Fahad Ameen Rajput
15 Years of Making Systems Resilient.Illuminating vulnerabilities. Automating the rest.
DevOps, security and compliance engineering for startups and fintechs — from the pipeline to the audit evidence.
SOC 2 ✦ GLBA ✦ GDPR ✦ Zero trust ✦ 100% Job Success ✦ 850+ hours
Track record
in infrastructure and security
See evidence
“15 years in infrastructure and security”
Upwork — 100% Job Success · 5.0★ client rating · held Top Rated for almost a year.SOURCE: UPWORKProof
Case studies
Financial services (fintech, US)
Genesys Financial Intelligence (GenesysFI) — maker of Zovox.app, formerly Pocket CFO
Designing and building a compliance-grade observability and audit system for a fintech, as its lead engineer
0 → full
compliance evidence system, designed and built from nothing
Read the case studyProperty technology, Australia
Homiee (homiee.au)
Putting every sale on the right house: the mapping engine behind an Australian property platform
95%
of addresses placed on the right building automatically — so every sale shows on the correct house
Read the case studyServices
What I do
DevOps & Cloud Infrastructure
Pipelines, migrations and deployments that don't need you awake at 2 am.
CI/CD on GitHub Actions and GitLab, blue/green deployments with zero downtime, cloud-to-cloud migrations, containerisation and multi-cloud Kubernetes. Recent work includes moving a dozen sites from LAMP 5 to LAMP 8 and migrating a production estate from GCP to DigitalOcean.
- GitHub Actions
- GitLab CI
- Docker
- Kubernetes
- Terraform
- GCP
- AWS
- DigitalOcean
See evidence
“CI/CD on GitHub Actions”
“CI/CD on … GitLab”
“blue/green deployments with zero downtime”
“blue/green deployments with zero downtime”
“cloud-to-cloud migrations”
“containerisation”
“multi-cloud Kubernetes”
“moving a dozen sites from LAMP 5 to LAMP 8”
“migrating a production estate from GCP to DigitalOcean”
Security & Compliance Engineering
The controls and the evidence an auditor asks for — built, not promised.
SOC 2, GLBA and GDPR control and evidence systems, zero-trust network segmentation, IAM audits, centralised audit logging and sensitive-data redaction in log pipelines. I hold the CSO and GDPR DPO roles at a US fintech, so this is day-to-day work, not a checklist.
- Elasticsearch
- Kibana
- Keycloak
- GCP IAM
- Grafana Alloy
- Zero Trust
See evidence
“SOC 2, GLBA and GDPR control and evidence systems”
“zero-trust network segmentation”
“IAM audits”
“centralised audit logging”
“sensitive-data redaction in log pipelines”
“I hold the CSO and GDPR DPO roles at a US fintech”
Observability & Reliability
Know it's broken before your customers tell you.
Logs, metrics and alerting that watch themselves: Loki and ELK pipelines into immutable storage, Prometheus and Grafana dashboards provisioned as code, health probes, retention and disaster-recovery drills.
- Prometheus
- Grafana
- Loki
- Elasticsearch
- Alloy
- PM2
See evidence
“Logs, metrics and alerting that watch themselves”
“Loki and ELK pipelines into immutable storage”
“Prometheus and Grafana dashboards provisioned as code”
“health probes”
“retention”
“disaster-recovery drills”
Fractional CTO
Technical leadership for a startup that needs a CTO before it can afford one.
Architecture, hiring, roadmap and delivery. Previously CTO and engineering lead at an Australian property-tech startup, leading a team of 18 from first commit to a delivered platform.
- Architecture
- Hiring
- Roadmap
- Delivery
See evidence
“Architecture, hiring, roadmap and delivery”
“Previously CTO and engineering lead at an Australian property-tech startup”
“leading a team of 18”
“from first commit to a delivered platform”
Packages
How it starts
Every engagement starts with the Tier 1 audit.
Why start with an audit? You see our work for $500 before committing more. We see your stack before quoting. Nobody buys blind.
Tier 1
$500 audit
$500* one-time
Tier 2
Project
Custom — scoped per project
Tier 3
Hire Fahad
$50/hour
Tier 4
Streetlight team
From $8,000/month
*Book a project or retainer within 90 days of your audit and the $500 is credited to your first invoice.
See PackagesClient feedback
Early in his tenure with us he restored a production environment by himself when other leads were not available. … His leadership capabilities were soon recognized, leading to his transition to a team lead/tech lead role. Currently, he adeptly manages a team of 6, under whom he has successfully completed more than 10 key initiatives.
Homiee (homiee.au)
Latest writing
See all posts- AI security
, 4 min read
AI-generated code is a security problem hiding in plain sight
Independent studies keep finding vulnerabilities in a large share of AI-generated code, and developers using assistants feel more confident about it. The fix isn't banning the tools. It's gates that don't care who wrote the code.
Read the post - War story
, 1 min read
The Elasticsearch deadlock that parked every index: ILM warm phases on a single node
A single-node Elasticsearch cluster hit 999 of its 1,000-shard ceiling, then deadlocked a month later. Both came from the same missing setting in the ILM policy.
Read the post - CVE explainer
, 4 min read
The XZ Utils Backdoor (CVE-2024-3094)
A contributor spent more than two years earning maintainer rights on a compression library, then shipped a backdoor that reached sshd. It was caught because a login took half a second too long.
Read the post
Start with a $500 audit.
See exactly where you stand. Actionable findings in a week.
The full report and debrief call. Delivery in 5–7 business days.








