Pouyesh Sabouri

AI & Automation Engineer  ·  Python / Django  ·  Secure Infrastructure

Delta, British Columbia, Canada AI-Consulting@sabouri.org linkedin.com/in/pouyesh-sabouri

Summary

Engineer and engineering leader with 22 years in production infrastructure and Python, Django and automation in production since 2019. I build systems that have to be right, not just impressive — most recently a complete self-hosted agentic AI platform for a Canadian accounting firm: retrieval over a 300,000-chunk corpus, deterministic financial computation, document generation and per-client access control, running on a single GPU with no external API dependency.

My background is the reason the AI work holds up. Two decades of network, telecom and security engineering — TELUS, the Government of Alberta, managed services consulting, a credit union's full infrastructure stack — means I treat an agent that executes code and reaches client data as what it is: a security and operations problem first. I led the teams that adopted Python, Django, Ansible and Jenkins into day-to-day operations, including automating significant parts of my own role away.

Those two halves meet in my current presales work, where I design and defend the controls for exactly this problem — AI runtime guardrails, DLP over prompt traffic, shadow-AI governance. I sell those controls by day and build to them by night, which means I answer the question every board eventually asks — what stops this thing leaking our data? — from both sides of the table.

Flagship build

Self-hosted agentic AI platform — accounting & professional services

Sole architect and engineer  ·  HPSD, 2025–present  ·  Python, FastAPI, LangGraph, PostgreSQL, Qdrant, vLLM, Docker  ·  in production

302kIndexed KB chunks
262kToken context, live
29Deterministic finance recipes
76Routed graph nodes
207Automated test files
0External API calls
  • Retrieval. Hybrid semantic + lexical search over Qdrant (bge-m3, 1024-d) with a two-stage rerank-and-MMR selection layer, a measured relevance floor, and a mandatory per-client visibility filter on every query. Closed a defect that had left 226,777 chunks silently invisible to search.
  • Correctness. Every financial figure computed deterministically in pandas over PostgreSQL — never by the model. Where free-form analysis is unavoidable, two independent generations must agree on the digits or the system visibly refuses to answer.
  • Data integrity. Document extraction gated by reconciliation contracts that check each parse against the source document's own printed totals and return a status the caller acts on, rather than storing an unverified figure as fact.
  • Trust. Citations verified in code — reachability, in-range source numbers, and embedding-based freshness against the indexed copy — never by asking the model whether it complied.
  • Access control. Fail-closed per-client authorisation across knowledge base, financial data and correspondence from one table, re-checked live at job execution time rather than only at request time.
  • Operations. 17-container Docker Compose stack on one 96 GB GPU: NVFP4-quantised 27B model on vLLM, durable Postgres job queue, sandboxed code execution, ingestion workers, admin console, and an automated regression suite.

Technical skills

Languages
Python (async/asyncio, typing), SQL, Bash, JavaScript, YAML/Jinja
Frameworks
Django, FastAPI, LangGraph, pandas, NumPy, Playwright, pytest-style regression harnesses
AI systems
Retrieval-augmented generation, hybrid vector + lexical search, cross-encoder reranking and MMR, tool-calling agent loops, prompt and context-budget engineering, evaluation corpora and scoring, vLLM / SGLang / Ollama, NVFP4 and FP8 quantisation, Unsloth supervised fine-tuning
AI security
LLM runtime guardrails (prompt injection, jailbreak, model poisoning and extraction), context-aware DLP over prompt and response traffic, shadow-AI discovery and risk-based access, OWASP Top 10 for LLM applications, prompt-level audit logging, token and compute-cost governance
Data
PostgreSQL, Qdrant, Redis, SQLite, schema design and migrations, document ingestion (PDF, XLSX, DOCX, PPTX, EML, EPUB, OCR)
Automation
Ansible, Jenkins, Docker & Docker Compose, Git, AWS, nginx, systemd, scheduled and event-driven pipelines
Infrastructure
Enterprise routing and switching, BGP/MPLS, next-generation firewalls (FortiGate, Palo Alto, Cisco FTD), VPN, NetScaler, virtualisation, mTLS and PKI, Linux/Unix
Practice
Test-first regression corpora, fail-closed security design, reconciliation-gated data pipelines, Agile, ITIL, team coaching and technical mentoring

