Network & Security Architect (SASE, Firewalls, Routing & Switching, Wireless, PAM, IAM, MFA, VPN, WAN-OP, SIEM/SOAR, EDR/XDR)
Network & Security Architect with 10+ years delivering design, deployment, and operationalization of enterprise networks and security stacks (Cisco, Juniper, Aruba, Fortinet, HPE, Huawei/H3C, VMware, Veeam). Proven at delivering secure, scalable, highly available solutions—SASE/Zero Trust, firewall consolidation, multi site wireless, SIEM/SOAR and EDR/XDR integrations—with architecture artifacts, automated playbooks, validation testing, and operational handover for SOC and NOC readiness.
Projects Delivered
1. Enterprise Core Routing and Switching Modernization
Campus and Data Center Redesign for 2,000 Users: Full campus and data center network redesign and deployment — logical and physical topology, IP addressing plan, VLAN/trunking, STP tuning, OSPF/BGP/MPLS routing, HSRP/VRRP high availability, route redistribution, interface optimization, and configuration templates with cutover and rollback plans. Technologies: Cisco, Juniper, Aruba, HPE, Dell, Huawei/H3C, Allied Telesis, Extreme, D Link, industrial grade switches. Outcome: 99.99% availability, reduced broadcast domains, and deterministic QoS for voice and video.
2. Multi Site Wireless Network Rollout
Multi Site Wireless Network Rollout: End to end wireless deployment across 25 sites — RF/site surveys, capacity and channel planning, AP placement, controller and standalone configurations, SSID and 802.1X/RADIUS security design, QoS and roaming optimization, NAC integration and monitoring for operational handover. Technologies: Cisco, Aruba. Outcome: Consistent coverage, voice handoff latency <50 ms, documented runbooks and operational readiness.
3. Firewall Consolidation and Perimeter Hardening
Consolidation and standardization of firewall estate: architecture, policy matrix, IPsec/SSL VPNs, IPS/IDS tuning, SSL inspection, NAT, HA/clustering, centralized logging and forensics. Technologies: Fortinet, Cisco ASA/FTD. Outcome: reduced policy sprawl and faster incident investigations.
4. SASE and Zero Trust Implementation
Phased SASE rollout and Zero Trust controls: SD WAN, SWG, CASB, ZTNA, identity aware policies, micro segmentation, service insertion, and telemetry for enforcement. Outcome: secure remote access, reduced lateral movement, improved branch performance.
5. SIEM, SOAR and EDR/XDR Deployments
SOC enablement with centralized telemetry and automated response: log ingestion and normalization, detection engineering, threat intel integration, SOAR playbooks, endpoint telemetry, automated containment, and forensic capture. Outcome: reduced MTTD, automated containment, improved forensic readiness.
6. Virtualization, Backup and AD Resilience
VMware ESXi cluster design, Veeam backup/replication, Active Directory hardening and HA, DNS/DHCP optimization, and SQL Server HA guidance. Outcome: met RTO/RPO targets and simplified failover procedures.
7. NAC and Identity Integration
802.1X/RADIUS/TACACS+ deployment, posture checks, RSA MFA integration, and onboarding workflows to enforce device compliance and secure access.
Core Technical Expertise
• Routing & Switching: Cisco, Juniper, Aruba, HPE, Dell, Huawei/H3C, Allied Telesis, Extreme, D Link, industrial switches; VLANs, STP, OSPF, BGP, MPLS, QoS, HSRP/VRRP, route redistribution, packet level troubleshooting.
• Wireless: Multiple end to end Cisco and Aruba deployments; RF surveys, capacity planning, WPA2/WPA3, 802.1X/RADIUS, QoS, roaming, NAC integration.
• Security Platforms: Fortinet, Cisco ASA/FTD; policy lifecycle, IPsec/SSL VPNs, IPS/IDS, UTM, SSL/TLS inspection, NAT, HA/clustering, centralized management.
• SASE and Zero Trust: SD WAN, SWG, CASB, ZTNA, microsegmentation, identity aware policies, east west controls.
• SIEM & SOAR: Log ingestion, correlation, detection rules, threat intel, automated playbooks, case management, tuning for low false positives.
• EDR / XDR: Endpoint telemetry, behavioral/ML detection, threat hunting, rapid containment, automated remediation, SIEM/SOAR integration.
• Virtualization & Backup: VMware ESXi, Veeam backup/DR orchestration.
• Identity & NAC: Active Directory, DNS/DHCP, GPOs, 802.1X, RADIUS, TACACS+.
Technical Certifications: CCNP R&S, CCNA R&S, CCNA Security; JNCIP SEC, JNCIA SEC, JNCIS SEC, JNCIA JUNOS, JNCDA; Fortinet NSE4–NSE7; CEH; RSA MFA SolarWinds Certified, MCSA, MCITP.
