Summary
Overview
Certification
Work History
Education
Skills
Timeline
Work Availability
CORE COMPETENCIES
CORE COMPETENCIES
Generic
Mohamed Mohey Elmasry

Mohamed Mohey Elmasry

Regina,SK

Summary

Senior Consultant | Cloud Infrastructure and Security Architect Lead, where I lead cloud platform and application modernization projects for enterprise clients across various industries.

Proficient in evaluating risks, implementing security controls, and conducting security reviews to align with best practices.

Expert in managing security architecture for multi-cloud environments, compliance with ISO 27001, and building high-quality deliverables for strategic security projects.

Expert in advising on secure infrastructure enforcing cloud security configuration baselines and driving cloud security architecture aligned with regulatory standards (ISO 27001, PCI DSS, NIST).

Performing information security design assessments & gap analysis, designing, deploying, and maintaining cloud-based security solutions, with a focus on cloud-native architecture.

Extensive experience in designing, deploying, and supporting cloud-based solutions, with a focus on cloud-native architecture and infrastructure as code (IaC) methodologies.

Extensive knowledge and experience in using public cloud offerings, such as Serverless, containers and CI/CD pipelines automation, to create complex hybrid and multi-cloud environments.

Designing and implementing key components of Cloud such as network & infrastructure security, threat detection, incident response, vulnerability management, security governance, risk and compliance, security architecture.

Designing and implementing defense-in-depth information security controls and concepts for critical application and data environments.

Designing and implementing solutions using principles and practices of Zero trust security architecture.

Developing in depth understanding of the regulatory requirements that apply to the organizations, such as ISO 27001, Payment Card Industry Data Security Standard (PCI DSS) regulations, NIST and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

leads the evaluation and implementation of security technologies and solutions, ranging from firewall systems and intrusion detection/prevention systems (IDS/IPS) to advanced threat detection and response tools.

Overview

19
19
years of professional experience
7
7
Certificate
2
2
Languages

Certification

  • AWS DevOps Engineer Professional
  • AWS Security Specialty
  • AWS Advanced Networking Specialty
  • AWS Big Data Specialty
  • AWS SysOps Administrator Associate
  • AWS Developer Associate
  • AWS Solutions Architect Associate
  • TOGAF

Work History

Cloud Solutions | Cybersecurity Architect Lead

Government Of Saskatchewan
01.2024 - Current
  • Leads the evaluation and implementation of security technologies and SaaS, PaaS, IaaS solutions in multi public cloud providers Oracle Cloud Infrastructure, Azure, AWS and Oracle fusion.
  • Performing information security design assessments & gap analysis.
  • Strengthened GoS cybersecurity posture by conducting regular risk assessments and implementing security controls.
  • Designing and implementing defense-in-depth information security controls and concepts for critical application and data environments.
  • Enhanced client satisfaction by providing timely and accurate guidance on Oracle Cloud Security best practices and features.
  • Collaborated with cross-functional teams to ensure secure seamless integration of Oracle Cloud solutions into existing IT environments.
  • Enhanced Oracle fusion HCM system security controls by conducting thorough analysis and identifying areas for improvement.
  • Increased cloud infrastructure efficiency by designing and implementing scalable solutions.

Cloud Solutions | Infrastructure Architect

CGI
12.2017 - 01.2024
  • Trusted Advisor and core customer liaison, creating and maintaining long-term strategic relationships.
  • Conducts interviews different key stakeholders such security architects, application architects, infrastructure architects.
  • Discovery and understanding of client business operations, models, and footprints to build custom enterprise secure solutions to maximize value.
  • Assessing and developing Infrastructure solutions and programs across multiple domains.
  • led the implementation and maintenance of NIST Cyber security framework (CSF), CIS controls, AWS Security pillars best practice, Network best practice controls and PCI DSS framework.
  • Designs and Implement Infrastructure as a code conformance packs pipelines to continues monitor the environment resources and generate alerts, and automatic remediation for non-compliance resources.
  • Working with engagement enablement, including scoping engagements, structuring customized engagements to meet client requirements, proposal writing, and drafting statements of work.
  • Working with development teams to ensure that new applications meet all required performance, security, and compliance standards before being deployed to production.
  • Having strong experience and hands-on for designing and deploying end-to-end networking infrastructure using infrastructure-as-code and pipelines.


