SECUREOPS READY

From network engineering to enterprise cybersecurity leadership.

My professional career began in 2011 in network engineering and enterprise infrastructure.

That foundation gave me direct experience with the systems, networks, identities, data centers, and operational dependencies that modern cybersecurity programs must protect.

Over time, my responsibilities expanded into infrastructure engineering, cloud architecture, security operations, application security, DevSecOps, governance, risk management, and technical leadership.

Today, I work across cloud, on-premises, and hybrid environments to help organizations build security capabilities that are practical, measurable, scalable, and aligned with business priorities.

Professional Journey

OPS READY
  1. 01

    Building the Infrastructure Foundation

    My early career focused on network engineering and infrastructure operations.

    I worked with routers, switches, firewalls, servers, data centers, identity services, virtualization, monitoring, backup platforms, and enterprise connectivity.

    This foundation continues to influence how I approach cybersecurity: security controls must be designed around how infrastructure and operations actually work.

  2. 02

    Moving into Financial Infrastructure and Security

    At Capital Investments, part of Capital Bank, I worked across enterprise infrastructure serving financial operations, external clients, internal users, and more than 100 servers.

    My responsibilities included data centers, Disaster Recovery, Office 365 migration, WAFs, load balancers, next-generation firewalls, Windows and Linux systems, virtualization, storage, monitoring, and telecommunications providers.

    This role expanded my experience from infrastructure administration into architecture, resilience, security, and regulated operations.

  3. 03

    Leading IT and Security Transformation

    As Information Technology & Security Manager at Al-Alami Financial Services, I managed technology and security across 20 locations processing approximately 30,000 to 50,000 financial transactions per day.

    I led infrastructure redesign, security hardening, identity integration, Disaster Recovery, operational automation, compliance alignment, monitoring, and security-platform management.

    The transformation delivered measurable improvements in cost, process speed, response time, security posture, and infrastructure availability.

  4. 04

    Moving into Enterprise Cybersecurity Consulting

    At Seniors IT, I led a team of six cybersecurity engineers delivering projects across Jordan, Saudi Arabia, and Qatar.

    The work included cybersecurity assessments, solution architecture, technical proposals, security transformation, government migrations, critical infrastructure, and air-gapped environments.

    This role strengthened my client-facing consulting, architecture, team leadership, and regional security-delivery experience.

  5. 05

    Securing Large-Scale Cloud Environments

    In my current role at Shahid within MBC Group, my work spans cloud security, DevSecOps, identity, application security, governance, incident response, and enterprise risk.

    I focus on multi-cloud security architecture, organization-level IAM, Zero Trust, automated delivery controls, risk visibility, and secure transformation programs.

    The work connects security strategy with engineering ownership so controls stay practical, measurable, and aligned with business priorities.

Experience

OPS READY
  1. 2023 – Present

    Senior Cloud Security & DevSecOps / Lead Security Architect

    Shahid — MBC Group · Amman, Jordan · Full-time

    Lead and contribute to cloud security architecture, DevSecOps, Zero Trust, IAM, application security, governance, and risk management across a multi-cloud enterprise digital platform — connecting strategy, engineering ownership, and practical operating controls.

    Show key highlights

    Security Strategy and Governance

    • Conducted security gap analyses across cloud, application, infrastructure, identity, and operations.
    • Developed multi-year cybersecurity roadmaps aligned with business growth, engineering priorities, and organizational risk.
    • Authored cybersecurity policies, standards, procedures, and technical security requirements.
    • Established risk registers and recurring posture reporting for stakeholders.
    • Supported governance aligned with GDPR, data-protection requirements, Saudi NCA controls, NIST principles, and ISO 27001-related practices.

    Multi-Cloud Security Architecture

    • Architected and governed security controls across AWS and GCP estates.
    • Restructured organization-level identity and access models and applied least-privilege principles.
    • Governed network security, segmentation, and secure inter-cloud connectivity.
    • Designed secure architectures for new services while hardening legacy environments.
    • Implemented cloud security monitoring and posture-management capabilities, including CNAPP-aligned controls.

    Zero Trust, IAM, and Secrets

    • Redesigned organizational IAM structures and strengthened service and machine identities.
    • Implemented Zero Trust controls for employee and machine access.
    • Improved API-to-API authentication and authorization patterns.
    • Reduced hardcoded credentials and improved secrets management in cloud and delivery workflows.
    • Strengthened SSO, MFA, and access governance for sensitive data.

