// security architecture & presales engineering

Security by Faisal Khan

Notes from 12+ years designing security and network architectures for Fortune 500 and public-sector clients — Zero Trust, SASE/SSE, cloud security, and the real-world lessons that don't make it into the vendor slide deck. Written toward the next chapter: independent security consulting.

Latest

View all →
Architecture

Designing a SASE Migration for a Multi-Site Retail Environment

An end-to-end architecture breakdown for migrating a multi-hundred-site retail network from MPLS/hub-and-spoke to SD-WAN + SASE, including the sequencing decisions that matter more than the vendor choice.

SASESD-WANarchitectureretailzero trust
Finding

The Segmentation Gap Nobody Budgets For: A Recurring Pattern in Retail SD-WAN RFPs

Across large multi-site retail transformations, the same segmentation gap keeps showing up between the network design and how PCI/PoS traffic actually gets isolated. Here's the pattern and what closes it.

network segmentationretailSD-WANPCI
Article

Vendor-Agnostic Doesn't Mean Opinion-Free: Rethinking the Presales Security Architect Role

Presales architects are trained to stay neutral between vendors. That habit quietly costs clients good security outcomes — here's where the line actually belongs.

presalessecurity strategycareer

What's here

Article

Opinion and analysis on where security strategy, vendor positioning, and real enterprise constraints collide.

Finding

Concrete lessons and patterns pulled from real engagements — the gaps that show up in RFPs, PoCs, and production environments.

Architecture

Deeper breakdowns of end-to-end designs — SASE, SD-WAN, Zero Trust, and hybrid cloud security architectures.