Key Projects:

Design and Implementation of Via Rail booking system.

Customer: Via Rail Canada

Role: Cloud Security infrastructure and DevOps Architect

  • Deigned landing zone baseline with multi-account architecture, identity and access management, governance, data security, network design, and logging
  • Designed and implemented privileged access management (PAM) solution that support temporary permissions access, tracking actions, store permissions history.
  • Designed and Integrated with Azure AD to achieve single sign on (SSO) requirements
  • Designed Implemented the DNS firewalls by only allowing only the necessary traffic to specific domains.
  • Designed and Implemented next generation firewalls to filter out the traffic and implement specific custom rules.
  • Designed and Implemented solution to protect the public end points during the maintenance window by leveraging firewalls capabilities and create custom FW rules.
  • Designed and implemented network and security controls by IaC (Infrastructure as code) to expedite replicating the environments to simulate the test scenarios without impacting production environment and avoid human interventions.
  • Designed and Implemented Remote access solution using Identity and access management and sessions services to control the access through sessions.
  • Applied security controls that monitor the effective of the encryption policies across the environment.
    Ensured the certification rotation at least annually in place and ensuring the certification expiration notifications is effective.
  • Implemented best security API security standards, such as protecting the API gateway with Web Application firewalls, enable the access and execution logging, IAM authentications, TLS/SSL Certifications, etc.
  • Design and implementation of landing zone multi-accounts environment including workload accounts, data security, network design and logging.
  • Designed and Implemented Identity access management (IAM) and privileged access management PAM on Public Cloud platforms.
  • Designed and implemented automation CI/CD pipeline with hands on experience in DevOps tools such as Code Pipeline, and Code Build.
  • Hands on experience in delivering Microservice, SPA, API gateway, building CI/CD pipelines to manage seamless deployments.
  • Strong understanding of containerization and Kubernetes orchestration, Hands on experience with building and deploying containerized applications.
  • Automated implementation of NIST security framework in five-function model (identify, protect, detect, respond, and recover)
  • Managed implementation and remediation of best practices, CIS and PCI DSS security controls and applied auto remediation strategy.


Project: Manage Farm Credit Canada Infrastructure

Customer: Farm Credit Canada

Role: Cloud and Client Architect

  • Work with stakeholders to understand their business requirements and design cloud solutions to meet those needs.
  • Deliver, maintain, and own high-level architectural roadmap that is constantly in alignment with Product Management roadmap, to support business growth.
  • Evaluate current state of enterprise's IT systems and identifying future state that better meets business objectives of enterprise.

Enterprise Architect Consultant

Wipro
10.2012 - 10.2017

Key Projects:

Design and Implementation of BSS Digital Transformation program.

Customer: Saudi Telecom Company (STC) - KSA

Role: Enterprise Architect

  • Created intelligent architectural decisions for Business Support Systems Transformation (BSST).
  • Provided detailed guidelines, blueprints, and transitional architecture for transformation program in addition to leading and managing transformation design workshops with architects and designers.
  • Led 70+ workshops in client meetings for requirement analysis and information gathering from business users and successfully transformed business requirements into robust solutions ahead of schedule.
  • Acted as liaising between marketing team and IT team for designing telecom b2c commercial products, bundles and offers on BSS where successfully delivered BAU 83 projects in first year.

Design and Implementation of Digital transformation.

Customer: Mobily - KSA

Role: Solution Architect

  • Supervised deployments and provided troubleshooting and user support.
  • Worked with client’s post-implementation on user testing, debugging, support and maintenance.
  • Conducted post-sale requirements gathering, analysis and documentation.
  • Installed, integrated, and deployed CRM and Billing products in client environments.
  • Conducted technical workshops and education sessions for customers and Support teams.

Solution Delivery Consultant

ADIB
05.2012 - 10.2012
  • Defined enterprise processes and best practices and tailored enterprise processes for applications.
  • Managed installation, upgrade and deployment projects and provided on-site direction for network engineers.
  • Managed and monitored installed systems for highest level of availability.

Solution Architect

Etisalat
07.2007 - 05.2012
  • Supervised deployments and provided troubleshooting and user support.
  • Guided and influenced existing partners on recommended upgrades and enhancements to integrated solutions.
  • Managed project planning, resource allocation, scope, schedule, status and documentation.

