Mamoun AlQaissi, Security Services & Forensics Analysis

Mamoun AlQaissi

Security Services & Forensics Analysis

Orange - Jordan

Location
Jordan - Amman
Education
Bachelor's degree, Mathematics
Experience
33 years, 8 Months

Share My Profile

Block User


Work Experience

Total years of experience :33 years, 8 Months

Security Services & Forensics Analysis at Orange - Jordan
  • Jordan - Amman
  • My current job since June 2017

Work in Network & Information Security Dept/Security operations center to conduct network and IT systems Vulnerability Assessment and Penetration Testing to identify vulnerabilities and to propose relevant remediation recommendations. Provide SOC services for enterprises and monitor their perimeters. Administrate, configure and implement SIEM solution and work as last security layer response, build use-case and conduct security analysis over whole Orange infrastructure.

Responsibilities:
• Conduct security Assessments for networks, systems and applications.
• Implement, configure and administrate SIEM solution (IBM QRadar, EiQ SecureVue)
• Develop and define detailed processes and procedures to manage the response to cyber security events of SOC (Security Operations Center)
• Provide SOC services for external customers, study, evaluate and implement SOC services.
• Build SOC Use cases and processes to adapt customer’s environment and protection perimeter.
• Design the SOC services architecture as needed inside customer premises
• In Depth knowledge in security Technology solutions, low level design & delivery
• In-depth knowledge of implementations from multiple vendors and different types.
• Support the Identification, development and implementation of new incident detection (Use cases)
• Perform technical and forensic investigations into cyber security events, identification of cyber-threats and respond accordingly
• Perform and conduct compliance assessment like CIS, PCI DSS, ISO 27001, DISA STING and provide full reports and remediation recommendations
• Perform forensic services for the collection, processing, preservation, analysis, and presentation of evidence in support of vulnerability mitigation and information security incident investigations
• Create monitors and dashboards, as well as reports according to need
• Be part of incident response team as well as APT detection and analysis
• Develop and implement risk responses to ensure that risk factors and events are addressed in a cost-effective manner, design methodology to integrate IOCs for effective Security Analysis
• Directly contributing to the continued technical enhancement of the security platforms
• Part of DDoS response team to mitigate all types of DDoS attacks
• Being L2/L3 incident response for SIEM and security cases incidents
• Conduct vulnerability assessment and Penetration testing to identify security threats and remediation actions, Perform cyber threat hunting for the detection of advanced threats
• Experience with Linux/Unix and Windows servers

Ethical Hacking Expert - Orange NIS at Orange - Jordan
  • Jordan - Amman
  • January 2016 to June 2017

Work in Network & Information Security Dept/Security operations center to conduct network and IT systems Vulnerability Assessment and Penetration Testing to identify vulnerabilities and to propose relevant remediation recommendations. Develop applications relevant to security projects and missions

Responsibilities:
• Conduct Security Assessments for networks, systems and applications.
• Conduct vulnerability assessment and Penetration testing to identify security threats and remediation actions, Perform cyber threat hunting for the detection of advanced threats
• Perform technical and forensic investigations into cyber security events, identification of cyber-threats and respond accordingly
• Perform forensic services for the collection, processing, preservation, analysis, and presentation of evidence in support of vulnerability mitigation and information security incident investigations
• Directly contribute to the continued technical enhancement of the security platforms
• Part of DDoS response team to mitigate all types of DDoS attacks
• Testing web applications for common web application security vulnerabilities as defined by OWASP including input validation vulnerabilities, broken access controls, session management vulnerabilities, cross-site scripting issues, SQL injection and web server configuration issues.
• Develop and implement risk responses to ensure that risk factors and events are addressed in a cost-effective manner
• In Depth knowledge in security Technology solutions, low level design & delivery
• In-depth knowledge of implementations from multiple vendors and different types.
• Experience with Linux/Unix and Windows servers
• Experience in networking infrastructure

Networks Security Supervisor / Orange Security Operations Center (SOC) at orange
  • Jordan - Amman
  • July 2011 to January 2016

Security Operation Center (SOC) is an entity within Jordan Telecom Group that holds those most professionals in IT Security field with high level of certificates, it provides security managed services for corporate internally and externally.

