SECUREOPS READY

Senior Cloud Security & DevSecOps / Lead Security Architect

Cloud Security · DevSecOps · Zero Trust · IAM · Security Governance · Enterprise Security Architecture

Securing complex enterprise environments without slowing the business behind them.

I am a Senior Cloud Security & DevSecOps / Lead Security Architect with 15+ years of experience across cloud security, enterprise infrastructure, DevSecOps automation, Zero Trust, security governance, and critical infrastructure.

I work across AWS, GCP, on-premises, and hybrid environments to transform security requirements into scalable architectures, automated controls, measurable risk programs, and practical engineering standards.

Available for selected cybersecurity advisory, Fractional CISO, cloud security architecture, and senior leadership opportunities.

SIGNAL LIVE

Security architecture that connects engineering, operations, risk, and executive direction.

My work sits between hands-on security engineering and strategic cybersecurity leadership.

I help organizations secure complex platforms, modernize infrastructure, integrate security into software delivery, strengthen identity and access controls, and establish governance that executives and technical teams can act on.

My experience spans high-traffic digital platforms, financial services, banking, government systems, national taxation platforms, and critical infrastructure.

Enterprise security at scale

OPS READY
  • 15+

    Years in technology and cybersecurity since 2011

  • Multi-cloud

    Enterprise AWS and GCP security programs

  • DevSecOps

    Security embedded across large delivery estates

  • Zero Trust

    Identity-led access across people, machines, and APIs

  • Critical infra

    Sensitive and regulated operating environments

  • Governance

    Roadmaps, risk visibility, and executive alignment

Core security domains

ZERO TRUST
  • 01

    Enterprise Cloud Security

    Designing and governing secure AWS and GCP environments across multiple accounts, projects, networks, applications, identities, and operational teams.

    Key areas include

    • Cloud security architecture
    • CNAPP and cloud posture management
    • Multi-account and multi-project governance
    • Cloud network segmentation
    • Workload protection
    • Secure inter-cloud connectivity
    • Encryption and data protection
    • Cloud risk and configuration assessments
  • 02

    DevSecOps and Secure Delivery

    Embedding security into the software-development lifecycle without turning security into a delivery bottleneck.

    Key areas include

    • CI/CD security
    • SAST, DAST, and SCA
    • Secrets detection and management
    • Container security
    • Secure release gates
    • Vulnerability-remediation workflows
    • Secure SDLC
    • Shift-Left security adoption
  • 03

    Zero Trust and Identity Security

    Strengthening access across users, applications, APIs, machines, and cloud services through identity-led security controls.

    Key areas include

    • IAM restructuring
    • Privileged Access Management
    • Least-privilege access
    • SSO and MFA
    • Machine and service identities
    • API-to-API authentication
    • Zero Trust employee access
    • Access governance and data classification
  • 04

    Security Strategy and Governance

    Translating technical exposure into clear priorities, controls, roadmaps, and executive decisions.

    Key areas include

    • Cybersecurity roadmaps
    • Security gap analysis
    • Risk registers
    • Security policies and standards
    • Executive posture reporting
    • Vendor and SOC governance
    • Regulatory alignment
    • Security-program maturity

Selected Security Programs

SECURE
  • Large-Scale Multi-Cloud Security Governance

    Security architecture and governance across dozens of AWS accounts and GCP projects supporting a high-traffic digital media platform.

    The program covers organization-level IAM, network governance, cloud monitoring, firewalls, WAFs, site-to-site connectivity, data protection, vulnerability management, and executive risk visibility.

  • DevSecOps Security Across Hundreds of Pipelines

    Security integration across hundreds of CI/CD pipelines and dozens of engineering environments.

    The work includes automated testing, secrets detection, application-security controls, container security, vulnerability remediation, and automated release decisions.

  • Zero Trust and IAM Transformation

    A broad identity and access transformation covering employee access, machine identities, cloud permissions, service authentication, and API-to-API communication.

    The program reduced dependency on hardcoded credentials and strengthened least-privilege access across cloud and application environments.

  • Air-Gapped Threat Intelligence Architecture

    Architecture of a threat-intelligence platform for a sensitive critical-infrastructure environment that processes large sensitive datasets without direct internet connectivity.

    The solution used controlled, unidirectional data flows to preserve isolation while supporting required information exchange.

  • Financial Infrastructure and Security Transformation

    Transformation of IT and security infrastructure across roughly twenty financial-services sites processing tens of thousands of transactions per day.

    The program included network redesign, security hardening, monitoring, access controls, automation, regulatory alignment, and Disaster Recovery.

  • National Tax Platform Cloud Security

    Cloud and application security architecture for a national-level taxation platform integrated with a national information-exchange authority.

    The work covered segmented environments, database clustering, cloud controls, application-security standards, and protection of sensitive taxpayer data.

Leadership and security approach

OPS READY

Clear strategic control without removing technical ownership.

I set what must be addressed, why it matters, and when it is due—while teams retain ownership of how to implement durable, automated controls.

  • Security ownership with accountable outcomes
  • Engineering autonomy within clear risk boundaries
  • Risk-driven prioritization over tool volume
  • Executive alignment through measurable posture reporting
OPS READY

Ready to discuss an advisory engagement?

Fractional leadership, architecture review, DevSecOps transformation, and governance support—scoped to the outcomes your organization needs next.

Selected experience

OPS READY
  1. 2023 – Present

    Senior Cloud Security & DevSecOps / Lead Security Architect

    Shahid — MBC Group · Full-time

    Lead and contribute to cloud security architecture, DevSecOps, Zero Trust, IAM, application security, security governance, and risk management in a multi-cloud enterprise environment.

  2. 2022 – 2023

    Cyber Security Team Leader & Consultant

    Seniors IT · Full-time

    Led a small cybersecurity team delivering enterprise and government security programs across Jordan, Saudi Arabia, and Qatar.

  3. 2019 – 2021

    Information Technology & Security Manager

    Al-Alami Financial Services · Full-time

    Managed IT and security infrastructure across roughly twenty financial-services locations, supporting regulated operations and tens of thousands of daily transactions.

  4. 2019

    Cloud and Security Engineer

    DareebaTech · Freelance

    Designed cloud and application security controls for a national taxation platform integrated with a national information-exchange authority.

  5. 2015 – 2019

    IT Infrastructure Engineer

    Capital Investments — Capital Bank · Full-time

    Managed enterprise infrastructure, data centers, servers, firewalls, monitoring, Office 365 migration, and Disaster Recovery initiatives.

  6. 2011 – 2014

    Network Engineer

    Hyperlink · Full-time

    Built foundational experience in enterprise networks, infrastructure, connectivity, troubleshooting, and security technologies.

How I approach security

Operating principles that keep architecture, engineering, and executive decisions aligned.

SECURE
  • Security by Design

    Security belongs in architecture and planning—not as a retrofit.

  • Identity Before Perimeter

    Users, services, machines, and privileges must be known and governed first.

  • Automation Over Manual Control

    Repeatable security decisions should be automated where possible.

  • Risk-Based Prioritization

    Not every finding carries equal business impact.

OPS READY

Need senior cybersecurity direction without hiring a full-time executive?

I provide selected advisory and leadership support for organizations that need to strengthen their security strategy, cloud architecture, DevSecOps practices, risk governance, or security operations.