Nayab Khan

Nayab Khan

Cybersecurity & Infrastructure Architect

14+ Years Leading Enterprise Security Solutions

Boston, MA US Citizen

About Me

Technical Leader with 14+ years of experience architecting large-scale distributed systems and driving industry-wide impact. Track record of leading complex initiatives from conception to delivery with expertise in building security and infrastructure products.

$600M+
Enterprise Revenue Led
20+
Engineers Managed
270M+
Users Scaled To

Professional Experience

System Cyber Security Engineer

Commonwealth Office of Comptroller, Massachusetts

Hybrid Boston • Aug 2025 - Current

Current
  • Engineered centralized endpoint management using NinjaOne, automating patching, monitoring, software deployment, and device provisioning.
  • Implemented IAM using Azure Entra ID (Azure AD), Active Directory, Intune, Duo MFA, and Conditional Access to support Zero Trust.
  • Automated workflows using PowerShell, Apps Script, Visual Studio, GitHub/GitLab, and REST APIs.
  • Administered cloud platforms and security tooling: M365, Defender, Google Workspace, OKTA, FortiGate, and UniFi.
  • Delivered data solutions including Snowflake automation, Oracle connectivity, and third-party integrations.

System Infrastructure Security Engineer

Scholar Rock

MA, Remote • Mar 2025 – August 2025

  • Spearheaded cloud and identity migrations, transitioning Active Directory, O365, and Windows environments to cloud platforms via Okta and Intune.
  • Engineered Okta lifecycle management, enterprise SSO integrations, and identity governance frameworks.
  • Designed public configuration APIs for security and implemented policies in Zscaler (MFA, DLP, PIM, PAM).

Microsoft Consultant

Ahead Financial Group

Remote • Aug 2024 – Feb 2025

  • Spearheaded a $600M initiative leading a 20-member team to onboard enterprise customers and integrate 30+ security detectors.
  • Delivered O365/IAM consulting for Okta, Ping Identity, CyberArk, SailPoint, and Microsoft Entra ID.
  • Managed PKI certificate management (TLS/SSL, Encryption) and defined CA hierarchy and trust models.

Cyber Defense Engineer

Ahold Delhaize

Remote • June 2024 – Aug 2024

  • Designed Power BI dashboards for service desk metrics and created Power Virtual Agents chatbots.
  • Managed Azure Cloud, IaaS, PaaS, AWS, Microsoft Defender, and Azure Sentinel integrations.
  • Worked on Zscaler Firewall, Palo Alto, Net Witness, and automated provisioning via CyberArk.

ITS Consultant

Boston Medical Center (BMC)

Remote • Aug 2023 – May 2024

  • Scaled Security Command Center to support 33K customers and 50M+ assets.
  • Managed IAM, OAuth, and PAM across Azure AD, OKTA, Saviynt, and Imprivata.
  • Deployed PKI infrastructure and administered O365 Exchange Online and SharePoint.

Sr. Security Engineer (Promoted to Architect)

Insight Enterprise

Arizona (Remote) • June 2021 – Aug 2023

  • Migrated on-prem environments to cloud for State/Government clients (Azure, AWS).
  • Architected migration of policy infrastructure scaling from 20M to 270M+ users with zero downtime.
  • Implemented Zero Trust frameworks across M365 and Defender, monitored via Azure Sentinel.

Technical Lead / Architect

Microsoft

Redmond, WA • Jan 2018 - Jun 2021

  • Administered Active Directory, Azure Entra ID, PKI/SSL, MFA, and AD migrations.
  • Defined DLP policies for email/cloud apps and configured Zscaler DLP.
  • Implemented secure Data Lifecycle Management and retention policies.

Technical Expertise

Cloud & Infrastructure

Azure AWS GCP Kubernetes Terraform

Security & Compliance

Zero Trust HIPAA PCI-DSS GDPR ISO 27001

Identity & Access

Azure AD Okta CyberArk SailPoint MFA

Microsoft Stack

M365 Defender Intune Sentinel Power BI

Certifications

SC-100

Cyber Security Architect

AZ-500

Azure Security Engineer

SC-200

Security Operations Analyst

MS-500

Security Administrator

AWS

Cloud Practitioner

CompTIA Security+

Network Security & Risk Management

Let's Connect

Interested in discussing cybersecurity solutions or opportunities?

Boston, MA • US Citizen