Billing System Information Analyst

HP
11.2005 - 07.2007
  • Displayed unsurpassed ability in managing the handover of Texas team applications to Egypt team.
  • Resolved delivery of systems problems when arise and liaised production releases within a specified SLA.
  • Pioneered the development of a process and template for handing over tickets between L2 and L3 teams that created demarcation point.

Education

Bachelor of Science - Electrical And Computer Engineering

Ain Shams
Cairo, EGY
09.2004

Skills

  • Detail-Oriented & Strategic Planning
  • Executive Support & Expert level communicator
  • Technical Leadership & Analytical Thinking
  • Vendor interaction and management
  • Stakeholders Handling
  • Critical Thinking & Effective Team worker
  • Highly Organized Decision Maker
  • Self-Motivated
  • Solution Presentation
  • Python
  • Endpoint Protection
  • Endpoint Security
  • Service Monitoring
  • Cloud Security
  • Automation
  • Communication Skills

Timeline

Cloud Solutions | Cybersecurity Architect Lead

Government Of Saskatchewan
01.2024 - Current

Cloud Solutions | Infrastructure Architect

CGI
12.2017 - 01.2024

Enterprise Architect Consultant

Wipro
10.2012 - 10.2017

Solution Delivery Consultant

ADIB
05.2012 - 10.2012

Solution Architect

Etisalat
07.2007 - 05.2012

Billing System Information Analyst

HP
11.2005 - 07.2007

Bachelor of Science - Electrical And Computer Engineering

Ain Shams
  • CISSP
  • AWS DevOps Engineer Professional
  • AWS Security Specialty
  • AWS Advanced Networking Specialty
  • AWS Big Data Specialty
  • AWS SysOps Administrator Associate
  • AWS Developer Associate
  • AWS Solutions Architect Associate
  • TOGAF

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

CORE COMPETENCIES

  • Identity access management (IAM).
  • Privileged access management (PAM).
  • Data loss protection (DLP).
  • Encryption in transit & Encryption at rest.
  • Web Application Firewall (WAF) and DDoS solutions.
  • SSL Certificates, HSM
  • NIST CSF, PCI DSS
  • Backup & Disaster recovery
  • VPN, VPC, WAF, NGFW, SNS, SQS, Lambda, ACM, TGW
  • Python, CI/CD, CloudFormation, CodeBuild, CodePipeline
  • Source control versions systems (GitHub, BitBucket)
  • Agile Development Methodologies
  • Serverless, Containers, EKS, Kubernetes
  • Cloud Solutions Architecture
  • Infrastructure Solutions Architecture
  • DevOps & SecOps
  • Security Architecture
  • Incidents management
  • Security Posture Assessment
  • Secure Development Life Cycle
  • Digital Transformation
  • Microservice Architecture
  • Containers orchestrations & Serverless
  • Endpoint Detection & Response (EDR)
  • SIEM, Log management, threat intelligence, continuous monitoring
  • Penetration testing
  • TOGAF & TMForum Frameworx (eTOM, TAM, SID)

CORE COMPETENCIES

  • Identity access management (IAM).
  • Privileged access management (PAM).
  • Data loss protection (DLP).
  • Encryption in transit & Encryption at rest.
  • Web Application Firewall (WAF) and DDoS solutions.
  • SSL Certificates, HSM
  • NIST CSF, PCI DSS
  • Backup & Disaster recovery
  • VPN, VPC, WAF, NGFW, SNS, SQS, Lambda, ACM, TGW
  • Python, CI/CD, CloudFormation, CodeBuild, CodePipeline
  • Source control versions systems (GitHub, BitBucket)
  • Agile Development Methodologies
  • Serverless, Containers, EKS, Kubernetes
  • Cloud Solutions Architecture
  • Infrastructure Solutions Architecture
  • DevOps & SecOps
  • Security Architecture
  • Incidents management
  • Security Posture Assessment
  • Secure Development Life Cycle
  • Digital Transformation
  • Microservice Architecture
  • Containers orchestrations & Serverless
  • TOGAF & TMForum Frameworx (eTOM, TAM, SID)
Mohamed Mohey Elmasry