Experience

Jan 2025 – PresentBritish Columbia, Canada

AI Consultant

HPSD

  • Design and delivery of self-hosted agentic AI systems for organisations that cannot send client data to an external provider — architecture, retrieval, evaluation and the security model, on their own hardware.
  • Architected and operate the platform described above: retrieval over a 300,000-chunk corpus, deterministic financial computation over a live ledger, document generation and fail-closed per-client access control, on a single GPU with no external API dependency.
  • Model selection and evaluation — NVFP4/FP8 quantised serving on vLLM and SGLang, context and VRAM budgeting, tool-call parser validation against a model's own chat template rather than its card, and scored evaluation corpora in place of demo impressions.
  • Retrieval engineering — hybrid semantic and lexical search, cross-encoder reranking with diversity selection, measured relevance floors, and citation verification performed in code rather than by asking the model to grade itself.
  • Data-integrity engineering for financial documents: reconciliation contracts that check every extracted figure against the source document's own printed totals, and deterministic computation in place of model-generated analytics wherever a number will be presented as fact.
  • Advisory on where agentic systems are safe to place in regulated and professional workflows — and, as often, where they are not.

Python · Django · FastAPI · LangGraph · PostgreSQL · Qdrant · vLLM · Docker · RAG · LLM evaluation

Dec 2023 – PresentBurnaby, BC · Remote

Presales Security Expert

Fortinet

  • Technical authority on security architecture for enterprise and public-sector opportunities across Western Canada, from discovery through design and proof of concept.
  • AI runtime security. Presales lead for an AI security gateway deployed inline between enterprise applications and their model providers, applying guardrails to both model input and output — prompt-injection and jailbreak detection, model-poisoning and model-extraction prevention, and excessive-consumption controls — mapped to the OWASP Top 10 for LLM applications. Unlike conventional network or web inspection, this reads the natural-language interaction itself, which is where the actual risk lives.
  • Data loss prevention. Context-aware DLP in the critical path of AI traffic, inspecting inbound and outbound prompts for PII and regulated data so sensitive material cannot leave the organisation through a chat box. This is classic egress DLP extended into a channel that traditional content inspection does not parse — and for regulated clients it is usually the control that decides whether AI adoption is approved at all.
  • Shadow AI and governance. Discovery and risk-based access control over unsanctioned AI service use, with per-prompt and per-response audit logging and token/compute cost attribution — giving security, compliance and finance the same visibility over AI usage they already expect from every other sanctioned service.
  • Translate customer risk, compliance and data-residency constraints into deployable architecture, and defend those designs in front of both technical and executive stakeholders.
  • Maintain deep currency across the platform — SASE, FortiClient EMS, FortiGate — carrying nine Fortinet certifications earned since joining, including Certified Solution Specialist SASE.

AI runtime security · LLM guardrails · DLP · shadow-AI discovery · OWASP Top 10 for LLMs · SASE · NGFW · zero trust

Feb 2020 – Dec 2023Surrey, BC · Remote

Senior Network, Unix & Telecom Manager

Coast Capital Savings

  • Led 12 network, Unix and telecom specialists owning the credit union's telephony, network and banking infrastructure stack — virtualisation, database and application tiers — for a 45-branch, 600,000-member financial institution.
  • Drove Python, Django and Ansible into the operational core as the team's problem-solving default, and trained the team in Agile delivery, Python and coding best practice — turning an operations group into one that ships software.
  • Built the internal automation platform that creates, modifies and removes networks, VPNs, interfaces and firewall rules organisation-wide, replacing manual change work that had previously consumed a significant share of the team's capacity.
  • Established CI/CD and infrastructure-as-code practice with Jenkins, Ansible and AWS; implemented ITIL operational standards across change, incident and problem management.
  • Managed leadership through a regulated financial-services environment with explicit focus on team wellbeing and sustainable on-call practice.