Responsibilities:
• Perform technical and forensic investigations into cyber security events, identification of cyber-threats and respond accordingly
• Conduct vulnerability assessment and Penetration testing to identify security threats and remediation actions
• Directly contribute to the continued technical enhancement of the security platforms
• Part of DDoS response team to mitigate all types of DDoS attacks
• Deploy, maintain and administer Security Platform inside SOC Data Center.
• Install, maintain all SOC Data Center servers.
• Maintain and administer Blades systems and related Enclosures.
• Build Servers and clustered solutions as needed (SQL Clusters, FTP Cluster, SIEM clusters).
• Deploy, maintain and administer virtualized platform (VMWare, Hyper-V)
• Deploy and administer Antivirus platforms, malware detection and IPS use case.
• Administer and deploy SAN storage and NAS
• Develop methodologies and infrastructure to host in-house solutions.
• Install, maintain all SOC Security products: SIEM (Security Information and Incident Management) system, VA (Vulnerability Assessment), DDOS solution.
• RD (research and Development) on all Security products, propose most convenient needed ones.
• Participate and provide all needed security assessment as well as Pen testing and VA.
• Security and risk assessment in physical security sites.
• Propose, supervise and work in CCTV projects.
• Develop, participate and install MVS (Managed video surveillance) projects.
• Maintain and administer Environmental sensors inside SOC DC.
• Provide Security advice to all internal external entities on related domain

Networks Security Advisor/ in Orange Security Operations Center (SOC) at orange
  • Jordan - Amman
  • February 2007 to July 2011

Security Operation Center (SOC) is an entity within Jordan Telecom Group that holds those most professionals in IT Security field with high level of certificates, it provides security managed services for corporate internally and externally.

Responsibilities:
• Provide Security and risk analysis for security projects, identify security wholes and propose remediation.
• Conduct Vulnerability assessment for security projects
• Participate building policies and procedures to address customers SOC needs.
• Maintain and Administer VMS (Vulnerability Management System).
• Liaison and reflect Security teams technical needs inside SOC, deep restricted technical information are mapped into easy legitimate info to other teams.
• Manage all projects logistic support and technical transactions within SOC teams.
• Assist on security projects budget allocation, invoices processing, PRs, POs and follow-up…etc.

Commissioned Officer at Jordan Armed Forces
  • Jordan - Amman
  • June 1990 to November 2006

Commissioned Officer/ Lt. Col.

Confidential

Education

Bachelor's degree, Mathematics
  • at Mu'tah University
  • June 1990

Regular study for four years, stood 3rd with V.Good GPA, all materials were in English, Mu'tah University is a military university where student study his degree side by side with military training, eventually graduates as Lieutenant in Army, as well as a Diploma in military sciences.

High school or equivalent, Scientific branch
  • at Ahmed Touqan School
  • July 1986

Specialties & Skills

Penetration Testing
Vulnerability Assessment
Security
Visul Basic 6
HTML and fronpage designing
Exams Building and Analysis
Flash Developer
MS Office
Servers Clustering
Linux flavor administrator
Virtualized Environment
Storage management (SAN & NAS)
Network Security
Vulnerability Assessment
AD DC administrator
Data center management
Penetration Testing
Servers Infrastructure
CIS, DISA Compliance and Audit
Configuration Review
QRadar SIEM
DDOS Solutions
Risk Assessment

Languages

Arabic
Expert
English
Expert

Memberships

Ec-Council
  • Certified Member and LPT
  • May 2010

Training and Certifications

CEH (Certified Ethical Hacker) - Ec-Council (Certificate)
Date Attended:
May 2010
Valid Until:
December 2019
Pravail APS User/Admin Training (Training)
Training Institute:
Arbor
Date Attended:
May 2015
Duration:
30 hours
Peakflow DDoS Detection & Mitigation Administrator Course (Training)
Training Institute:
Arbor
Date Attended:
May 2015
Duration:
56 hours
Protecting Against Malware Threats with Cisco AMP for Endpoints (Certificate)
Date Attended:
July 2017
ECSA (Certified Security Analysit)- Ec-Council (Certificate)
Date Attended:
December 2010
Valid Until:
December 2019
LPT (Licensed Pentration Tester)- Ec-Council (Certificate)
Date Attended:
May 2011
Valid Until:
December 2019
CHFI (Certified Computer Hacking Forensics Investigator) - Ec-Council (Certificate)
Date Attended:
September 2013
Valid Until:
December 2019
Securing Networks Cisco Firepower Next-Generation IPS (NGIPS) (Certificate)
Date Attended:
July 2017
CISSP (Certified Information Security Systems Professional) (Training)
Training Institute:
TeleProbe - Cisco Partner
Date Attended:
July 2011
Duration:
80 hours
Test Of English for International Communication (TOEIC) - AMIDEAST (Certificate)
Date Attended:
May 2006
Valid Until:
January 9999
Cisco Certified Network Associate- CCNA (Training)
Training Institute:
TeleProbe
Date Attended:
December 2008
Duration:
60 hours
Intel learning to the Future-Certified Expert Instructor - UNESCO (Certificate)
Date Attended:
August 2004
Valid Until:
January 9999
ICDL (International Computer Driving License) - UNESCO (Certificate)
Date Attended:
April 2003
Valid Until:
January 9999
Total Quality Management (TQM) - Jordan University (Certificate)
Date Attended:
March 2006
Valid Until:
January 9999

Hobbies

  • Chess
  • Reading