    DevSecOps and Application Security

    • Embedded security controls into CI/CD and release workflows.
    • Introduced SAST, DAST, SCA, secrets detection, and container-security checks where they improve outcomes.
    • Built automated security gates that support clear release decisions.
    • Promoted Shift-Left practices and continuous remediation cycles with engineering teams.
    • Supported Secure SDLC across architecture, coding, testing, deployment, and monitoring.

    Monitoring, Incident Response, and SOC

    • Supported centralized monitoring, logging, and SIEM integration.
    • Led and coordinated incident-response and threat-mitigation activities.
    • Governed third-party SOC services through clear expectations and quality feedback.
    • Improved detection quality by reducing noise and strengthening actionable alerting.

    Secure Transformation

    • Directed security architecture alignment during major enterprise domain and service migrations.
    • Reviewed and reconfigured controls for affected identities, networks, accounts, and applications.
    • Supported secure migration planning while preserving business continuity.
  2. 2022 – 2023

    Cyber Security Team Leader & Consultant

    Seniors IT · Amman, Jordan · Full-time

    Led a cybersecurity team delivering enterprise and government security programs across Jordan, Saudi Arabia, and Qatar — covering architecture, assessments, proposals, and critical-infrastructure delivery.

    Show key highlights

    Leadership and Delivery

    • Led a team of six cybersecurity engineers across planning, implementation, and client delivery.
    • Acted as the primary client-facing technical and security lead for multiple engagements.
    • Gathered technical, operational, security, and regulatory requirements from stakeholders.
    • Mentored engineers and strengthened delivery quality across concurrent programs.

    Architecture and Consulting

    • Designed enterprise cybersecurity strategies and target-state architectures.
    • Developed solutions spanning cloud, on-premises, and hybrid infrastructure.
    • Led discovery, architecture design, prototyping, and transformation planning.
    • Supported technical and commercial proposals with clear scope and assumptions.

    Security Solution Portfolio

    • WAF, SIEM, VAPT, DLP, DDoS protection, NGFW, IPS, and sandboxing
    • IAM, PAM, NAC, MFA, SOC, TIP, monitoring, and incident response

    Critical Infrastructure and Government

    • Led zero-downtime migrations of email and infrastructure security systems for sensitive government environments.
    • Supported security-transformation initiatives for critical sectors, including water and electricity.
    • Architected threat-intelligence patterns for offline, air-gapped environments with controlled unidirectional data flows.
  3. 2019 – 2021

    Information Technology & Security Manager

    Al-Alami Financial Services · Jordan · Full-time

    Owned IT and security transformation across a regulated financial-services footprint — rebuilding infrastructure, strengthening controls, improving recovery, and accelerating operations through automation.

    Show key highlights

    Infrastructure and Security Transformation

    • Managed technology and security across roughly twenty financial-services locations.
    • Redesigned headquarters and branch network and security architecture.
    • Implemented and strengthened NGFW, WAF, endpoint security, segmentation, monitoring, and access control.
    • Integrated cloud services with Active Directory, SSO, and identity platforms.
    • Designed and launched a functional Disaster Recovery site.

    Governance, Compliance, and Risk

    • Authored and enforced IT and security policies, standards, and operational controls.
    • Aligned practices with Central Bank requirements, PCI DSS, ISO 27001-related controls, and NIST principles.
    • Supported regulatory reviews, assessments, audit preparation, and remediation.
    • Conducted infrastructure penetration testing and vulnerability assessments.

    Automation and Operational Improvement

    • Automated major IT, security, operational, and financial workflows.
    • Delivered measurable improvements in response time, process speed, cost, security posture, and uptime.
    • Coordinated internal teams, vendors, and multi-workstream technology programs.
  4. 2019

    Cloud and Security Engineer

    DareebaTech · Amman, Jordan · Freelance

    Designed cloud and application security controls for a national taxation platform integrated with Jordan’s National Information Center, protecting sensitive taxpayer and transaction data.

    Show key highlights

    Project Context

    • Supported cloud and security architecture for a national-level Jordanian taxation application.
    • Focused on sensitive income and sales-tax information protection.

