m
moussa11283

Ahmed Moussa

@moussa11283

Network And Cybersecurity Solutions

Ägypten
Englisch, Arabisch
Einige Informationen werden in englischer Sprache angezeigt.
Über mich
What I Offer đŸ”¶ FortiGate Firewall Policies, NAT, VPN, HA, monitoring, best-practice hardening. đŸ”¶ VPN & Zero Trust (ZTNA) Site-to-site, remote-access VPN, and Zero Trust access policies. đŸ”¶ Routing & Switching Cisco, Dell & Huawei — VLANs, STP, OSPF/BGP, HSRP/VRRP. đŸ”¶ Endpoint & Threat Protection Kaspersky Security Center, Cloud & KATA deployment. Also experienced with VMware ESXi/vCenter and Windows Server (AD, DNS, DHCP).... Mehr lesen

Kompetenzen

m
moussa11283
Ahmed Moussa
offline ‱ 
Durchschnittliche Antwortzeit: 1 Stunde

Meine Dienstleistungen

Software-Installation
I will configure and harden your fortigate firewall
Software-Installation
I will setup site to site and remote access VPN

Arbeitserfahrung

Network Security Engineer

GS Consultancy ‱ Vollzeit

Jul 2024 - Present ‱ 2 yrs 1 mo

‱ Designed and rolled out a greenfield FortiClient EMS and Zero Trust Network Access (ZTNA) deployment, securing a mixed desktop and mobile endpoint environment. ‱ Built VPN and ZTNA access profiles, mapping ZTNA servers over TCP forwarding and HTTPS, and tied proxy policies to dynamic user tags in FortiClient EMS to enforce least-privilege access. ‱ Worked directly with SOC analysts on Managed Detection and Response (MDR) cases, carrying out real-time remediation on FortiGate firewalls and writing up incident reports for the security record. ‱ Deployed multi-vendor network security infrastructure — FortiGate, Palo Alto and Cisco/Dell switching — including FortiLink managed FortiSwitch environments with LACP for redundancy and added bandwidth. ‱ Built Palo Alto and FortiGate policies from the ground up: zone-based security architecture, VLAN segmentation, IPS, web filtering and application control. ‱ Configured SD-WAN for branch sites, with active security enforcement built into the routing. ‱ Delivered full-lifecycle SDN deployment and configuration of a Huawei enterprise campus network — core, distribution, TOR and access switching — managed end-to-end through the Huawei iMaster NCE-Campus SDN controller. ‱ Built and validated Network Access Control (NAC) policies — authentication, authorization, dynamic VLAN assignment and endpoint profiling — integrated with the SDN platform. ‱ Provisioned and validated GPON access services at scale, covering service profile assignment, VLAN mapping and end-to-end connectivity testing. ‱ Engineered high availability across core and distribution layers, validating failover, port-channel bundling and link aggregation to remove single points of failure. ‱ Carried out a major-version platform upgrade of the SDN controller in-place, resolving backup connectivity and package compatibility issues with zero service disruption.