Infrastructure operations specialist with extensive experience at Saudi Telecom Company, specializing in firewall configuration and incident response. Demonstrated success in enhancing network security posture and effectively managing change. Skilled in traffic analysis and project management, driving successful security initiatives across diverse environments.
Overview
25
25
years of professional experience
Work History
Sr. Network Security Engineer
Al- Inma Bank
Riyadh
08.2006 - 11.2009
Installed and configured 4 high availability pairs of Sidewinder Firewalls for Al Inma Bank, enhancing security for online and corporate banking applications, bank-to-bank transactions, and internet access.
Installed and configured high availability pair of Sidewinder Firewalls for SAMA, facilitating secure connectivity for the Saudi Arabian Riyal Inter-bank Express system (SARIE) to the SAMA Joint Network.
Implemented firewalls and intrusion detection systems for enhanced security measures.
Implemented security measures for network infrastructure and data protection.
Developed security policies to protect network infrastructure from potential threats.
Collaborated with IT teams to ensure secure data transmission across networks.
Monitored network traffic for suspicious activity and potential breaches.
Provided training to staff on best practices for network security protocols.
Responded to security incidents, investigating breaches and recommending corrective actions.
Investigated security incidents and performed root cause analysis to determine source of attack vectors.
Collaborated closely with internal stakeholders such as application developers and database administrators while assessing risk associated with changes made by them.
Facilitated communication among departments to define their roles in information security initiatives.
Created firewalls, access control lists, virtual private networks and other security measures to protect the organization's data assets.
Network Security Engineer
SADAD (Electronic Payments system)
Riyadh
03.2005 - 11.2009
Installed and configured 4 pairs of Cyberguard Firewalls for online transaction protection, connecting all banks and SAMA networks, along with internal firewalls for SADAD applications.
Upgraded SAMA CyberGuard Firewalls from version 5 to 5.2, enhancing security features and performance.
Configured firewalls and intrusion detection systems to secure network environments.
Monitored network traffic for unusual activity and potential breaches.
Developed security policies and procedures to safeguard sensitive data.
Analyzed system logs from various sources including routers, switches, servers, and applications to identify suspicious activities or patterns.
Facilitated electronic customer payment collection through SADAD, linking commercial sector with local banks across all banking channels in the kingdom.
Infrastructure Operations Specialist
SAUDI TELECOMMUNICATION COMPANY
Riyadh, Riyadh
05.2010 - Current
Collaborated with Communications and Information Technology Commission (Saudi Arabia) CST (Communications, Space & Technology Commission) to resolve urgent URL filtering issues 24/7.
Reviewed and approved/rejected Network Security Requests (NSCR) from IPSD design team for implementation on firewalls.
Govern daily Change Management activities performed by MSPs
Govern daily Change Management activities performed by MSPs.( MDT/EMDT/TCN/ETCN).
Audit SLA of the MSPs
Facilitated communication between system and security teams.
Overall interact with Design Team in order to escalate points that need improvement, fix, expansion, removal from the network … etc.
MAJOR ASSIGNMENTS: Web (URL) filtering Project, STC Public DNS Project
Collaborated with IT teams to ensure compliance with security policies.
Reviewed vendor contracts for compliance with company security policies prior to signing off on them.
Performed regular patch management activities including installation of critical patches and updates on all computers within the organization's domain.
Installed anti-malware solutions such as antivirus software and malware protection programs on servers, workstations and mobile devices.
Manage SaudiNet RIPE Account and reply back to MSPs requests regarding RIPE objects of STCs (IP Subnets, Root Objects … etc.)
