Shakeel Bajwa
Lead Network/Security Architect @ IBM
About
I build secure, high-availability networks that pay for themselves. 15+ years leading SD-WAN/SASE/SSE programs, Zero-Trust access, and multi-cloud networking (AWS/Azure/GCP). Hands-on with Fortinet, Cisco/Viptela, Palo Alto/CloudGenix, Silver Peak/EdgeConnect, Versa, Zscaler, EVPN/VXLAN, NGFW/proxy stacks, and IaC (Terraform/Ansible).Recent outcomes: standardized 200+ sites via multi-vendor SD-WAN/SASE RFPs (~$2.4M/yr savings); designed secure hybrid blueprints adopted by 25+ programs; engineered NGFW/proxy stacks with centralized policy and runbooks. Patent author in flow processing & compression.Consulting offers: (1) SASE/SD-WAN vendor down-select (scorecards, bake-offs, TCO) (2) Zero-Trust access quickstart (ZTA per NIST 800-207) (3) Cloud transit & landing zones (AWS TGW / Azure vWAN / GCP) (4) Firewall/Proxy modernization (policy migration + rollback) (5) Observability/SLOs (ThousandEyes + NPM/NDR).
United States
San Francisco Bay Area
Information Technology & Services
SASE, Zero Trust Architecture (ZTA) , Cloud Networking (AWS / Azure / GCP), SASE (Secure Access Service Edge), Network Automation (Terraform / Ansible), Multi-vendor SD-WAN, Cloud Networking (AWS, Azure, GCP), BGP, OSPF, MPLS, EVPN/VXLAN, Network Architecture, Data Center Networking, Zero Trust Architecture, sase, Encryption, Identity and Access Management (IAM), PKI, FIDO2/WebAuthn, Multi-factor Authentication (MFA), Firewalls (Palo Alto, Fortinet), Cisco Technologies
Experience

Lead Network/Security Architect
Houston, Texas
Oct 2021 – Present · Houston, TX (Global remit) Lead architect for global SD-WAN / SASE and Zero-Trust-aligned network security, supporting hybrid work, multi-cloud adoption, and cost optimization across a 200+ site enterprise. Own SD-WAN / SASE strategy and RFPs – Authored and led multi-vendor SD-WAN/SASE RFP processes (Fortinet, Cisco/Viptela, Palo Alto, Zscaler, Versa, etc.), standardizing global connectivity for 200+ locations and delivering ~$2.4M in annual WAN and licensing savings through design and commercial optimization. Design secure hybrid & multi-cloud blueprints – Created repeatable network/security architectures for global data centers, branches, and AWS/Azure/GCP environments, integrating SASE/SSE, CASB, SWG and ZTNA controls. These blueprints were adopted by 25+ internal programs to support hybrid work and Zero-Trust initiatives. Engineer next-gen perimeter & web security stacks – Designed and deployed multi-vendor NGFW and proxy stacks (Palo Alto, Fortinet, Cisco, Zscaler) with centralized policy, segmentation and change automation, reducing security incidents by >40% and improving consistency of enforcement across regions. Set enterprise encryption & remote-access standards – Established end-to-end encryption baselines (TLS/IPsec/IKE) and remote access patterns (VPN / ZTNA-ready designs) across the estate, ensuring consistent posture for compliance and modern Zero-Trust-style access. Drive network automation & IaC – Led adoption of Terraform and Ansible for network and security infrastructure, implementing version-controlled configurations, reusable modules and automated rollout/runbooks that improved reliability, reduced manual error, and shortened MTTR for changes and incident recovery. Partner with security, cloud and business leaders – Run architecture reviews and design workshops with CISO, cloud, and application teams; translate business and compliance requirements into actionable network/security roadmaps

Chief Technology Officer
Bolo Network, Inc.
Remote/San Francisco Bay Area
Founder-level CTO for a boutique consultancy focused on SASE/SD-WAN, Zero-Trust access, and multi-cloud networking for mid-market and enterprise customers. Build vendor-agnostic SASE / SD-WAN architectures – Lead evaluations and designs across leading SASE and SD-WAN platforms (e.g., Fortinet, Palo Alto, Cisco/Viptela, Zscaler, CloudGenix, Silver Peak, Versa). Guide clients from MPLS and legacy VPNs to modern, internet-first connectivity with Zero-Trust controls. Design Zero-Trust access blueprints (NIST 800-207 aligned) – Develop practical reference architectures for ZTNA, SWG, CASB and identity-aware access, mapping NIST 800-207 principles to real-world networks, users, and applications. Deliver runbooks, policy catalogs, and phased rollout plans. Engineer secure multi-cloud connectivity (AWS / Azure / GCP) – Architect hub-and-spoke and mesh overlays, cloud on-ramps, and private connectivity (Transit Gateways, virtual WAN, cloud firewalls) to connect users, branches, data centers, and SaaS platforms as a single secure fabric. Productize RFPs, scorecards, and PoC playbooks – Create standard RFP templates, vendor scorecards, and PoC methodologies that let CIO/CISO teams down-select SASE/SD-WAN vendors objectively, reduce decision time, and maximize commercial leverage. Data-driven security & cost optimization – Work with Data Science teams to land Snowflake-based analytics for network and security telemetry (latency, incidents, policy hits, egress spend), identifying tuning opportunities and quantifying ROI for SASE and Zero-Trust projects. Infrastructure-as-Code and automation – Use Terraform/Ansible and vendor APIs to templatize site turn-ups, policy deployment, and change management, shrinking rollout cycles from weeks to days and reducing configuration drift. Executive advisory & expert-network work – Provide briefings and Q&A sessions for investors and executives (via platforms like Tegus/AlphaSense and direct engagements), covering vendor roadmaps.

Senior Network Architect
San Ramon, CA
Architected a globally scalable, highly available enterprise network, delivering 99.999% uptime across multi-homed data centers and regional hubs supporting 100,000+ users. Engineered end-to-end L1–L7 designs – BGP/OSPF routing, MPLS/VPLS WAN, VPN, firewall/proxy stacks, and F5 LTM/GTM traffic steering – to cut latency, stabilize application performance, and increase resiliency for critical business systems. Led IP strategy, segmentation, and configuration standards across core platforms, simplifying network growth, reducing misconfigurations, and significantly lowering operational complexity for global operations. Partnered with security and infrastructure teams to integrate robust perimeter controls, remote-access patterns, and monitoring, laying the foundation for later Zero-Trust and SASE initiatives adopted in the post-2020 environment.

Lead Network Architect, IP Engineering
Pleasanton, CA
Designed large-scale carrier LAN/WAN architectures using MPLS VPN and IPsec VPN with strict SLA targets, improving end-to-end network reliability and reducing latency by ~35% for enterprise customers. Led backbone routing and traffic engineering, using BGP, OSPF, QoS/CoS and redundancy designs to keep national and regional networks stable under heavy load and planned maintenance. Evaluated next-generation data-center fabric technologies (Cisco FabricPath, Juniper QFabric based on TRILL) and produced reference designs that laid the groundwork for high-performance, non-blocking network fabrics. Standardized configuration patterns and migration playbooks for customer VPNs and data-center interconnects, reducing implementation time and operational risk for future rollouts.
Shakeel Bajwa's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.




