DNS / DDI Architecture
Answerable Systems DNS Engineering

Amir Mousavi DNS Architect

Amir Mousavi

Resume Summary

Technical Lead – DNS / DDI Architect with 15+ years of experience designing and operating large-scale enterprise DNS, DHCP, and IPAM platforms for Canada / US Telecom, financial organizations and multi-national Insurance Companies.

Currently serving as Technical Lead – Engineering, responsible for leading the DNS/DDI engineering team and designing the enterprise architecture for DNS and IPAM platforms supporting critical banking infrastructure. Proven expertise in large-scale DNS architecture, high availability design, infrastructure modernization, and automation-driven operations within highly regulated environments.

Recognized for combining deep protocol-level networking knowledge with software development and automation, enabling resilient, scalable, and secure infrastructure for mission-critical services.

>> Core Expertise:

  • Enterprise DNS & DDI Architecture: BIND DNS, ISC DHCPv4/v6, IPAM, High Availability design, large-scale enterprise deployments
  • DNS Infrastructure Design: Architecture, re-architecting, migrations, DR planning, redundancy, Windows DNS & BIND integration
  • DHCP Engineering: DHCP failover design, custom options, vendor classes, raw options, large-scale troubleshooting and upgrades
  • Network & Data Center Diagnostics: Deep packet inspection, Wireshark, TCPDUMP, protocol-level analysis
  • Automation & Development: Python OOP, Flask WebApps, REST APIs, automation scripting, JSON/YAML/XML parsing, MySQL integration
  • Enterprise Operations Leadership: incident and change management, vendor coordination, enterprise customer engagement
  • ITIL Service Lifecycle: service design, service operation, technical catalog development, documentation standards.

>> Additional Experience:

  • Enterprise Networking: WAN, LAN, Anycast DNS, BGP, VRF | CCNP Switching Certified
  • Platforms & Infrastructure: Linux administration, VMware vSphere, Windows Server, Active Directory, DNSSEC
  • Cloud & Modern Infrastructure: AWS architecture, Docker, Git/GitHub, serverless platforms (FaaS / BaaS / SaaS)

>> Personality:

Detail-oriented technical leader with strong ownership mindset, known for clear architecture design, precise documentation, and stakeholder communication. Self-driven problem solver who thrives in complex environments and quickly adapts to emerging technologies and operational challenges.

Skills:

DNS/DHCP:

  • BIND DNS/ ISC DHCPv4 and v6 Server management, High Availability design.
  • Designing TLD, Resolver, and Cashing architectures, DNS Anycast design.
  • DHCP Failover, Rebalancing, Vendor class, Match Class, customized options.
  • DNS transfers (XFR), dig and drill utility set, DDNS, KNOT TLD DNS Design.
  • DNSSEC implementation and maintenance
  • Threat Protection, Spamhaus transfers, Response Policy Zones, TSIG management.
  • Zone Groups, Hidden Master implementation, Update Policy, DNS Views, ACLs.
  • Stub zones, Forwarders, Recursion and customized root hints.
  • BlueCat, InfoBlox and BT Diamond platform implementation and maintenance.

System Development:

  • Bash and Python scripting to automate implementation of servers, REST and SOAP API Calls support.
  • Linux Administration (Ubuntu, CentOS), VMware vSphere, SAN/NAS deployment.
  • Integration with Network and Business Elements (NBI/SBI).

Network and Packet Inspection:

  • Routing and Switching :
  • WAN: OSPF, IPv6, BGP.
  • Security essentials: DM VPN, IP-SLA, port security.
  • Tools: Wireshark, Reverse mapping service infrastructure using NMap, Solar winds and TCPDUMP captures with L4 Filters and DHTEST.

ITIL v3:

  • Skilled in evaluating, defining, developing and deploying new service support processes and enhancements to existing processes. Implementing SLC, Service Operation, Portfolio, Technical Catalogue and more.
  • Strong in product deployment cycle, vendor managed inventory processes for large mobile operators.
  • Network performance monitoring and reporting based on SLA compliance / MTTR.
  • Developing new solutions and extracting best practices to deliver to Project Managers and Stakeholders.
  • Collaboration and ticketing systems such as JIRA / Scrum-Agile / Sales Force/ Service Now / TTMS and CRM.

Other skills:

  • Superior skills in Office works, Visio design, Excel Macros, PPT presentation.
  • Technical leadership, executive presentations, architecture reviews, stakeholder engagement, technical documentation, and cross-functional alignment.