Expert/ SPOC Security & Systems critical technologies URL filtering,DNS,LB's..etc
DATA NW governor & managing MPS's Juniper/Huawei/Cisco
Overall interact with IPSD Design for Implementation of NSCR's / SCR's and working on RFP's & new POC's
Working with SNIC-NOC 24/7 for any issue related to CST /systems / Filtering and Security in IGW/SDN networks
Working with multiple vendors / MSP's and different departments in STC to resolve trivel and crtitical issues raised during the NSCR's and SCR's implementation & troubleshooting
Working with many different projects for Transport Operations, /involves /works /leads the projects as per decision from management
Working with Systems & Security for issues related to CST for URL web filtering, DNS, LB's and insure (as governor) the availability of Filtering system are working as per CST standards. This filtering systems is one of the very important techonology in STC. Which CITC is keeping an eye 24/7
Govern daily Change Management activities performed by MSPs (Juniper/Huawei/Cisco)
Sr. Network Security Engineer
SaudiNet (ISP) / STC
Riyadh
12.2007 - Current
Executed the installation, maintenance, monitoring, and troubleshooting of 128 Sidewinder high-end firewalls for SaudiNet's Internet filtering system, managing HTTP and HTTPS traffic for nearly all ISPs in Saudi Arabia with a throughput exceeding 20 GB per second.
Led team of 5 engineers in security department for SaudiNet ISP, enhancing overall security posture.
Installed and configured Smart Filter Server for IGW filtering in Riyadh and Jeddah, including Windows 2003 servers, improving internet security filtering capabilities.
Installed, maintained, and monitored Smart Servers for SaudiNet, effectively blocking unauthorized websites across Saudi Arabia.
Resolved HTTP and HTTPS traffic issues in collaboration with ISPs.
Responsible for Installing and configuring Sawmill (Log files Analysis and reporting tool) for all IGW Filters at STC (Saudi Telecom Company) Riyadh and Jeddah.
Responsible for configuring log server for storing all Firewall logs.
Migrated ISPs from old Internet Gateway to new Internet Gateway network.
Addressed routing challenges for ISPs to ensure smooth migration to new Internet Gateway.
Network Security Engineer
Al-Rumaih Company/BMC/(MidEast Data System) MDS Group
06.2001 - 04.2010
Configured and implemented Sidewinder Firewalls environments for various government and public/private sector clients.
Deployed hardware and managed software to streamline implementation processes for the team.
Collaborated with customers and vendors to achieve contract milestones, facilitating progress that may have stalled without my involvement.
Contributed to MidEast Data Systems Saudi Arabia, a key IT player, in delivering components that ensure business continuity across organizational levels.
Monitored network security systems for potential threats and vulnerabilities.
Developed and implemented security policies to protect sensitive information.
Configured firewalls and intrusion detection systems for enhanced protection.
Configured and maintained firewalls, intrusion detection systems, and virtual private networks.
Trained new employees on proper usage of company resources with regards to information security policies.
Performed regular backups of critical data stored on the corporate network in accordance with established guidelines.
Implemented security patches, hotfixes, and service packs on all systems in order to maintain system integrity.
Developed security policies and procedures for network infrastructure to ensure organizational compliance.
Performed vulnerability scans and penetration testing of the corporate network to identify any potential security risks.
Conducted periodic reviews of user accounts and privileges within the organization's directory structure.
Directed vulnerability assessments or analysis of information security systems.
Network Security Engineer
Saudi Hollandi Bank
Riyadh
02.2003 - 11.2008
Configured and maintained firewalls, intrusion detection systems, and virtual private networks.
Configured firewalls and intrusion detection systems to enhance security measures.
Implemented network security protocols to protect sensitive company data.
Monitored network traffic for potential security threats and vulnerabilities.
Performed vulnerability scans and penetration testing of the corporate network to identify any potential security risks.
Developed security policies and procedures for network infrastructure to ensure organizational compliance.
Configured and installed three high availability pairs along with a standalone Cyberguard firewall for personal and corporate banking, bank-to-bank online transactions, internet firewall for Hollandi Bank, and disaster recovery site firewall.
Network Security Engineer – Contractor at MidEast Data Systems
Saudi Arabian Monetary Agency (SAMA)
Riyadh
01.2002 - 11.2007
Worked with securing the most critical & Economy Financial applications and networks of Saudi Arabian Monitoring Agency, as a team leader. Heading with 6 engineers.
Executed installation and configuration of CyberGuard Firewalls across all banks, ensuring compliance with SAMA security standards.
Conducted installation, maintenance, monitoring, and troubleshooting of 40 high availability pairs of CyberGuard Firewalls for banks and their DR sites in Saudi Arabia, ensuring reliable connections to SAMA via SARIE, TADAWUL, SPAN, and SADAD networks.
