Khalid Nazmus Sakib

Staff Security Architect (AI)

knsakib@gmail.com

Montreal, Quebec, Canada


Profile

Staff Security Architect focused on AI security, Application Security, DevSecOps, and cloud/container security.

   • Lead security architecture and secure SDLC programs for AI-enabled products, modern applications, and engineering platforms.
   • 6+ years in Application Security leadership, including program development, secure design guidance, security tool benchmarking, and metrics-driven security decisions.
   • Deep experience with SAST, DAST, IAST, RASP, mobile security testing, workload protection, container security, Kubernetes/OpenShift security, and CI/CD security.
   • Build practical guardrails for engineering teams: reusable security libraries, pipeline controls, secure coding guidance, vulnerability remediation workflows, and developer training.
   • Broader engineering background across cloud infrastructure, DevOps, Node.js, Python, Java, PHP, React, IoT, embedded systems, and network engineering.

Core Skills

Application & AI Security

Security architecture, threat modeling, secure design review, Secure SDLC, SAST, DAST, IAST, RASP, mobile application security, vulnerability management, and developer enablement.

DevSecOps & Cloud

CI/CD security, security automation, Jenkins, Kubernetes, OpenShift, container security, workload protection, cloud hardening, GCP, AWS, Linux, logging, monitoring, and alerting.

Engineering Background

Node.js, Next.js, React, Python, Java, PHP, Go, Docker, microservices, IoT, embedded systems, data pipelines, research, and practical product engineering.

Experience

Fortis Games

Staff Security Architect (AI)

Oct 2025 - Present

• Lead security architecture for AI-enabled products, internal platforms, and application security programs.
• Define practical guardrails for secure AI and application development, including threat modeling, secure design review, data handling, and secure SDLC controls.
• Partner with engineering, DevOps, product, and security teams to turn security requirements into reusable patterns, automation, and developer-friendly workflows.
• Benchmark and consolidate security capabilities across SAST, DAST, IAST, RASP, mobile application security, workload protection, and cloud/container security.
• Guide vulnerability remediation, risk prioritization, and security decision-making for modern game and platform engineering teams.


Fortis Games

Staff Application Security Engineer

Mar 2024 - Sep 2025

• Led Application Security program execution, SSDLC standardization, and security tooling adoption across mobile game development teams.
• Worked closely with application and DevOps teams to integrate SAST, DAST, RASP, IAST, mobile security testing, and workload protection into delivery workflows.
• Built tool benchmarking, consolidation analysis, and maturity metrics to support business-oriented security decisions.
• Supported reusable Application Security libraries and pipeline controls to standardize end-to-end DevSecOps practices.
• Partnered with penetration testing and engineering teams to identify vulnerabilities, prioritize remediation, and improve secure coding practices.


National Bank of Canada

Security Process and Service Owner - Application Security

Nov 2021 - Feb 2024

• Responsible for choosing, benchmarking, and maintaining Container and Kubernetes Security Solution Provider and DevSecOps best practice in Container Orchestration.
• Supporting team to develop reusable Application Security Libraries to standardize end-to-end DevSecOps and SSDLC best practices.
• Responsible for Security Analysis, Benchmarking, and choosing SAST, DAST, and IAST solutions and advisory suggestions in security best practice for Jenkins, shared by major Application Teams in the Bank.
• Guiding different delivery towers and lines of business to remediate vulnerabilities and Application Security findings.
• Supporting teams in developing and building DevSecOps pipelines and integrating security tools into existing DevOps workflows.
• Policy creation for Kubernetes security and container runtime protection
• Working in collaboration with the Pentest team to identify application codebase vulnerabilities and provide solutions to resolve them.
• Responsible for developer training for secure coding practice and training content creation.


National Bank of Canada

Senior DevSecOps Advisor

Jan 2019 - Oct 2021

• Responsible for Application and Container Security best practices and automation and integration of security tools in a DevSecOps context.
• Kubernetes and OpenShift security best practices, Linux hardening, and secure implementation of Kafka.
• Provided advisory support to delivery towers and application teams on security best practices, vulnerability identification, and remediation.
• Led development initiatives for building DevSecOps pipelines and integrating security tools into existing DevOps workflows.
• Runtime protection and policy management at the application and container level.
• Hardened Unix servers and supported secure configuration for IBM bare-metal systems in collaboration with the IBM team.
• Worked in collaboration with the Development teams to identify and secure some major vulnerabilities in secret management and environment configuration in some major and critical applications in the Bank.
• Detailed Security Analysis and Advisory suggestion in security best practice for Jenkins, shared by major Application Teams in the Bank.