    Responsibilities and Achievements

    • Designed secure AWS and Azure-based environments with the development team.
    • Defined the initial security framework and application security standards.
    • Conducted security-gap reviews and documented cloud and web-application controls.
    • Designed segmented development, testing, and production environments.
    • Supported clustered database architecture and secure connectivity with the National Information Center.
  5. 2015 – 2019

    IT Infrastructure Engineer

    Capital Investments — Capital Bank · Amman, Jordan · Full-time

    Managed enterprise infrastructure for financial operations — covering data centers, servers, firewalls, monitoring, Office 365 migration, and Disaster Recovery initiatives.

    Show key highlights

    Environment

    • Supported critical financial infrastructure used by external clients and internal teams.
    • Managed a multi-server estate, firewalls, WAF capabilities, and dual data-center operations.

    Key Programs

    • Disaster Recovery site implementation
    • WAF and load-balancer deployment
    • NGFW and data-center firewall improvements
    • Office 365 migration and Azure adoption

    Operations and Platforms

    • Administered Windows/Linux servers, hypervisors, storage, directory services, and backup platforms.
    • Worked with VMware, Hyper-V, SAN, Veeam, Active Directory, F5, Splunk, Palo Alto, Fortinet, and Cisco security products.
    • Served as a primary contact for telecommunications carriers and automated repetitive infrastructure tasks.
  6. 2011 – 2014

    Network Engineer

    Hyperlink · Amman, Jordan · Full-time

    Built foundational experience in enterprise networks, infrastructure, connectivity, troubleshooting, and security technologies that later supported the transition into cloud and cybersecurity leadership.

    Show key highlights

    Foundation

    • Supported routers, switches, network connectivity, security devices, and infrastructure operations.
    • Developed practical experience in network administration, troubleshooting, and infrastructure support.
    • Built the systems knowledge that later enabled enterprise infrastructure, cloud architecture, and cybersecurity leadership work.

Professional Focus

SECURE
  • 01

    Enterprise Cloud and Hybrid Security

    I design security controls across cloud, on-premises, and hybrid environments.

    My work considers identity, networks, workloads, applications, APIs, data, monitoring, resilience, and operational ownership as connected parts of one architecture.

  • 02

    DevSecOps Transformation

    I work with development and infrastructure teams to integrate security into planning, code, pipelines, testing, releases, and production operations.

    The objective is not simply to introduce more tools. It is to create a repeatable remediation process and make security part of engineering responsibility.

  • 03

    Security Governance

    Security programs require more than technology.

    I develop policies, roadmaps, risk registers, reporting structures, release controls, vendor governance, and executive decision frameworks that turn security requirements into accountable action.

  • 04

    Critical and Regulated Environments

    My experience includes media platforms, banking, financial services, government organizations, taxation systems, water, electricity, and sensitive offline environments.

    These environments require controlled change, operational resilience, auditability, clear ownership, and security controls that reflect regulatory and business realities.

Leadership Approach

OPS READY

Clear strategic control without removing technical ownership.

My leadership model separates strategic authority from implementation autonomy.

  • Direction and Priorities

    I retain responsibility for defining:

    • What must be addressed
    • Why it matters
    • When it must be completed
    • Which risks require escalation
    • Which decisions affect architecture, compliance, or business continuity
  • Team Ownership

    Teams are encouraged to determine:

    • How implementation can be improved
    • Which practical technical approach is most effective
    • How workflows can be automated
    • How recurring operational issues can be reduced
    • How security controls can be integrated into everyday delivery

Senior Review

Decisions affecting security architecture, sensitive data, access control, critical dependencies, production releases, or long-term risk remain subject to senior review.

Education

Bachelor of Information Technology and Computing

Arab Open University, Jordan

2010 – 2014

Professional Certifications

  • PCNSE
  • NSE 4
  • ITIL
  • CCNA
  • MCSA
  • CompTIA A+

Career Direction

SECURE

I am open to selected opportunities as:

  • Chief Information Security Officer
  • Head of Cloud Security
  • Head of Cybersecurity
  • Director of Cybersecurity
  • Lead Security Architect
  • Fractional CISO
  • Senior Cybersecurity Consultant
  • Cloud Security Advisor
  • DevSecOps Security Lead

My primary regional focus includes Saudi Arabia, the GCC, and MENA, while remaining open to global remote engagements.