Work Experience:

Technical Lead – Engineering

  • Lead the design, governance, and operation of enterprise BIND DNS and infrastructure, delivering highly available name resolution services supporting all Enterprise business units and critical banking platforms.
  • Designed and led the deployment of enterprise DNS Anycast architecture, defining the end-to-end solution, high-availability model, operational standards, and integration with existing DNS, IPAM, and network infrastructure to improve resiliency and service continuity.
  • Performed large-scale IP network discovery and optimization across 50,000+ subnets, improving IPAM accuracy and resource utilization while maintaining clear subnet allocation and governance.
  • Provide enterprise-level DDI (DNS, DHCP, IPAM) consultation to engineering and business teams, including architecture design, hybrid cloud integration, operational governance, and the delivery of highly available and scalable network services.
  • Collaborate directly with Akamai engineering teams on DNS proxy and traffic management integrations, including FastDNS, TerraAlta, and eDNS solutions supporting enterprise-scale DNS operations.
  • Supervise and administer enterprise IPAM platforms, including BT Diamond IP and Infoblox, ensuring accurate subnet allocation, lifecycle management, and integration with DNS and DHCP infrastructure.
  • Created detailed network infrastructure and topology diagrams in Visio for DNS platforms, data center networks, and routing environments to support engineering design, documentation, and implementation planning.
  • Develop automation tools using Python OOP, Flask Web applications, and API integrations, enabling SSH command automation, operational monitoring, and improved infrastructure management workflows.
  • Maintain Linux-based DNS and network infrastructure with Azure/AWS integration, supporting IPv4/IPv6 networking, shell scripting automation, and enterprise server operations.
  • Mentor junior engineers and promote engineering standards, documentation practices, and knowledge transfer across teams.
  • Provided enterprise support for BIND DNS and ISC DHCP (v4/v6), resolving complex DNS/DHCP issues and advising on architecture and deployments.
  • Worked directly with enterprise and federal organizations, identifying technical concerns and architectural requirements.
  • Published technical articles on DNS and DHCP issues and solutions, contributing to knowledge base and best practices.
  • Reverse engineered network infrastructure using TCPDUMP, SolarWinds, and NMap to analyze service ports, traffic flows, and DNS/DHCP behavior.
  • Supported datacenter and cloud environments including VMware vSphere, vRealize, and Linux administration.
  • Developed automation scripts using Shell and Python to streamline server integration, inspection, and operational workflows.
  • Contributed to IPv6, Anycast DNS, and enterprise network/server architecture design.
  • Worked within Agile environments using JIRA, Confluence (Colab), Scrum, and Salesforce for incident management and collaboration.
  • Executed network changes and infrastructure deployments within enterprise MPLS, BGP, and OSPF routing environments, ensuring high availability and service continuity across production networks.
  • Supported large-scale enterprise network operations across Cisco and CASA Systems, participating in infrastructure upgrades, network migrations, and production cutover activities.
  • Administered and troubleshot DNS, DHCP, and IP networking services, utilizing packet captures and protocol analysis tools to diagnose name resolution, connectivity, and application performance issues.
  • Managed Linux-based network systems and operational tools, performing server administration, shell scripting, log analysis, and system troubleshooting in production environments.
  • Administered enterprise VMware vCenter and ESXi environments, including virtual machine provisioning, template and snapshot management, resource allocation, capacity planning, performance optimization, and support of highly available Linux-based network and infrastructure services.
  • Utilized packet analysis and monitoring tools, including Wireshark and tcpdump, to investigate network traffic patterns, DNS transactions, and service degradation issues.
  • Performed disaster recovery activities and production incident resolution, applying ITIL service management practices, change management processes, and incident response procedures to minimize business impact.
  • Utilized OSS, ticketing, and provisioning systems to maintain operational visibility, configuration integrity, and service lifecycle management across enterprise networks.
  • Troubleshot M-CMTS and CCAP platforms supporting large-scale broadband and cable network infrastructure, performing root cause analysis and service restoration activities.
  • Documented and presented network architecture, topology, and operational procedures using MS Office, LAN-Flow, and SolarWinds, following technical documentation and engineering standards.

Major Certifications and Trainings:

  • CCNP Switching – 2014 (Certified)
  • CCNA 2014 IPv6 version – (Certified)
  • CCVA Cisco Voice over IP – 2013 (Certified)
  • ITIL v3 foundation – 2015
  • Python OOP Development Training.
  • Advanced Flask CRUD WebApp Training.
  • VMware WS Administration.
  • Business Analysis Fundamentals.
  • Docker Integration.
  • BIND DNS and ISC DHCP – BlueCat Support Professional Certified.
  • + other training courses on MPLS, Wireshark, VoIP, IP Internetworking with other systems, …