec running against UniFi/Ubiquiti gear on my home network. It flags anomalies, classifies threats automatically, and shares signals with the CrowdSec community blocklist, so the whole setup gets better at spotting bad traffic over time.

2026
Open source · Rust

ETS2 Radio Companion

A Windows client, written in Rust, that connects Euro Truck Simulator 2 events to a private radio service. A plugin DLL reads game telemetry and hands compact events to a helper process on localhost; the helper owns the network side, with automatic enrollment, retries, and a per-installation credential protected by Windows DPAPI. Players run one installer that finds the game on its own and never type a token. It's the same identity discipline as my day job, pointed at a truck simulator: a restricted enrollment credential, one device credential per install, and nothing sensitive on a game thread. The code and the wire protocol are public.

2015 — now
Home lab

AMS, the automated media server

A media server for friends and family, running since 2015 as a collection of services behind one simple interface. I keep coming back to improve, update, and optimize it. A lot of my Linux, networking, and reliability habits started there.

2019 — 2022
Self-hosted · retired

Exitium documentation site

A self-hosted documentation site, built on BookStack, for sharing my project write-ups with anyone who wanted them. It included a fifteen-page guide I wrote for setting up VoiceMeeter Banana with Discord, which got passed around gaming communities including the PCMR Discord.

The part I liked came later. A stranger in Italy found the guide, emailed me asking how to build a macro that muted his microphone, and I wrote back with the settings. He replied: it all works perfectly, thank you so much. That is the whole argument for writing things down.

Pathway to Hope

I founded a federally registered nonprofit running free mental health and addiction education for people aged 13 to 25, run out of Kitchener and open across Canada. It has reached more than 8,000 young people. I built the technology behind it and still handle much of the technical side, including the three-tier access model that copes with around fifty volunteers arriving and leaving.

The full story, and how the access model works →

Community

I came to Canada from Pakistan in 1999, when I was six. A lot of my volunteer work is about returning some of what this country gave my family, usually by being the IT department a nonprofit could never afford.

2015 — 2018

Velocity

IT Technician, Network Technician, Security Advisor (volunteer)

  • IT, Linux, and security support for early-stage teams at the University of Waterloo startup incubator
  • Wikis and documentation sites, Linux user and security management, database backup and recovery
2016 — 2018

Cultured.bio

Senior IT Technician, Linux Server Administrator, Security Advisor (volunteer)

  • Ran websites and wikis for multiple Velocity groups, each on its own subdomain
  • Load balancing and process queuing for Linux applications to maximize performance and reduce downtime
  • Network infrastructure setup and security

Education

2013 — 2015

Sheridan College

Computer Engineering Technician, Information Technology

Networking, computer and server systems, security, CI/CD pipelines, and industry-standard IT practices. Later added the Red Hat RHCSA Rapid Track course.

Contact

Looking for: senior IT or IAM roles, remote or Waterloo region. Startups are my favourite kind of company. I was at Aiven while it scaled and around Velocity teams for years, and I like being the person who builds the IT function before there is one. Also happy to talk identity, automation, or IT operations war stories.

Message me on LinkedIn GitHub Resume (PDF)