IoTSoft Solutions designs and operates Zero Trust and SASE architectures for
enterprises that can't afford ambiguity — from Zscaler ZIA/ZPA/ZDX deployments
to SD-WAN traffic engineering and hardened OT/ICS networks for industrial sites.
30+YEARS IN NETWORK & SECURITY
#1904CCIE EMERITUS
5+YEARS ZSCALER SASE / ZERO TRUST
UNITEDHEALTH GROUP
HONEYWELL PROCESS SOLUTIONS
SCHLUMBERGER
CISCO SYSTEMS
KIPIC AL-ZOUR REFINERY
SHAH GAS DEVELOPMENT
// What we deliver
Solutions built on hands-on operational depth.
Every engagement is led by the same engineer who administers the tenants,
reads the packet captures, and owns the Sev 1 tickets — not a hand-off between sales and delivery.
Zero Trust & SASE Architecture
Design and deployment of ZTNA/SASE environments across Zscaler ZIA, ZPA, and ZDX, aligned to Zero Trust principles from the ground up.
SD-WAN & Traffic Engineering
Resilient traffic-forwarding designs, PAC-file strategy, GRE/IPsec tunneling, and Z-Tunnel configuration for distributed, hybrid networks.
OT/ICS & Industrial Security
Purdue-model network design, segmentation, and hardening for offshore and onshore industrial sites, refineries, and process-control environments.
Incident Response & RCA
Ownership of security incidents from triage to root-cause resolution, using PCAP analysis, ZDX hop-by-hop diagnostics, and SAML/MFA flow tracing.
Secure AI Adoption
AI application discovery, access governance, and GenAI data-protection guardrails using Zscaler AI Security and NIST AI RMF principles.
Tenant Administration
Day-to-day operation and policy tuning of ZIA/ZPA/ZDX tenants, URL filtering, Cloud Firewall, App Segments, and Client Forwarding Profiles.
A repeatable path from requirements to stable operations.
01
Assess
Network and security assessment: traffic analysis, firewall-rule review, and compliance alignment against your current posture.
02
Architect
Solution design covering forwarding, segmentation, identity integration, and Zero Trust policy — documented, not improvised.
03
Deploy
Staged rollout with FAT/SAT-style test procedures, PAC-file and policy migration, and stakeholder sign-off at each stage.
04
Operate
Ongoing tenant health, incident response, and enhancement backlog work — the same engineer who designed it keeps it running.
// Led by
A principal engineer, not a delivery layer.
SU
Sana Ullah
PRINCIPAL SASE, SD-WAN & ZERO TRUST SECURITY ENGINEER · CCIE EMERITUS #1904
Over 30 years of enterprise infrastructure, architecture, and operations experience, including
more than five years focused on Zscaler SASE and Zero Trust. Career spans principal design work
at Honeywell Process Solutions on industrial OT/ICS networks, global MPLS/BGP operations at
Schlumberger, systems engineering at Cisco, and current enterprise Zscaler administration for
UnitedHealth Group. Currently expanding into secure AI adoption and Zscaler AI Security.
M.S. Computer Engineering — Wayne State UniversityB.S. Computer Engineering — NED UniversityKaty / Houston, Texas
// Get in touch
Tell us what you're securing.
Share a few details about your environment and we'll respond within one business day.