SECUREOPS READY

From network engineering to enterprise cybersecurity leadership.

My professional career began in 2011 in network engineering and enterprise infrastructure.

That foundation gave me direct experience with the systems, networks, identities, data centers, and operational dependencies that modern cybersecurity programs must protect.

Over time, my responsibilities expanded into infrastructure engineering, cloud architecture, security operations, application security, DevSecOps, governance, risk management, and technical leadership.

Today, I work across cloud, on-premises, and hybrid environments to help organizations build security capabilities that are practical, measurable, scalable, and aligned with business priorities.

Professional Journey

OPS READY
  1. 01

    Network Engineering

    My career began in network engineering and infrastructure operations.

    I worked with routers, switches, firewalls, servers, data centers, identity services, virtualization, monitoring, backup platforms, and enterprise connectivity.

    That foundation still shapes how I design cybersecurity: controls must fit how infrastructure and operations actually work.

  2. 02

    Enterprise Infrastructure

    At Capital Investments, part of Capital Bank, I moved into enterprise infrastructure supporting financial operations, external clients, and internal users across a multi-server estate.

    Responsibilities spanned data centers, Disaster Recovery, Office 365 migration, WAFs, load balancers, next-generation firewalls, Windows and Linux systems, virtualization, storage, monitoring, and carrier coordination.

    The role expanded my work from infrastructure administration into architecture, resilience, security, and regulated operations.

  3. 03

    Financial Infrastructure & Security Transformation

    As Information Technology & Security Manager at Al-Alami Financial Services, I owned technology and security across roughly twenty locations processing approximately 30,000 to 50,000 financial transactions per day.

    I led infrastructure redesign, security hardening, identity integration, Disaster Recovery, operational automation, compliance alignment, monitoring, and security-platform management.

    The transformation produced measurable gains in cost, process speed, response time, security posture, and infrastructure availability.

  4. 04

    Cybersecurity Consulting

    At Seniors IT, I led a team of six cybersecurity engineers delivering programs across Jordan, Saudi Arabia, and Qatar.

    Engagements covered assessments, solution architecture, technical proposals, security transformation, government migrations, critical infrastructure, and air-gapped environments.

    This stage strengthened client-facing consulting, architecture leadership, team delivery, and regional security execution.

  5. 05

    Enterprise Cloud Security Leadership

    In my current role at Shahid within MBC Group, I operate at the intersection of cloud security, DevSecOps, identity, application security, governance, incident response, and enterprise risk.

    Focus areas include multi-cloud security architecture, organization-level IAM, Zero Trust, automated delivery controls, risk visibility, and secure transformation programs.

    The work connects security strategy with engineering ownership so controls remain practical, measurable, and aligned with business priorities.

Experience

OPS READY
  1. 2023 – Present

    Senior Cloud Security & DevSecOps / Lead Security Architect

    Shahid — MBC Group · Amman, Jordan · Full-time

    Lead and contribute to cloud security architecture, DevSecOps, Zero Trust, IAM, application security, governance, and risk management across a multi-cloud enterprise digital platform — connecting strategy, engineering ownership, and practical operating controls.

    Show key highlights

    Security Strategy and Governance

    • Conducted security gap analyses across cloud, application, infrastructure, identity, and operations.
    • Developed multi-year cybersecurity roadmaps aligned with business growth, engineering priorities, and organizational risk.
    • Authored cybersecurity policies, standards, procedures, and technical security requirements.
    • Established risk registers and recurring posture reporting for stakeholders.
    • Supported governance aligned with GDPR, data-protection requirements, Saudi NCA controls, NIST principles, and ISO 27001-related practices.

    Multi-Cloud Security Architecture

    • Architected and governed security controls across AWS and GCP estates.
    • Restructured organization-level identity and access models and applied least-privilege principles.
    • Governed network security, segmentation, and secure inter-cloud connectivity.
    • Designed secure architectures for new services while hardening legacy environments.
    • Implemented cloud security monitoring and posture-management capabilities, including CNAPP-aligned controls.

    Zero Trust, IAM, and Secrets

    • Redesigned organizational IAM structures and strengthened service and machine identities.
    • Implemented Zero Trust controls for employee and machine access.
    • Improved API-to-API authentication and authorization patterns.
    • Reduced hardcoded credentials and improved secrets management in cloud and delivery workflows.
    • Strengthened SSO, MFA, and access governance for sensitive data.

