Mohamed Farouk Zyada
25 years turning security architecture into signed deals for regulated banks and government in Egypt, Qatar and the Gulf. One of roughly 5,000 people worldwide holding both CCIE and CISSP.
Head of Cybersecurity Solutions & Presales · Cairo, Egypt · Working across Egypt and the Gulf
$10M+
Annual security pipeline influenced
banking, government, critical infrastructure30+
Engineers and consultants led
across four security practices25+
Years in cybersecurity
engineer → architect → director40%
Service footprint growth
in major financial accounts (CIB, NBE)Profile
I build and lead the presales and professional-services organisations that design multi-vendor security for banks, ministries, exchanges and critical infrastructure. Twenty-five years, starting as a network engineer pulling fibre in Cairo and ending up in the room where a CISO decides what to buy.
The technical foundation is a CCIE (#24249, passed 2009) and an active CISSP. The commercial half is a decade of running practices, owning pipeline and writing the proposals that win bids. Both halves matter: I have never been able to sell an architecture I could not also defend at a whiteboard.
Certifications
CCIE #24249
Routing & Switching, passed 2009
CISSP
ISC2, active
CCIE Security
Written, lab track
CCIE Service Provider
Written, 2015
LogRhythm LRSA & LRPA
Security & Platform Analyst
Cortex XDR & XSOAR
Palo Alto Networks
Experience
- Jan 2026 — Present
Cylert
Cairo, EgyptCurrentHead of Cybersecurity Solutions & Presales
Own the solution strategy and roadmap for enterprise security across high-growth markets.
- Define the strategy and roadmap for enterprise security solutions, and run vendor evaluation, selection and strategic partnerships.
- Integrate best-of-breed technologies into a coherent SOC and threat-intelligence offering rather than a vendor list.
- Run executive consultations and deep-dive technical workshops, aligning security architecture to business objectives and regulatory requirements.
- Author technical proposals and presentations for both emerging and established technologies.
- Track regulatory frameworks and align the offering to compliance requirements as they move.
- Jan 2025 — Dec 2025
Hemaya Information Technology
Cairo, EgyptPresales Director
Built the presales lifecycle management framework from scratch.
- Architected the end-to-end presales lifecycle, improving pipeline conversion through standardised methodology and disciplined proposal and SoW authoring.
- Delivered multi-technology security architectures spanning SIEM, SOAR, XDR, PAM, MFA, UEBA, DLP, web and email gateway, NGFW, VPN, LTM/ASM, EPP/EDR, NDR, IDS/IPS/HIPS, vulnerability management, API security and SAST/DAST.
- Onboarded strategic vendor partnerships: Cisco, Fortinet, Palo Alto, Forcepoint, LogRhythm, BeyondTrust, OneSpan, Tenable, Rapid7, Black Duck, Cyber Ranges, Seclore, Darktrace, Group-IB, Kaspersky, Recorded Future, Mandiant, Google, Veridium.
- Established reusable solution architectures and templates, cutting proposal response time.
- Directed complex PoCs including environment setup and performance benchmarking, securing competitive wins in banking and government.
- Mar 2020 — Dec 2024
Hemaya Information Technology
Cairo, EgyptProfessional Services Manager
Ran four specialised practices — Network Security, Identity, Information Security and SOC.
- Led 30+ senior consultants and engineers across enterprise delivery.
- Oversaw large-scale multi-vendor deployments across Cisco, Fortinet, Palo Alto, Forcepoint, LogRhythm, BeyondTrust, Ivanti, Symantec, F5, Trellix, OneSpan, Tenable, Rapid7, Darktrace and Group-IB.
- Delivered enterprise-scale implementations for NBE, CIB and Banque Misr, including Palo Alto, Ivanti, Tripwire, LogRhythm SIEM and OneSpan MFA.
- Designed layered defensive architectures (DLP, WAF, EDR/XDR) and grew service footprint in key financial accounts by roughly 40% through multi-year engagements.
- Jan 2019 — Feb 2020
Arian747 IT Partners
Cairo, EgyptChief Technology Officer
Built a SOC-centred offering anchored on LogRhythm SIEM.
- Positioned the company as a niche specialist in SOC design and information-security consulting in the Egyptian market.
- Delivered tailored security solutions for SMEs and larger enterprises.
- Used a multi-vendor stacking approach to reduce single-vendor risk and improve commercial flexibility for clients.
- Feb 2017 — Nov 2018
SEE — System Engineering of Egypt
Cairo, EgyptProfessional Services Manager, Network Security & InfoSec
Led a team of 16+ security architects and engineers.
- Structured and managed specialised delivery teams — security architects and professional technical engineers — for scalable enterprise service delivery.
