Handling entire IT Infrastructure/security at Altuwairqi Holding.
Responsible for managing the overall IT security across the group targeting both network, systems and end user nodes.
Managing ASA 5525 in clustered mode for Remote access VPN, Site to Site VPN and its integration with MS NAP server for centralized authentication and authorization.
For maintaining maximum security implementation of 2 Factor authentication for OWA and IPsec VPN clients by using SMSPasscode technology.
For managing the inside network security, implementation of Cisco 6507 with VSS along with FWSM (Firewall switch module) and IDM (Intrusion detection module), in order to make sure critical IT servers can be accessed only by legitimate IT resources.
Establish email security by implementing Cisco Email Gateways (ESA-C370) in pair for maximum protection of email contents by implementing features like SPF, DLP, GTI, and AMP etc.
Implementation of internet security by using Cisco WSA-S170 with features like AVC, DLP and AMP etc.
Implementation of MBSA for scanning and vulnerability assessment for IT servers along with MS Forefront malware protection for maximizing the security.
Managing HP 3 PAR (7400, 7200) along with HP blade (B460, C7000 chassis) as primary hardware platform for mission critical applications like (SAP, Exchange 2010, Lync 2010, SQL 2008 etc.)
Managing and implementation of VMware ESXi 5.5 hypervisor as a base virtualization platform for various applications along with enabling various features like Vmotion, HA, FT, DRS, SVmotion etc.
Managing Active Directory 2012 infrastructure with single forest, single domain, and multiple sites across the group.
Performing the MS RAP (Risk Assessment Program) for AD, Exchange, and SQL in order to make sure these technologies are free from vulnerabilities and having up-to-date security.
Managing MS Exchange 2016 as messaging platform for entire group with geographically dispersed DAG for DR scenario.
Implementation of Cisco ESA C370 cluster in DMZ as email gateway and anti-spamming solution for MS Exchange 2016 with KEMP LM 3000 as hardware load balancer for MAPI over HTTP clients.
Proactive monitoring of MS Exchange 2010/2016 by using SCOM 2012 for generating email/SMS alerts for critical events.
Implementation of MS SFB (Skype for Business) as primary unified communication for the group covering many features like (IM, VC, PSTN calls, External access, push notification, Lync meeting, outlook voice access, and integration with Avaya aura.
For system side monitoring implementation of SCOM 2012 in a clustered environment and its integration with OZEKI SMS gateway for SMS notification for proactive monitoring while for network links monitoring solar winds NPM with various modules like (netflow traffic analyzer, network configuration manger and UDT), also using solar winds ELM as SIEM solution for all network security devices.
Implementation of Blue coat technologies (SG, AV) as caching and acceleration engines along with web protection for entire group while TMG for small sites; also using the CYBEROAM for guest and auditors access.
Implementation of companywide Polycom based VC solution by using HDX7000 encoders along with RMX1500 MCU and its integration with MS Lync 2010.
For physical security implementation of Access control system by using GE Facility commander along with biometrics devices in the form of 4G V-station, 4G V-Flex.
Implementation of Cisco Wireless controller 5508 along with aironet 1260 access points for maintaining the single SSID across the group
Work as internal IT auditor for doing IT security audits with external auditors.
Making RFP, analyzing the vendor proposals for various projects & coordinate with them on all stages of project implementation like (initiation, planning, executing, monitoring, closing) along with implementation of MS Project server for task assignment and approval system.
- Company industry:
- Industrial Production
- Job role:
-
Information Technology