Securing complex enterprise environments without slowing the business behind them.
I am a Senior Cloud Security & DevSecOps / Lead Security Architect with more than 15 years of experience across cloud security, enterprise infrastructure, DevSecOps automation, Zero Trust, security governance, and critical infrastructure.
I work across AWS, GCP, on-premises, and hybrid environments to transform security requirements into scalable architectures, automated controls, measurable risk programs, and practical engineering standards.
Available for selected cybersecurity advisory, Fractional CISO, cloud security architecture, and senior leadership opportunities.
Security architecture that connects engineering, operations, risk, and executive direction.
My work sits between hands-on security engineering and strategic cybersecurity leadership.
I help organizations secure complex platforms, modernize infrastructure, integrate security into software delivery, strengthen identity and access controls, and establish governance that executives and technical teams can act on.
My experience spans high-traffic digital platforms, financial services, banking, government systems, national taxation platforms, and critical infrastructure.
Credibility Highlights
OPS READY~15
Years of professional experience since 2011
Millions
Users supported within environments under security scope
Billions
Daily platform operations within enterprise environments secured
Hundreds
CI/CD pipelines supported by integrated security controls
Dozens
AWS accounts and GCP projects governed across multi-cloud footprints
Hundreds
CIDR blocks governed across interconnected cloud environments
Hundreds
Firewalls governed within enterprise security programs
~20
Financial-services sites managed within a regulated environment
Core Professional Focus
ZERO TRUST01
Enterprise Cloud Security
Designing and governing secure AWS and GCP environments across multiple accounts, projects, networks, applications, identities, and operational teams.
Key areas include
- Cloud security architecture
- CNAPP and cloud posture management
- Multi-account and multi-project governance
- Cloud network segmentation
- Workload protection
- Secure inter-cloud connectivity
- Encryption and data protection
- Cloud risk and configuration assessments
02
DevSecOps and Secure Delivery
Embedding security into the software-development lifecycle without turning security into a delivery bottleneck.
Key areas include
- CI/CD security
- SAST, DAST, and SCA
- Secrets detection and management
- Container security
- Secure release gates
- Vulnerability-remediation workflows
- Secure SDLC
- Shift-Left security adoption
03
Zero Trust and Identity Security
Strengthening access across users, applications, APIs, machines, and cloud services through identity-led security controls.
Key areas include
- IAM restructuring
- Privileged Access Management
- Least-privilege access
- SSO and MFA
- Machine and service identities
- API-to-API authentication
- Zero Trust employee access
- Access governance and data classification
04
Security Strategy and Governance
Translating technical exposure into clear priorities, controls, roadmaps, and executive decisions.
Key areas include
- Cybersecurity roadmaps
- Security gap analysis
- Risk registers
- Security policies and standards
- Executive posture reporting
- Vendor and SOC governance
- Regulatory alignment
- Security-program maturity
Selected Security Programs
SECURELarge-Scale Multi-Cloud Security Governance
Security architecture and governance across dozens of AWS accounts and GCP projects supporting a high-traffic digital media platform.
The program covers organization-level IAM, network governance, cloud monitoring, firewalls, WAFs, site-to-site connectivity, data protection, vulnerability management, and executive risk visibility.
DevSecOps Security Across Hundreds of Pipelines
Security integration across hundreds of CI/CD pipelines and dozens of engineering environments.
The work includes automated testing, secrets detection, application-security controls, container security, vulnerability remediation, and automated release decisions.
Zero Trust and IAM Transformation
A broad identity and access transformation covering employee access, machine identities, cloud permissions, service authentication, and API-to-API communication.
The program reduced dependency on hardcoded credentials and strengthened least-privilege access across cloud and application environments.
Air-Gapped Threat Intelligence Architecture
Architecture of a threat-intelligence platform for a sensitive critical-infrastructure environment that processes large classified datasets without direct internet connectivity.
The solution used controlled, unidirectional data flows to preserve isolation while supporting required information exchange.
Financial Infrastructure and Security Transformation
Transformation of IT and security infrastructure across roughly twenty financial-services sites processing tens of thousands of transactions per day.
The program included network redesign, security hardening, monitoring, access controls, automation, regulatory alignment, and Disaster Recovery.
National Tax Platform Cloud Security
Cloud and application security architecture for a national-level taxation platform integrated with Jordan’s National Information Center.
The work covered segmented environments, database clustering, cloud controls, application-security standards, and protection of sensitive taxpayer data.
Experience
OPS READY2023 – Present
Senior Cloud Security & DevSecOps / Lead Security Architect
Shahid — MBC Group · Full-time
Lead and contribute to cloud security architecture, DevSecOps, Zero Trust, IAM, application security, security governance, and risk management in a multi-cloud enterprise environment.
2022 – 2023
Cyber Security Team Leader & Consultant
Seniors IT · Full-time
Led a small cybersecurity team delivering enterprise and government security programs across Jordan, Saudi Arabia, and Qatar.
2019 – 2021
Information Technology & Security Manager
Al-Alami Financial Services · Full-time
Managed IT and security infrastructure across roughly twenty financial-services locations, supporting regulated operations and tens of thousands of daily transactions.
2019
Cloud and Security Engineer
DareebaTech · Freelance
Designed cloud and application security controls for a national taxation platform integrated with the National Information Center.
2015 – 2019
IT Infrastructure Engineer
Capital Investments — Capital Bank · Full-time
Managed enterprise infrastructure, data centers, servers, firewalls, monitoring, Office 365 migration, and Disaster Recovery initiatives.
2011 – 2014
Network Engineer
Hyperlink · Full-time
Built foundational experience in enterprise networks, infrastructure, connectivity, troubleshooting, and security technologies.
Compliance and Governance Experience
Security-control implementation and governance experience related to:
- Saudi National Cybersecurity Authority controls
- GDPR
- DPBL and data-protection requirements
- ISO 27001-related controls
- NIST frameworks and principles
- PCI DSS
- Central Bank requirements
- Internal governance, audit, and risk controls
Technology Overview
SIGNAL LIVECloud and Architecture
- AWS
- GCP
- Azure
- CNAPP
- CloudFormation
- Kubernetes
- Docker
- Cloud Security Posture Management
DevSecOps and Application Security
- GitLab
- Jenkins
- SAST
- DAST
- SCA
- IAST
- RASP
- ASM
- Secure SDLC
- Secrets Management
Identity and Data Protection
- IAM
- PAM
- SSO
- MFA
- NAC
- DLP
- Zero Trust
- Data Classification
Security Operations
- SIEM
- SOAR
- TIP
- SOC Governance
- Incident Response
- VAPT
- Elastic
- Splunk
- Zabbix
Network and Infrastructure Security
- WAF
- DDoS Protection
- NGFW
- Palo Alto
- Fortinet
- IPS
- Sandbox
- F5
- VPN
- Proxy
Enterprise Infrastructure
- Windows Server
- Linux
- VMware
- Hyper-V
- Office 365
- Active Directory
- SAN
- Veeam
- Disaster Recovery
Need senior cybersecurity direction without hiring a full-time executive?
I provide selected advisory and leadership support for organizations that need to strengthen their security strategy, cloud architecture, DevSecOps practices, risk governance, or security operations.