- Negotiated strategic vendor partnerships across Cisco, Fortinet, Palo Alto, F5, Forcepoint, Tenable, Gemalto, RSA, Trend Micro, Infoblox and Symantec (Blue Coat).
- Oversaw SOC implementations, network security architectures and professional services engagements.
- Directed vulnerability assessment and management programmes for key accounts.
- Nov 2012 — Jan 2017
National Command Center, Ministry of Interior
Doha, QatarNetwork Security Team Lead
Five years owning 24/7 national-scale infrastructure behind emergency response.
- Ran mission-critical infrastructure operating 24/7 across data, voice and video networks inside a multinational team.
- Designed high-availability architectures: MPLS-based core, Nexus data-centre networks and layered security controls.
- Architected a two-tier firewall architecture (Cisco ASA and Check Point) with RSA identity management enforcing real separation between management and data planes.
- Built the multi-vendor environment: Cisco Nexus 7K/5K/2K and 6500, EMC data-centre technology, F5 LTM/ASM for application delivery, RSA for identity.
- Supported wired and wireless communications including GPRS and TETRA radio across large-scale infrastructure.
- Jun 2011 — Nov 2012
Equinox International Egypt
Cairo, EgyptTechnical Team Leader, Network Security
Delivered Egypt's first Network Access Control deployment.
- Pioneered the first NAC deployment in Egypt — distributed Cisco ISE for major banks including NDB and ADIB, on an eight-server architecture (2 admin/monitoring, 6 policy nodes) — and demonstrated the solution for Banque Misr.
- Designed and implemented network and security solutions across Cisco ASA/PIX firewalls, IDS/IPS (v4–v7) and HIPS.
- Delivered end-to-end routing, switching and network security architectures across Cisco, Fortinet and McAfee environments.
- Authored the CCIE Routing & Switching and Security technical documentation that became the company's internal engineering standard.
- Jan 2007 — Jun 2011
SEE — System Engineering of Egypt
Cairo, EgyptNetwork Security Team Leader
Security gateways, national infrastructure and university campus networks.
- Deployed Symantec SGS 5000 series security gateways — firewalling, antivirus, anti-spam, content filtering, IDS/IPS and email security — across a diverse enterprise customer base.
- Designed and built the National Security Center network on a Nortel 8600 core with a full fibre-optic backbone.
- Deployed early-stage Fortinet FortiGate UTM firewalls.
- Delivered university-scale infrastructure for Menia University (Paradyne DSLAM, SDSL/HDSL across distributed campuses) and Assiut University (Cisco multilayer and core switches 4005/4007).
- Jan 2001 — Jun 2007
SEE — System Engineering of Egypt
Cairo, EgyptNetwork & Network Security Engineer
Large-scale network transformations from legacy Motorola to Cisco.
- Migrated legacy Motorola infrastructure to Cisco routing and switching across enterprise and government customers.
- Connected 450+ sites of the Social Insurance Ministry via X.25 and Frame Relay — one of the largest WAN environments in the country.
- Jan 2008 — Jan 2009
Raya Academy & Ain Shams University
Cairo, EgyptInstructor — Networking and Security
Taught CCNA and CCNA Security; designed the learning modules.
- Delivered professional training in routing & switching and network security, including the CCNA and CCNA Security curricula.
- Designed structured learning modules and hands-on assessments preparing students for certification and real-world scenarios.
Selected client engagements
Named where the client relationship allows it. The technology and the scope are accurate in every case.
| Client | Sector | Scope |
|---|---|---|
| CIB (Commercial International Bank) | Banking | Internal banking security aligned to PCI-DSS and SWIFT CSP: OneSpan 2FA, Tripwire FIM, Forcepoint DLP, Palo Alto NGFW integrated with web and email gateways. |
| National Bank of Egypt (NBE) | Banking | LogRhythm SIEM distributed across DC/DR, Tenable vulnerability management, perimeter firewalls, IPS and VPN acceleration. |
| Banque Misr | Banking | Forcepoint DLP (web and email), Ivanti MobileIron MDM, OneSpan 2FA for internet banking, Cisco ISE proof of concept. |
| Central Bank of Egypt — MAQASA | Central bank | Network access secured via L2L VPN for all Egyptian banks. |
| Banque du Caire | Banking | DMVPN across 300+ branches, OneSpan 2FA and Tripwire FIM. |
| EGX (The Egyptian Exchange) | Capital markets | Forcepoint email and web gateways plus sandboxing, with Palo Alto NGFW distributed across DC/DR. |
| PPC & GASCO | Oil & gas / OT | SCADA leak-detection security, firewalls (Palo Alto and FTD), SSL gateways, Ivanti/Cisco NAC and SolarWinds monitoring across national critical infrastructure. |
| Social Insurance Ministry | Government | Connectivity and security across 450+ offices nationwide. |
| National Command Center, Ministry of Interior | Government / national security | 24/7 national emergency-response infrastructure across data, voice, video, GPRS and TETRA. MPLS core, Nexus data centres, two-tier ASA/Check Point firewall architecture with RSA identity. |
Technical domains
- Strategic presales & architecture
- End-to-end presales lifecycle, solution architecture, C-level engagement, RFP/RFI/RFQ, SoW authoring, PoC management, technical discovery, value-based selling, competitive analysis, technical workshops and demos.
