m
moussa11283

Ahmed Moussa

@moussa11283

Network And Cybersecurity Solutions

Egito
Inglês, Árabe
Algumas informações são exibidas no idioma inglês.
Sobre mim
What I Offer 🔶 FortiGate Firewall Policies, NAT, VPN, HA, monitoring, best-practice hardening. 🔶 VPN & Zero Trust (ZTNA) Site-to-site, remote-access VPN, and Zero Trust access policies. 🔶 Routing & Switching Cisco, Dell & Huawei — VLANs, STP, OSPF/BGP, HSRP/VRRP. 🔶 Endpoint & Threat Protection Kaspersky Security Center, Cloud & KATA deployment. Also experienced with VMware ESXi/vCenter and Windows Server (AD, DNS, DHCP).... Saiba mais

Habilidades

m
moussa11283
Ahmed Moussa
offline • 
Tempo médio de resposta: 1 hora

Conheça meus serviços

Instalação de software
I will configure and harden your fortigate firewall
Instalação de software
I will setup site to site and remote access VPN

Experiência profissional

Network Security Engineer

GS Consultancy • Período integral

Jul 2024 - Present2 yrs 1 mo

• Designed and rolled out a greenfield FortiClient EMS and Zero Trust Network Access (ZTNA) deployment, securing a mixed desktop and mobile endpoint environment. • Built VPN and ZTNA access profiles, mapping ZTNA servers over TCP forwarding and HTTPS, and tied proxy policies to dynamic user tags in FortiClient EMS to enforce least-privilege access. • Worked directly with SOC analysts on Managed Detection and Response (MDR) cases, carrying out real-time remediation on FortiGate firewalls and writing up incident reports for the security record. • Deployed multi-vendor network security infrastructure — FortiGate, Palo Alto and Cisco/Dell switching — including FortiLink managed FortiSwitch environments with LACP for redundancy and added bandwidth. • Built Palo Alto and FortiGate policies from the ground up: zone-based security architecture, VLAN segmentation, IPS, web filtering and application control. • Configured SD-WAN for branch sites, with active security enforcement built into the routing. • Delivered full-lifecycle SDN deployment and configuration of a Huawei enterprise campus network — core, distribution, TOR and access switching — managed end-to-end through the Huawei iMaster NCE-Campus SDN controller. • Built and validated Network Access Control (NAC) policies — authentication, authorization, dynamic VLAN assignment and endpoint profiling — integrated with the SDN platform. • Provisioned and validated GPON access services at scale, covering service profile assignment, VLAN mapping and end-to-end connectivity testing. • Engineered high availability across core and distribution layers, validating failover, port-channel bundling and link aggregation to remove single points of failure. • Carried out a major-version platform upgrade of the SDN controller in-place, resolving backup connectivity and package compatibility issues with zero service disruption.