Skip to content
About

Twenty-five years, one thread: securing the systems a country runs on.

Engineer first, executive second. The career runs from crimping cable in Cairo server rooms to owning national security infrastructure in Doha, and from there to building the presales organisations that design security for MENA's banks.

Currently Head of Cybersecurity Solutions & Presales at Cylert, Cairo.

Portrait pending — upload one in Settings
  1. 1999 — 2011

    The engineering decade

    I graduated in electrical engineering from Ain Shams in 1999 and added a higher diploma in telecommunication systems from Egypt's National Telecommunication Institute. Then came a decade at System Engineering of Egypt doing the unglamorous work that actually makes engineers: security gateways, early FortiGate firewalls, fibre backbones, university campus networks, X.25 and Frame Relay links that had to stay up.

    Two projects from that decade still shape how I think. Building the network for Egypt's National Security Center, where "it works" was never enough — it had to keep working. And connecting 450+ offices of the Social Insurance Ministry, one of the largest WAN environments in the country, where scale punishes every shortcut you took at site three.

  2. 2008 — 2012

    The CCIE, and the teaching habit

    In 2009 I passed the CCIE Routing & Switching lab. Number 24249 — at the time, one of a small handful in Egypt. Around the same period I was teaching CCNA and CCNA Security at Raya Academy and Ain Shams, designing the modules myself.

    Teaching turned out to be the best presales training there is. If you can make spanning tree make sense to a room of students at eight in the evening, you can make a security architecture make sense to a board.

    At Equinox I led the team that delivered Egypt's first Network Access Control deployment — distributed Cisco ISE for NDB and ADIB on an eight-server architecture — and wrote the CCIE-level engineering documentation that became the company's delivery standard.

  3. 2012 — 2017

    Qatar: five years where downtime was not a word

    I led network security for Qatar's National Command Center at the Ministry of Interior — the 24/7 infrastructure behind national emergency response, spanning data, voice, video, GPRS and TETRA radio. MPLS core, Nexus data centres, a two-tier firewall architecture across Cisco ASA and Check Point, with RSA identity enforcing real separation between the management and data planes.

    Working inside a multinational team on infrastructure a country depends on recalibrates your standards permanently. Every architecture I have reviewed since gets the same question I learned to ask there: what happens at three in the morning when this fails?

  4. 2017 — 2024

    Building the organisations that deliver

    Back in Cairo I moved from delivering security to building the teams that deliver it. At SEE I managed 16+ security architects and engineers. As CTO of Arian747 I built a SOC-centred offering anchored on LogRhythm. At Hemaya I ran four specialised practices — network security, identity, information security and SOC — leading 30+ senior consultants through enterprise deployments at NBE, CIB and Banque Misr.

    That period produced the number this site quotes: multi-year engagements that grew service footprint in major financial accounts by roughly 40%. Not built on sales tactics — built on architectures that passed their audits and did what the proposal said they would.

  5. 2025 — today

    Presales leadership

    As Presales Director at Hemaya I architected the end-to-end presales lifecycle: standardised proposals, SoW authoring, reusable architectures, and vendor onboarding across Cisco, Fortinet, Palo Alto, Forcepoint, LogRhythm, BeyondTrust, F5, Tenable, Darktrace, Group-IB and more.

    Since January 2026 I have headed Cybersecurity Solutions & Presales at Cylert, defining solution strategy and running executive consultations and technical workshops, with influence on $10M+ of annual security pipeline across banking, government and critical infrastructure.

How I work

Three habits from twenty-five years

  • 01

    Write it down.

    From CCIE reference material to hardening standards for PIX, ASA, FortiGate and Palo Alto — documentation is how one engineer's experience becomes a team's capability.

  • 02

    Teach as you go.

    The instructor period never really ended, it just changed audiences: students, then engineers I managed, now client teams. Mentoring engineers into architects is the part of leadership I rate highest.

  • 03

    Stay neutral where it counts.

    I have sold alongside 25+ vendors, which is exactly why bank-facing advisory is vendor-neutral in writing: no commissions, no referral fees, and never both sides of the same deal.

Credentials

Verifiable, not asserted

Both numbers below can be checked against the issuing body. Roughly 5,000 people worldwide hold CCIE and CISSP together; the combination is the whole point, because one proves the engineering and the other proves the governance.

  • CCIE #24249

    Routing & Switching, passed 2009

  • CISSP

    ISC2, active

  • CCIE Security

    Written, lab track

  • CCIE Service Provider

    Written, 2015

  • LogRhythm LRSA & LRPA

    Security & Platform Analyst

  • Cortex XDR & XSOAR

    Palo Alto Networks

Higher Diploma, Telecommunication Systems

National Telecommunication Institute (NTI), Egypt

Specialisation: network & data communication design. Grade: Very Good (80.4%).

B.Sc. Electrical Engineering

Ain Shams University, Faculty of Engineering, Egypt

Vendor ecosystem

32 technologies I have actually put in front of a customer

Sold, designed with, deployed, or run a PoC against. Knowing how each of them sells is exactly why the bank-facing work stays neutral.

  • Cisco
  • Palo Alto Networks
  • Fortinet
  • Check Point
  • F5
  • Forcepoint
  • LogRhythm
  • Splunk
  • IBM QRadar
  • CrowdStrike
  • Trellix
  • Kaspersky
  • BeyondTrust
  • OneSpan
  • RSA Security
  • Veridium
  • Ivanti
  • Tenable
  • Rapid7
  • Darktrace
  • Group-IB
  • Akamai
  • Imperva
  • Kong
  • Symantec / Broadcom
  • Trend Micro
  • Seclore
  • Black Duck
  • Mandiant
  • Recorded Future
  • Infoblox
  • VMware

The full record is one click away.

The CV carries the complete engagement list, every certification and the technology matrix. Or skip the reading and send me the actual problem.