- SOC, detection & response
- SIEM (LogRhythm, QRadar, Splunk, Elastic, RSA NetWitness), SOAR (Cortex XSOAR), XDR (Cortex XDR, Trellix), UEBA, NDR (Darktrace), EDR/EPP (Trellix, Kaspersky), IDS/IPS/HIPS, incident response, threat hunting, malware analysis, digital forensics.
- Network, perimeter & OT security
- NGFW (Cisco Firepower, Fortinet, Palo Alto, Check Point), VPN (IPsec, SSL VPN, DMVPN, GETVPN), segmentation, ZTNA (Ivanti, Appgate), NAC (Cisco ISE, Ivanti), OT/ICS and SCADA security, PKI and HSM.
- Identity, access & Zero Trust
- Zero Trust architecture, PAM (BeyondTrust PAM/PRA/EPM), MFA/2FA (OneSpan, RSA, Veridium), IAM, identity federation and access control.
- Application & API security
- WAAP and WAF (F5 BIG-IP ASM/APM, NGINX App Protect), API security (F5, Akamai, Imperva), API gateway (Kong, NGINX Plus), OAuth/JWT, secure SDLC, OWASP Top 10, bot protection.
- Data security & encryption
- DLP (Forcepoint, Symantec), DRM (Seclore), data classification (Boldon James), encryption and key management, HSM concepts.
- Vulnerability & exposure management
- Vulnerability assessment and management (Tenable, Rapid7), DAST (Rapid7 InsightAppSec, Invicti), SAST (Black Duck, Checkmarx), BAS, CTEM, attack surface management, cyber ranges, risk-based prioritisation.
- Threat intelligence & analytics
- Threat intelligence (Group-IB, Recorded Future, Mandiant, Google Threat Intelligence), AI-driven detection (Darktrace), malware and fraud analysis.
- Cloud & modern workload security
- Cloud security fundamentals (AWS/Azure), cloud workload protection (CWPP), container and Kubernetes security, microservices security, DevSecOps integration.
- Network infrastructure & routing
- BGP, OSPF, EIGRP, MPLS; Cisco Nexus 7K/5K/2K, Catalyst 6500; DSL/DSLAM; Motorola (Vanguard, Codex); high-availability network design.
Regulatory frameworks
- CBE
Central Bank of Egypt cybersecurity regulations
Control mapping and gap-assessment support, plus incident-reporting readiness aligned with EG-FinCIRT. Delivered security programmes inside CBE-regulated banks.
- SAMA
SAMA Cyber Security Framework, Saudi Arabia
Advisory for Saudi financial institutions working toward SAMA CSF maturity targets.
- SWIFT CSP
SWIFT Customer Security Programme
Delivered against the mandatory and advisory controls inside CIB's banking environment.
- PCI-DSS
Payment Card Industry Data Security Standard
Segmentation, logging and access-control work in card environments. Advisory, not certified attestation.
- ISO 27001
Information security management
Control alignment for enterprise and government programmes.
Advisory and solution alignment. Not certified audit or attestation.
Vendor ecosystem
Technologies I have sold, designed with, deployed or run a PoC on. Knowing how each of them sells is exactly why bank-facing advisory stays vendor-neutral.
- Cisco
- Palo Alto Networks
- Fortinet
- Check Point
- F5
- Forcepoint
- LogRhythm
- Splunk
- IBM QRadar
- CrowdStrike
- Trellix
- Kaspersky
- BeyondTrust
- OneSpan
- RSA Security
- Veridium
- Ivanti
- Tenable
- Rapid7
- Darktrace
- Group-IB
- Akamai
- Imperva
- Kong
- Symantec / Broadcom
- Trend Micro
- Seclore
- Black Duck
- Mandiant
- Recorded Future
- Infoblox
- VMware
Education & languages
- Sep 2001 — Jun 2003
Higher Diploma, Telecommunication Systems
National Telecommunication Institute (NTI), Egypt
Specialisation: network & data communication design. Grade: Very Good (80.4%).
- Sep 1993 — Jun 1999
B.Sc. Electrical Engineering
Ain Shams University, Faculty of Engineering, Egypt
- Arabic
- Native
- English
- Fluent