Compliance: ISO 27001 certified ISMS practitioner experienced in risk assessments, control frameworks, audits, and compliance.
Network Monitoring
ManageEngine ServiceDesk Plus
Server
Desktop Support
Microsoft Active Directory
System Monitoring
Fortinet
Helpdesk
Cisco IOS
Network Administration
Aditya S.
Dubai, United Arab Emirates
$30/hr
5.0
4 jobs
Microsoft Security Architect | SOC & Cloud Security Specialist (SC-100, SC-200)
I help organisations design, implement, and operate secure Microsoft environments across Microsoft 365, Azure, and hybrid infrastructures, from architecture through 24×7 SOC operations.
I currently lead security engineering initiatives as Assistant Manager at KPMG International, where I've driven SIEM migration and endpoint modernisation across 70,000+ endpoints and 118+ countries, alongside ongoing work as a Senior SOC Analyst / Security Engineer supporting a global enterprise GSOC.
If your goal is to move from reactive IT to structured, security-first architecture, or you need hands-on SOC/detection engineering support. I can help.
What I Deliver:
🔐 Microsoft Security Architecture & Hardening
Security design across M365, Azure, and hybrid environments aligned to Zero Trust principles.
🛡 Defender XDR & Sentinel (SIEM/SOAR)
Deployment, optimisation, detection engineering, KQL analytics rules, automation playbooks, and threat hunting, including large-scale SIEM migrations (RSA NetWitness → Sentinel, or any other Cloud Provider).
📱 Endpoint & Device Security (Intune + Defender for Endpoint)
Secure device onboarding, compliance policies, ASR tuning, EDR optimisation, proven at 70,000+ endpoint scale.
🔑 Identity & Access Management (Entra ID / Azure AD / AD)
Conditional Access design, MFA strategy, identity protection, privileged access governance, Active Directory hardening.
📋 Data Governance & Compliance (Microsoft Purview)
Sensitivity labels, DLP across Exchange/SharePoint/Teams, information protection, and regulatory alignment (GDPR, ISO 27001, HIPAA, SOC 2).
☁ Cloud Security & Compliance
Defender for Cloud, Defender for M365, Cloud Apps, secure configuration baselines, multi-cloud exposure (Azure, AWS, GCP).
🔄 M365 & Azure Migrations (Secure by Design)
Tenant migrations, GoDaddy defederation, domain transitions, license restructuring, secure cutovers, zero data loss planning.
📊 Security Assessments & Gap Analysis
Technical posture reviews, misconfiguration discovery, licensing optimisation, roadmap creation.
🖥 Managed Detection & Response Enablement
Helping organisations build or optimise 24×7 monitoring capabilities, including SIEM integration and alert triage workflows.
Why Clients Work With Me
✔ I combine architecture-level thinking with hands-on engineering execution
✔ Track record of measurable impact, 76% reduction in manual security workflows, 50%+ log ingestion cost savings
✔ I understand both enterprise SOC environments and SMB constraints
✔ I prioritise clarity, documentation, and structured delivery
✔ Currently active in live enterprise SOC operations, not just theory
Cyber incidents are expensive. Poorly configured security is even more expensive.
The goal is not to buy more tools. It's to configure them correctly.
Microsoft Azure
Microsoft Windows
Office 365
Python
Microsoft Word
Microsoft Excel
Data Entry
Cybersecurity Management
Cybersecurity Monitoring
Technical Support
Power Query
Scripting
Palo Alto Firewalls
ServiceNow
Cybersecurity Tool
Yasir A.
Dubai, United Arab Emirates
$90/hr
5.0
22 jobs
I am Cisco Dual CCIE (Routing & Switching, Service Provider, DC(in process) Network professional with demonstrable experience in the design and delivery of Enterprise, DC, Service provider, and AI/ML Training DataCenter Networks.
I have also worked on AI Architect roles for customers are who are looking to determine hardware requirements for AI training systems, Architect enhancements required for efficient training of AI models, Scale-Out and Scale-Up Architectures, based on Cisco and Arista AI enhanced Spine & Leaf SW.
I have considerable experience in SD-WAN deployments including Cisco iWAN, Cisco Viptela, Velocloud.
I have deployed projects based on Cisco ACI, DCNM, NDFC, and Manual VXLAN Fabric from Cisco, Arista.
I am an advocate of Automation in Network deployment and Operations and have significant commercial Python and Ansible experience.
I am also Network Security Expert, have deployed multiple projects in DC, Cloud, or private Colo with Palo Alto Firewalls, Fortinet, Cisco Firepower, Juniper Firewall with BGP, S2S VPNs, IPS, NAT, Policies and remote-access deployments.
Certifications:
Cisco:
CCIE Routing & Switching (26003)
CCIE Service Provider
CCIE DataCenter (Written)
CCDE Written, CCNP, IOS XR Specialist.