Longbow Advantage

Cloud Server Administrator

March 2018 - Jan 2019

• Responsible for Automatic deployment and Rollout Grunt task configuration and troubleshooting.
• Load Balancer configuration, implementation, and infrastructure autoscaling in Google Cloud Platform.
• New microservice deployment using Docker on bare-metal instances and Kubernetes.
• Shell Scripting to automate Cron Jobs
• LDAP server configuration SSO and SAML configuration for unifying Auth service in the infrastructure level
• Used Stackdriver for detailed log collection, custom log generation, and dashboard configuration.
• Legacy network migration to Modern Virtual Private Cloud
• Linux administration and using it as a development and reproduction environment, shell scripting for automatic backup


Telus Inc.

Network Specialist

Nov 2014 - Feb 2018

• Automatic deployment configurations, troubleshooting and best practice suggestion to the users by hands-on reproduction of Jenkins environment with issues.
• Automatic agent configure for Puppet Master, Standalone Configuration, Manifest for Auto-scaling based on CPU and traffic utilization, Modules configuration, Certificate generation, Auto sign certificate configuration
• Used Stackdriver for detailed log collection, custom log generation, and dashboard configuration.
• Used Salesforce and JIRA as IT management tools, and Buganizer to report and monitor bugs.
• Used Git with GitHub, GitLab, and Google Cloud repositories for version control.
• Assisted with deployment configuration and troubleshooting coding and runtime issues for Python, Node.js, and Java.
• Supported BigQuery and Dataflow configuration and code troubleshooting in Google Cloud.
• Work on and write reproduction code to raise bugs and provides guidelines for resolution
• Used microservice architecture in Docker-based environments and Kubernetes cluster configuration.


D3 Innovation Center

Innovation Engineer

Mar 2014 - Oct 2014

• Android app development and microcontroller coding to collect sensor data and send notifications when data reached a threshold.
• Built complete IoT products from hardware connections and microcontroller code through Android and iOS app prototypes for SmartWiFi configuration.
• Used Firebase as a database, displayed sensor data on web and mobile interfaces, and triggered events based on data thresholds.
• Designed client-server applications with Node.js running in the cloud and React on the client.
• Programmed Bluetooth modules to communicate with microcontroller-attached sensors.
• Provided bootstrap support for startup companies including Heddoko and Maker Blocks, and managed crowdfunded project SLAs.


Concordia University

Research Assistant


Jan 2011 - Nov 2013

Following Publications were published during my research

• K. N. Sakib, M. Z. Kabir, and S. S. Williamson, "Cadmium telluride solar cell: From device modeling to system implementation" 2013 IEEE International Conference on Industrial Technology (ICIT), Cape Town, 2013, pp. 1561-1566.
• K. N. Sakib, M. Z. Kabir, and S. S. Williamson, "Cadmium telluride solar cell: From device modeling to electric vehicle battery management" 2013 IEEE Transportation Electrification Conference and Expo (ITEC), 2013 IEEE, Detroit, MI, USA



Orascom Telecom BD.

Network Subsystem Jr. Engineer

Jul 2009 - Dec 2010

• Developed a tool with VBScript to automate GSM site creation and configuration in Home Location Server (HLS).
• Troubleshot core network issues, analyzed GSM call flow for KPI improvement, and configured GSM Softswitch.
• Configured cell sites, transmission channels, and transceivers.
• Conducted Base Station Controller and site creation in GSM switch/core and E1 addition.

Huawei Technologies

Asst. Radio Network Planning Engineer

Apr 2008 - Jun 2009

• Conducted Base Station Controller (BSC) and Location Area Code (LAC) planning.
• Optimized radio network, new site, and TRX planning for swap and expansion projects.
• Engineered KPI improvement through drive test log files and result analysis.
• Facilitated Base Station Subsystem (BSS) engineers in radio interface problems.

Education

• Master of Applied Science in Electrical and Computer Engineering, Concordia University - Montreal, Canada
• Bachelor of Science in Electrical and Electronic Engineering, Bangladesh University of Engineering and Technology

Extra-Curricular Activities

• Volunteer works and guided students in ISO, Concordia (Certificates)
• Student member of IEEE and awarded in the International Web-page Design Contest
• Served as BUET reporter in a prominent national daily Newspaper for more than 2 years during undergraduate
• Nominated as one of the 2001 World Champion Amateur Poets in 2001 Summer Convention Washington D.C., USA and poem had been recorded in ‘The Sound of Poetry’ released both in CD and Cassette tape.

References

References available upon request.

Khalid Nazmus Sakib — Staff Security Architect (AI) — knsakib@gmail.com