Managed installation projects for emerging banks, conducting site surveys and overseeing installation and configuration processes.
Executed the upgrade of all CyberGuard high availability pairs of firewalls in SAMA from version 5.0 to 5.2, ensuring minimal downtime.
Oversaw upgrade of SAMA CyberGuard Firewalls, enhancing security through latest version configuration.
Implementation Engineer for SARIE / Tadawul Migration (Cyberguard firewalls).
Implementation Engineer for installing SADAD and SPAN in 8 Banks.
Installing and configuring CyberGuard Firewall for E-Trust project.
Creating Host to Gateway VPN tunnels for SPAN application at bank side in Kuwait Bank.
Preparing network design in Microsoft Visio and giving network solution to customer.
Ensured availability of SAMA applications (SARIE, TADAWUL, and SPAN) for banks with no downtime.
The central bank of the Kingdom of Saudi Arabia was established in 1952.
Installed and configured CyberGuard Firewalls for the Following, New and upcoming banks with specific applications to secure SAMA Network with the Banks networks.
Sr. Network Security Consultant
Samba Financial Group
Riyadh
02.2004 - 02.2005
Configured and installed CyberGuard and Sidewinder Firewalls, securing Online Banking and DMZ servers in compliance with SAMBA standards.
Implemented updated rules and policies across all SAMBA Firewalls following business requirement approvals.
Troubleshot and monitored 8 pairs of Cyberguard Firewalls alongside 10 pairs of CISCO Pix Firewalls.
Configured, installed, monitored, and troubleshot remote location Firewalls in London.
Established VPN tunnels between Riyadh (Head Office & Branch Office) and London (SAMBA Branch) using CyberGuard, Sidewinder, and SnapGear Firewalls for secure connectivity.
Performed daily configuration backups for each Cyberguard Firewall.
Configuring Cyberguard & Cisco Pix Firewalls to send Syslog to remote Syslog servers.
Established user accounts on firewalls to control access for local administrator group.
Upgraded all CyberGuard High Availability pairs in SAMBA from version 5.0 to 5.2, minimizing downtime during the transition.
Samba Financial Group is a leading financial institution in Saudi Arabia.
Project handled at SAMBA: SAMBA SwiftNet Project [Society for Worldwide Interbank Financial Telecommunication (SWIFT)].
Swiftnet is an application designed to transfer money securely from Bank to Bank.
Planning, Designing and providing connectivity from Servers in DMZ area at SAMBA to the server in Belgium and across the world.
Upgraded all the SAMA CyberGuard Firewalls from version 5 to 5.2.
Migrating all 8 pairs of CyberGuard Firewalls to Sidewinder Firewalls version 7 patch 70007.
Sr.Network Security Engineer
STC (Saudi Telecom) DNS Project/Saudi Arabia
Riyadh
03.2002 - 08.2004
Cyberguard firewalls installation and configuration for 8 pairs of Cyberguard firewalls.
Implemented firewall configurations to safeguard sensitive data transmission.
Developed guidelines to enhance compliance with security policies, strengthening overall security framework.
Approved final configurations of firewalls for STC engineers.
Configured and set up Webtrends Servers (Firewall reporting center) for Cisco-Pix and Cyberguard Firewalls at STC (Saudi Telecom Company) across Riyadh, Dammam, and Jeddah.
Configured, managed, monitored, and resolved issues with Symantec IDS Manhunt at STC (Saudi Telecom).
Collaborated with cross-functional teams to enhance overall security posture.
Performed regular security audits and assessments on network systems, identifying vulnerabilities and ensuring adherence to security standards.
Trained junior engineers on best practices in network security management.
Trained personnel on information assurance and cyber defense strategies, increasing awareness of social engineering attacks and improving organizational resilience.
Coordinated with other departments regarding their respective roles and responsibilities with respect to Information Security initiatives.
Conducted periodic vulnerability scans using automated tools such as Nessus or QualysGuard to assess the security posture of the organization's networks.
Created firewalls, access control lists, virtual private networks and other security measures to protect the organization's data assets.
Configured routers and switches with ACLs, NAT and PAT, VLANs and VPNs to secure the network infrastructure.
Implemented authentication protocols such as RADIUS, TACACS+, Kerberos to manage user access rights.