Splunk:
Cert-57763 Splunk Certified Knowledge Manager, Admin, Power User
Cloud:
AWS Certified Solution Associate (Exam Pending)
Skills (Expert Level):
Software Defined Data Center:
Cisco ACI :
Capacity Planning, Design, Deployment
Migration of existing DC to ACI (Brownfield, Greenfield)
Migrating WAN Services to ACI, L3out
Automation the Migration with the help of Ansible
Implementing Multi-Pod or Multi-site ACI
Cisco ACI and Vmware VMM integration
Cisco VXLAN, Single Fabric, Multi Pod Fabric and Multisite Fabric Design, CLI, Nexus Dashboard, NDFC
Arista EVPN VxLAN
Cumulus Linux and White Box Switches
Vmware NSX-T
IP/MPLS/WAN:
Cisco SD-WAN, Viptela/Velocloud Deployments and Troubleshooting
IOS, IOS XR, NX-OS, JunOS, SROS.
Cisco Nexus Platform, CRS, ASR9K, Cisco Adaptive Security Appliance (ASA) 55xx.
OSPF, BGP, Fabrickpath, MPLS, Multicast, EVPN.
Cisco SD-Access SDA DNA Center
Splunk:
Analyzing the customer requirements
Design and implementation of Splunk Architecture
Creating Reports and Dashboard according to the requirements
Troubleshooting the Splunk operations and scalability issues
Security:
Configuration and Troubleshooting Palo Alto, CheckPoint, F5 Appliances, Fortinet, Cisco Firepower Hardware Appliances or Cloud in Azure, AWS.
Network Automation and Programmability with CI/CD
Python
JSON, XML, YAML
Ansible
Jenkins
Git
VPN
Network Security
Cisco WLC
Palo Alto Firewalls
AWS Systems Manager
Cisco ACI
Data Center Operations
Data Center Design
Cisco Certified Internetwork Expert
Cisco Router
Cisco Certified Design Expert
Data Center Migration
Network Design
Virtual LAN
Network Equipment
Khaled S.
Dubai, United Arab Emirates
$75/hr
5.0
11 jobs
I have Experience in Penetration Testing(Network, Web Application, Desktop, Mobile, IVR and webservice), performed lots of Security Implementations related to Security Solutions such as SIEM, Two Factor Authentication, Firewalls,...etc. in Egypt and Large banks in Qatar. . I have experience in PCI Audits , did lot's of gap assessments and pre-audits on many banks and payment gateway.
Also I wrote multiple articles in big security magazines like Hakin9 in Europe and Security Kaizen in Middle East, I'm currently having two 0day vulnerability and listed in multiple hall of fames including Microsoft.
I have multiple certifications like OSCP, OSEP, OSWE And OSCE
Job Experience:
• Running PCI-DSS Gap Assessments, Pre-Audits, Final Audits in big payment gateways and large ISP's in Egypt
• Performing Internal / External Network Penetration testing for large bank, ISP & other clients.
• Performing Internal / External Application Penetration Testing “Web / Desktop” for large customers in Egypt and Qatar.
• Performing advanced Penetration testing including Mobile,Web service, IOT and IVR PT in Egypt.
• Supervising big Vulnerability Assessment projects in Egypt most required by PCI-DSS clients.
• Performing large SIEM Solution implementations for ISPs, Banks, government sector & others in Egypt, Qatar
• Implementing biggest Two Factor Authentication Solution implementation in the middle east.
• Vulnerability Management Solutions for large customers in Egypt
•End Point Protection implementation in large banks in Egypt
• McAfee Next Generation FW deployments for large clients in Qatar.
• McAfee Network Security Manager IPS deployments for large clients in Qatar.
•Deploying Anti Fraud solutions at one of the biggest banks in Middle east.
•Deploying Mobile Device Management solutions (Mobile Iron)at one of the biggest banks in Middle east.
•One of the consultants responsible for securing the 4G Network(IMS Core,HSS,...etc.) at one of the biggest Mobile operators in Egypt.
•Leading a team of 3 Engineers to perform mentioned activities previously.
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a OSPF Specialist near Dubai, on Upwork?
You can hire a OSPF Specialist near Dubai, on Upwork in four simple steps:
Create a job post tailored to your OSPF Specialist project scope. We’ll walk you through the process step by step.
Browse top OSPF Specialist talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top OSPF Specialist profiles and interview.
Hire the right OSPF Specialist for your project from Upwork, the world’s largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a OSPF Specialist?
Rates charged by OSPF Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a OSPF Specialist near Dubai, on Upwork?
As the world’s work marketplace, we connect highly-skilled freelance OSPF Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream OSPF Specialist team you need to succeed.
Can I hire a OSPF Specialist near Dubai, within 24 hours on Upwork?
Depending on availability and the quality of your job post, it’s entirely possible to sign up for Upwork and receive OSPF Specialist proposals within 24 hours of posting a job description.