Skip to content

About & contact

I lead cyber defense operations across enterprise and MSSP environments, combining team leadership, security consulting, and hands-on engineering.

Contact

GitHub LinkedIn

ThreatOps approach

My approach is ThreatOps: managing the full picture of threat operations from the defense side. I connect threat intelligence, security telemetry, threat hunting, detection engineering, compromise assessments, and incident response so that each activity informs the others. Investigation findings drive new detections, intelligence shapes hunting priorities, and defensive assessments guide improvements in visibility and response.

Leadership

I lead and mentor SOC analysts and engineers, develop operational processes, assess SOC maturity, and translate technical findings into practical roadmaps for clients and management.

Engineering & automation

I also design and integrate the platforms and workflows that support these operations. Using REST APIs, Python, n8n, and security platforms including SIEM, SOAR, EDR, and MISP, I build integrations and automation that reduce manual work and help teams act on relevant information.

Professional focus

My MAD20 certifications cover detection engineering, threat hunting, cyber threat intelligence, adversary emulation, purple teaming and SOC assessment.

I’m interested in Cyber Defense Manager and Cyber Defense Architect roles in enterprise and MSSP environments.

Education

Bachelor’s degree in Computer Science
Modern Academy Maadi · 2015–2019.

Recognition

  • SOC GUARDIAN · Fortinet · September 2025 · Flag the Hack 2.0.
  • Contributions to PCI DSS v4 and ISO 27001 in 2024 · Fawry · January 2025.

Skills

SOC leadership

Leading Resident SOC and Managed SOC teams, developing analysts and organizing day-to-day defensive operations.

Team leadershipSOC maturity assessmentIncident managementPlaybooks & procedures

Defense architecture

Designing security operations platforms and assessing how controls, telemetry and integrations support the defense team.

SIEM & SOAR architectureSecurity integrationsEDR assessment

DFIR & compromise assessment

Investigating incidents and assessing compromise through forensic evidence and security telemetry.

Incident investigationWindows & memory forensicsCompromise assessment

Threat hunting

Using adversary behavior and threat intelligence to guide hunts and investigate suspicious activity.

Hypothesis-driven huntingMITRE ATT&CKTelemetry analysis

Detection engineering

Developing detections around adversary techniques and reviewing coverage across security platforms.

ATT&CK-informed detectionLog parsingDetection coverage

ThreatOps & automation

Connecting intelligence, hunting, detection and response through shared workflows and security automation.

Cyber threat intelligenceWorkflow automationAPI integrations

Platforms & tools

Defense platforms

IBM QRadar, Elastic Stack, MISP, TheHive & Cortex.

Automation & integration

Python, REST APIs, n8n and syslog.