Network & Telecom Manager — Feb 2020 – Dec 2022

  • Managed a team of 8 across operations, project delivery and daily service; set the automation-first direction the senior role then scaled.

Python · Django · Ansible · Jenkins · AWS · PostgreSQL · Linux/Unix · Cisco · Fortinet · ITIL

Mar 2015 – Feb 2020Vancouver, BC

Team Lead — Network Services

Long View Systems

  • Consulting delivery lead across municipal government, manufacturing and hospitality clients — presales, RFP response, architecture, documentation and implementation.
  • Designed, documented and deployed Palo Alto firewalls and Panorama across a municipal WAN and MPLS network, then trained the client's own security and architecture teams to operate them.
  • Led a dual-data-centre redesign replacing legacy NetScaler and Juniper infrastructure with MPX8000 and active/active Palo Alto firewalls, including global site selection and virtual services.
  • Migrated a client's entire network to a new site overnight with no user impact, and designed VPN, MPLS and WAN connectivity for ten new satellite offices.
  • Deployed Cisco Firepower Threat Defense and Firepower Management Center as an ASA replacement, with client enablement material.

Team Lead — Managed Services, Network — Mar 2015 – May 2017

  • Operations lead for a resorts and hospitality client and technical lead across Long View's managed-services base, coaching a team of 12 infrastructure analysts.
  • Owned five-year data-centre and branch refresh planning and budget, multi-vendor renewals, and contractual SLA performance including director-level escalation.
  • Established network security policy, change control and patching standards to PCI and HIPAA requirements, in partnership with the client's security department.

Palo Alto · Panorama · Cisco FTD/FMC · NetScaler · Juniper · MPLS/WAN · PCI · HIPAA

Feb 2012 – Feb 2015Edmonton, AB

Network Team Lead

Government of Alberta — Justice & Solicitor General

  • Led the network team operating secure infrastructure for Justice and Solicitor General, including Change Advisory Board planning and cross-team implementation coordination.
  • Designed and implemented redundant secure network infrastructure across three geographic sites using Cisco, Juniper and HP, and a BGP multi-homed core across the Alberta SuperNet and Government of Alberta networks.
  • Delivered 20+ secure remote sites providing controlled access to protected justice applications and resources.
  • Established the formal documentation standard for secure access methods, monitoring, logging and reporting; technical adviser to other departments and directors.
Feb 2004 – Feb 2012Edmonton, AB

Senior Network Specialist

TELUS

  • Provisioned and supported network services for TELUS corporate clients across a large managed estate.
  • Tier-3 troubleshooting of client Cisco routing, switching and firewall infrastructure (ASA, PIX).
  • Built and maintained client VPNs over MPLS, ADSL and T1 using Cisco and Check Point concentrators.

Education

2020

Bachelor of Technology (BTech), Computer Science

Thompson Rivers University

2008 – 2012

Telecommunications Journeyman — Telecommunications Technology

Northern Alberta Institute of Technology (NAIT)

Certifications

Fortinet

  • Certified Solution Specialist, SASE 2026 – 2028
  • FortiSASE 24 Administrator 2025
  • FortiClient EMS 7.2 Administrator 2024
  • Certified Professional, Network Security 2024 – 2026
  • FortiGate 7.2 Administrator 2024
  • FortiGate 7.4 Operator 2023
  • Certified Associate / Fundamentals, Cybersecurity 2023

Cisco — valid to Jun 2027

  • CCNP Enterprise
  • Certified Specialist — Enterprise Core
  • Certified Specialist — Enterprise Design
  • Certified Specialist — Enterprise Advanced Infrastructure
  • Certified Specialist — Security Core
  • Certified Specialist — Network Security, Firepower
  • Certified Specialist — Network Security, VPN
  • Certified Specialist — Security Identity Management
  • Certified Specialist — Web Content Security

Palo Alto Networks

  • Certified Network Security Engineer (PCNSE) 2018

Languages

  • English — native / bilingual
  • Farsi — native / bilingual