    DevSecOps and Application Security

    • Embedded security controls into CI/CD and release workflows.
    • Introduced SAST, DAST, SCA, secrets detection, and container-security checks where they improve outcomes.
    • Built automated security gates that support clear release decisions.
    • Promoted Shift-Left practices and continuous remediation cycles with engineering teams.
    • Supported Secure SDLC across architecture, coding, testing, deployment, and monitoring.

    Monitoring, Incident Response, and SOC

    • Supported centralized monitoring, logging, and SIEM integration.
    • Led and coordinated incident-response and threat-mitigation activities.
    • Governed third-party SOC services through clear expectations and quality feedback.
    • Improved detection quality by reducing noise and strengthening actionable alerting.

    Secure Transformation

    • Directed security architecture alignment during major enterprise domain and service migrations.
    • Reviewed and reconfigured controls for affected identities, networks, accounts, and applications.
    • Supported secure migration planning while preserving business continuity.
  2. 2022 – 2023

    Cyber Security Team Leader & Consultant

    Seniors IT · Amman, Jordan · Full-time

    Led a cybersecurity team delivering enterprise and government security programs across Jordan, Saudi Arabia, and Qatar — covering architecture, assessments, proposals, and critical-infrastructure delivery.

    Show key highlights

    Leadership and Delivery

    • Led a team of six cybersecurity engineers across planning, implementation, and client delivery.
    • Acted as the primary client-facing technical and security lead for multiple engagements.
    • Gathered technical, operational, security, and regulatory requirements from stakeholders.
    • Mentored engineers and strengthened delivery quality across concurrent programs.

    Architecture and Consulting

    • Designed enterprise cybersecurity strategies and target-state architectures.
    • Developed solutions spanning cloud, on-premises, and hybrid infrastructure.
    • Led discovery, architecture design, prototyping, and transformation planning.
    • Supported technical and commercial proposals with clear scope and assumptions.

    Security Solution Portfolio

    • WAF, SIEM, VAPT, DLP, DDoS protection, NGFW, IPS, and sandboxing
    • IAM, PAM, NAC, MFA, SOC, TIP, monitoring, and incident response

    Critical Infrastructure and Government

    • Led zero-downtime migrations of email and infrastructure security systems for sensitive government environments.
    • Supported security-transformation initiatives for critical sectors, including water and electricity.
    • Architected threat-intelligence patterns for offline, air-gapped environments with controlled unidirectional data flows.
  3. 2019 – 2021

    Information Technology & Security Manager

    Al-Alami Financial Services · Jordan · Full-time

    Owned IT and security transformation across a regulated financial-services footprint — rebuilding infrastructure, strengthening controls, improving recovery, and accelerating operations through automation.

    Show key highlights

    Infrastructure and Security Transformation

    • Managed technology and security across roughly twenty financial-services locations.
    • Redesigned headquarters and branch network and security architecture.
    • Implemented and strengthened NGFW, WAF, endpoint security, segmentation, monitoring, and access control.
    • Integrated cloud services with Active Directory, SSO, and identity platforms.
    • Designed and launched a functional Disaster Recovery site.

    Governance, Compliance, and Risk

    • Authored and enforced IT and security policies, standards, and operational controls.
    • Aligned practices with Central Bank requirements, PCI DSS, ISO 27001-related controls, and NIST principles.
    • Supported regulatory reviews, assessments, audit preparation, and remediation.
    • Conducted infrastructure penetration testing and vulnerability assessments.

    Automation and Operational Improvement

    • Automated major IT, security, operational, and financial workflows.
    • Delivered measurable improvements in response time, process speed, cost, security posture, and uptime.
    • Coordinated internal teams, vendors, and multi-workstream technology programs.
  4. 2019

    Cloud and Security Engineer

    DareebaTech · Amman, Jordan · Freelance

    Designed cloud and application security controls for a national taxation platform integrated with a national information-exchange authority, protecting sensitive taxpayer and transaction data.

    Show key highlights

    Selected Impact

    • Designed secure AWS and Azure environments with the development team and defined the initial security framework.
    • Documented cloud and web-application controls, segmented development/testing/production environments, and supported secure connectivity with a national information-exchange authority.
  5. 2015 – 2019

    IT Infrastructure Engineer

    Capital Investments — Capital Bank · Amman, Jordan · Full-time

    Managed enterprise infrastructure for financial operations — covering data centers, servers, firewalls, monitoring, Office 365 migration, and Disaster Recovery initiatives.

