// security architecture & presales engineering
Security by Faisal Khan
Notes from 12+ years designing security and network architectures for Fortune 500 and public-sector clients — Zero Trust, SASE/SSE, cloud security, and the real-world lessons that don't make it into the vendor slide deck. Written toward the next chapter: independent security consulting.
Latest
View all →Designing a SASE Migration for a Multi-Site Retail Environment
An end-to-end architecture breakdown for migrating a multi-hundred-site retail network from MPLS/hub-and-spoke to SD-WAN + SASE, including the sequencing decisions that matter more than the vendor choice.
The Segmentation Gap Nobody Budgets For: A Recurring Pattern in Retail SD-WAN RFPs
Across large multi-site retail transformations, the same segmentation gap keeps showing up between the network design and how PCI/PoS traffic actually gets isolated. Here's the pattern and what closes it.
Vendor-Agnostic Doesn't Mean Opinion-Free: Rethinking the Presales Security Architect Role
Presales architects are trained to stay neutral between vendors. That habit quietly costs clients good security outcomes — here's where the line actually belongs.
What's here
Opinion and analysis on where security strategy, vendor positioning, and real enterprise constraints collide.
Concrete lessons and patterns pulled from real engagements — the gaps that show up in RFPs, PoCs, and production environments.
Deeper breakdowns of end-to-end designs — SASE, SD-WAN, Zero Trust, and hybrid cloud security architectures.