Senior Cloud Security & DevSecOps / Lead Security Architect
Cloud Security · DevSecOps · Zero Trust · IAM · Security Governance · Enterprise Security Architecture
Securing complex enterprise environments without slowing the business behind them.
I am a Senior Cloud Security & DevSecOps / Lead Security Architect with 15+ years of experience across cloud security, enterprise infrastructure, DevSecOps automation, Zero Trust, security governance, and critical infrastructure.
I work across AWS, GCP, on-premises, and hybrid environments to transform security requirements into scalable architectures, automated controls, measurable risk programs, and practical engineering standards.
Available for selected cybersecurity advisory, Fractional CISO, cloud security architecture, and senior leadership opportunities.
Security architecture that connects engineering, operations, risk, and executive direction.
My work sits between hands-on security engineering and strategic cybersecurity leadership.
I help organizations secure complex platforms, modernize infrastructure, integrate security into software delivery, strengthen identity and access controls, and establish governance that executives and technical teams can act on.
My experience spans high-traffic digital platforms, financial services, banking, government systems, national taxation platforms, and critical infrastructure.
Enterprise security at scale
OPS READY15+
Years in technology and cybersecurity since 2011
Multi-cloud
Enterprise AWS and GCP security programs
DevSecOps
Security embedded across large delivery estates
Zero Trust
Identity-led access across people, machines, and APIs
Critical infra
Sensitive and regulated operating environments
Governance
Roadmaps, risk visibility, and executive alignment
Core security domains
ZERO TRUST01
Enterprise Cloud Security
Designing and governing secure AWS and GCP environments across multiple accounts, projects, networks, applications, identities, and operational teams.
Key areas include
- Cloud security architecture
- CNAPP and cloud posture management
- Multi-account and multi-project governance
- Cloud network segmentation
- Workload protection
- Secure inter-cloud connectivity
- Encryption and data protection
- Cloud risk and configuration assessments
02
DevSecOps and Secure Delivery
Embedding security into the software-development lifecycle without turning security into a delivery bottleneck.
Key areas include
- CI/CD security
- SAST, DAST, and SCA
- Secrets detection and management
- Container security
- Secure release gates
- Vulnerability-remediation workflows
- Secure SDLC
- Shift-Left security adoption
03
Zero Trust and Identity Security
Strengthening access across users, applications, APIs, machines, and cloud services through identity-led security controls.
Key areas include
- IAM restructuring
- Privileged Access Management
- Least-privilege access
- SSO and MFA
- Machine and service identities
- API-to-API authentication
- Zero Trust employee access
- Access governance and data classification
04
Security Strategy and Governance
Translating technical exposure into clear priorities, controls, roadmaps, and executive decisions.
Key areas include
- Cybersecurity roadmaps
- Security gap analysis
- Risk registers
- Security policies and standards
- Executive posture reporting
- Vendor and SOC governance
- Regulatory alignment
- Security-program maturity
Selected Security Programs
SECURELarge-Scale Multi-Cloud Security Governance
Security architecture and governance across dozens of AWS accounts and GCP projects supporting a high-traffic digital media platform.
The program covers organization-level IAM, network governance, cloud monitoring, firewalls, WAFs, site-to-site connectivity, data protection, vulnerability management, and executive risk visibility.
DevSecOps Security Across Hundreds of Pipelines
Security integration across hundreds of CI/CD pipelines and dozens of engineering environments.
The work includes automated testing, secrets detection, application-security controls, container security, vulnerability remediation, and automated release decisions.
Zero Trust and IAM Transformation
A broad identity and access transformation covering employee access, machine identities, cloud permissions, service authentication, and API-to-API communication.
The program reduced dependency on hardcoded credentials and strengthened least-privilege access across cloud and application environments.
Air-Gapped Threat Intelligence Architecture
Architecture of a threat-intelligence platform for a sensitive critical-infrastructure environment that processes large sensitive datasets without direct internet connectivity.
The solution used controlled, unidirectional data flows to preserve isolation while supporting required information exchange.
Financial Infrastructure and Security Transformation
Transformation of IT and security infrastructure across roughly twenty financial-services sites processing tens of thousands of transactions per day.
The program included network redesign, security hardening, monitoring, access controls, automation, regulatory alignment, and Disaster Recovery.
National Tax Platform Cloud Security
Cloud and application security architecture for a national-level taxation platform integrated with a national information-exchange authority.
The work covered segmented environments, database clustering, cloud controls, application-security standards, and protection of sensitive taxpayer data.
Leadership and security approach
OPS READYClear strategic control without removing technical ownership.
I set what must be addressed, why it matters, and when it is due—while teams retain ownership of how to implement durable, automated controls.
- Security ownership with accountable outcomes
- Engineering autonomy within clear risk boundaries
- Risk-driven prioritization over tool volume
- Executive alignment through measurable posture reporting
Ready to discuss an advisory engagement?
Fractional leadership, architecture review, DevSecOps transformation, and governance support—scoped to the outcomes your organization needs next.
Selected experience
OPS READY2023 – Present
Senior Cloud Security & DevSecOps / Lead Security Architect
Shahid — MBC Group · Full-time
Lead and contribute to cloud security architecture, DevSecOps, Zero Trust, IAM, application security, security governance, and risk management in a multi-cloud enterprise environment.
2022 – 2023
Cyber Security Team Leader & Consultant
Seniors IT · Full-time
Led a small cybersecurity team delivering enterprise and government security programs across Jordan, Saudi Arabia, and Qatar.
2019 – 2021
Information Technology & Security Manager
Al-Alami Financial Services · Full-time
Managed IT and security infrastructure across roughly twenty financial-services locations, supporting regulated operations and tens of thousands of daily transactions.
2019
Cloud and Security Engineer
DareebaTech · Freelance
Designed cloud and application security controls for a national taxation platform integrated with a national information-exchange authority.
2015 – 2019
IT Infrastructure Engineer
Capital Investments — Capital Bank · Full-time
Managed enterprise infrastructure, data centers, servers, firewalls, monitoring, Office 365 migration, and Disaster Recovery initiatives.
2011 – 2014
Network Engineer
Hyperlink · Full-time
Built foundational experience in enterprise networks, infrastructure, connectivity, troubleshooting, and security technologies.
How I approach security
Operating principles that keep architecture, engineering, and executive decisions aligned.
Security by Design
Security belongs in architecture and planning—not as a retrofit.
Identity Before Perimeter
Users, services, machines, and privileges must be known and governed first.
Automation Over Manual Control
Repeatable security decisions should be automated where possible.
Risk-Based Prioritization
Not every finding carries equal business impact.
Need senior cybersecurity direction without hiring a full-time executive?
I provide selected advisory and leadership support for organizations that need to strengthen their security strategy, cloud architecture, DevSecOps practices, risk governance, or security operations.