    Show key highlights

    Selected Impact

    • Supported critical financial infrastructure across a multi-server estate, firewalls, WAF capabilities, and dual data-center operations.
    • Delivered Disaster Recovery, WAF/load-balancer, NGFW, and Office 365 / Azure adoption workstreams.
    • Operated Windows/Linux, virtualization, storage, directory services, backup platforms, and carrier coordination using VMware, Hyper-V, SAN, Veeam, Active Directory, F5, Splunk, Palo Alto, Fortinet, and Cisco security products.
  6. 2011 – 2014

    Network Engineer

    Hyperlink · Amman, Jordan · Full-time

    Built foundational experience in enterprise networks, infrastructure, connectivity, troubleshooting, and security technologies that later supported the transition into cloud and cybersecurity leadership.

    Show key highlights

    Foundation

    • Supported routers, switches, connectivity, security devices, and infrastructure operations while building the systems knowledge that later enabled enterprise infrastructure and cybersecurity leadership work.

Professional Focus

SECURE
  • 01

    Enterprise Cloud and Hybrid Security

    I design security controls across cloud, on-premises, and hybrid environments.

    My work considers identity, networks, workloads, applications, APIs, data, monitoring, resilience, and operational ownership as connected parts of one architecture.

  • 02

    DevSecOps Transformation

    I work with development and infrastructure teams to integrate security into planning, code, pipelines, testing, releases, and production operations.

    The objective is not simply to introduce more tools. It is to create a repeatable remediation process and make security part of engineering responsibility.

  • 03

    Security Governance

    Security programs require more than technology.

    I develop policies, roadmaps, risk registers, reporting structures, release controls, vendor governance, and executive decision frameworks that turn security requirements into accountable action.

  • 04

    Critical and Regulated Environments

    My experience includes media platforms, banking, financial services, government organizations, taxation systems, water, electricity, and sensitive offline environments.

    These environments require controlled change, operational resilience, auditability, clear ownership, and security controls that reflect regulatory and business realities.

Leadership Approach

OPS READY

Clear strategic control without removing technical ownership.

My leadership model separates strategic authority from implementation autonomy. I set direction, risk priorities, and decision boundaries—while teams retain practical ownership of how work gets done.

  • Security Ownership

    I retain responsibility for defining:

    • What must be addressed and why it matters
    • When work must be completed
    • Which risks require escalation
    • Which decisions affect architecture, compliance, or business continuity
    • Where security ownership sits across cloud, identity, delivery, and operations
  • Engineering Autonomy

    Teams are trusted to determine:

    • How implementation can be improved
    • Which practical technical approach is most effective
    • How workflows can be automated
    • How recurring operational issues can be reduced
    • How security controls fit into everyday delivery
  • Risk-Driven Prioritization

    Remediation and investment decisions consider:

    • Business exposure and criticality
    • Exploitability and operational context
    • Dependencies that affect delivery or continuity
    • What can wait versus what must escalate now
  • Executive Alignment

    Leadership communication focuses on:

    • Clear risk narrative in business terms
    • Progress against roadmap and remediation priorities
    • Unresolved decisions that need executive input
    • Trade-offs between security investment and delivery speed
  • Measurable Outcomes

    Security programs should produce:

    • Visible posture and risk-register progress
    • Release controls with clear go/no-go criteria
    • Reduced noise and more actionable detection
    • Evidence that owners, deadlines, and outcomes stay connected

Senior Review

Decisions affecting security architecture, sensitive data, access control, critical dependencies, production releases, or long-term risk remain subject to senior review.

Education

Bachelor of Information Technology and Computing

Arab Open University, Jordan

2010 – 2014

Professional Certifications

  • PCNSE
  • NSE 4
  • ITIL
  • CCNA
  • MCSA
  • CompTIA A+

Career Direction

SECURE

I am open to selected opportunities as:

  • Chief Information Security Officer
  • Head of Cloud Security
  • Head of Cybersecurity
  • Director of Cybersecurity
  • Lead Security Architect
  • Fractional CISO
  • Senior Cybersecurity Consultant
  • Cloud Security Advisor
  • DevSecOps Security Lead

My primary regional focus includes Saudi Arabia, the GCC, and MENA, while remaining open to global remote engagements.