Senior Systems & Virtualization Engineer
Tehran Provincial Government
- VMware Virtualization
Transformed the virtual infrastructure by designing a scalable VMware environment for 200+ VMs. Through implementing DRS and HA, eliminated unplanned downtime and automated resource allocation, directly supporting the organization's 99.9% SLA requirement.
- Active Directory
Transformed the identity and access management architecture by redesigning Active Directory with a tiered administrative model (Tier 0/1/2) and structured access controls. Eliminated privilege creep and lateral movement risks by enforcing least-privilege principles and logical OU segmentation, directly supporting the organization's security compliance and audit requirements.
- Microsoft Exchange
Transformed the messaging and collaboration platform by architecting a purely on-premises Microsoft Exchange environment for 2,000+ mailboxes with Database Availability Groups (DAG) for automatic failover. Implemented organization relationships and federation trusts to enable secure calendar sharing and cross-organization collaboration with external partners. Eliminated email downtime and single points of failure, directly supporting organizational productivity SLAs.
- Linux Server Administration
Transformed the on-premises file sharing and collaboration infrastructure by designing and deploying a Linux-based Nextcloud platform for 2,000+ users. Implemented a scalable architecture with load-balanced web servers, Redis caching, and MariaDB clustering for high concurrency. Eliminated reliance on unsecured file sharing methods (USB drives, personal cloud, email attachments) while providing controlled, auditable access to organizational data, directly supporting internal data governance and productivity requirements.
- ManageEngine Endpoint Central
Deployed ManageEngine Endpoint Central for 2,000+ clients across 20 buildings with role-based access controls enforcing site-level technician scoping, eliminating unauthorized cross-site access while centralizing patch and software management.
February 2023 - Present
System Administrator
Sepehr Electronic Payment
- VMware Virtualization
Engineered a dual-zone VMware vSphere environment supporting 400+ virtual machines, strictly isolating the banking payment network (PCI-like zone) from the internal organizational network. Implemented cluster-level HA and vMotion to guarantee continuous operation for payment processing VMs, directly supporting 99.95% uptime requirements for financial transactions.
- Active Directory
Architected a secure Active Directory infrastructure managing identities for 1,000 users across both corporate and payment processing units. Enforced logical separation by implementing distinct Organizational Units (OUs) and Group Policies for payment operators versus internal staff, while integrating AD authentication with critical banking applications. Eliminated credential sharing and enforced least-privilege access for payment workflows.
- Microsoft Exchange
Deployed a resilient Microsoft Exchange solution for 1,000 mailboxes, dedicated to internal organizational communication while ensuring no integration with the isolated payment network. Implemented mailbox database replication for automatic failover, guaranteeing the delivery of critical system alerts without single point of failure.
- Veeam Backup & Replication
Designed a tiered Veeam backup strategy for 400+ VMs across two distinct zones, with aggressive 6-hour RPO for critical payment VMs versus daily backups for internal corporate VMs. Implemented automated restore testing for payment domain controllers and transaction servers, ensuring recoverability and consistency of the banking payment zone. Eliminated backup gaps for financial data while meeting both operational and audit requirements.
January 2022 - December 2023
System Administrator
Farmand Food Industries
- Active Directory
Led a full Active Directory migration from legacy 2012 to 2019 across the organization, redesigning the logical structure to support 700+ users. Extended authentication infrastructure by deploying additional domain controllers to remote branch offices (factory sites), eliminating cross-site authentication latency and providing local failover capability. Directly supported business continuity by ensuring each branch could operate independently during WAN outages.
- Microsoft Exchange
Hardened the Exchange infrastructure by adding a second mailbox server and implementing Database Availability Groups (DAG) for automatic database failover across 500+ mailboxes. Designed a tiered archiving policy with online archiving for recent mail (6 months) and PST-based long-term retention for legal/compliance requirements. Deployed an SMTP relay gateway to handle application-generated emails (ERP, production alerts, scanner outputs), offloading the primary hub transport servers and securing internal-to-external mail flow.
- OS Deployment & Imaging
Designed and deployed Windows Deployment Services (WDS) to standardize OS provisioning across all factory locations. Created custom Windows reference images pre-loaded with line-of-business applications, required drivers for all hardware models, and organizational security baselines. Reduced helpdesk PC setup time from 4 hours to 45 minutes, enabling same-day workstation replacement and eliminating manual configuration errors across all branches.
- Patch Management
Implemented a tiered WSUS architecture with a central upstream server at headquarters and replica WSUS servers deployed to each branch office. Enabled local patch downloads for 700+ endpoints, reducing internet bandwidth consumption by 60% while ensuring timely security updates. Achieved 95% patch compliance within 7 days of Microsoft release.
June 2020 - April 2022
Helpdesk
Shariati Hospital
- OS Installation
Installed and configured Windows on new and existing systems, including drivers, basic software, and initial settings for medical and administrative staff.
- Manage Client Computers
Provided daily support for client computers across hospital departments, troubleshooting hardware/software issues and replacing faulty parts.
- Patch Management
Maintained WSUS server to automate Windows security updates, preventing unnecessary internet bandwidth consumption across the hospital.
- OS Deployment
Used WDS for remote Windows installation on multiple systems simultaneously, eliminating the need for USB drives or DVDs for new equipment or major repairs.
June 2019 - February 2021