name: Fady Mounir Zaghloul
current_role: IT & Security Manager @ AsusCard FinTech
location: Cairo, Egypt
experience: 12+ years across infrastructure, cloud, operations and security
engineering_focus:
- platform and infrastructure engineering
- cloud architecture and migration
- DevSecOps and software supply-chain security
- observability, SLOs and operational reliability
- identity, endpoint and infrastructure security
open_to:
- Infrastructure / Platform Lead
- Cloud / Platform Engineer
- DevOps / SRE
- Security Architecture / Operations- Rollback is a feature. A deployment path is incomplete until the known-good recovery path is documented and tested.
- Identity before static credentials. Prefer short-lived OIDC/workload identity and least privilege over stored cloud keys.
- Security belongs in delivery. Scan source/configuration, generate provenance/SBOM, sign artifacts, then enforce policy at admission/runtime.
- Operate from signals. SLOs, error budgets, runbooks and recovery tests matter more than decorative dashboards.
- Public evidence ≠ public infrastructure. Production write-ups are sanitized; credentials, live endpoints, private network plans and customer data stay private.
A production-style public reference implementation that now covers:
Terraform · AWS EKS · GitHub OIDC · Argo CD · Cosign · Kyverno · Falco · Trivy Operator · Prometheus/Grafana · SLOs · OpenCost · VPA recommendations · backup/game-day patterns · DR architecture
- Seven staged engineering releases from baseline through live-readiness and local runtime evidence
- protected
main, required security checks and signed commits - project-owned container supply chain with provenance, SBOM, scanning and keyless signing
- policy/runtime security, reliability and cost controls separated into reviewable layers
- real Kubernetes 1.36 local runtime evidence: Argo CD, Kyverno admission, Prometheus/SLOs, Trivy, Falco, VPA, OpenCost and a controlled recovery game day
- live-cloud activation deliberately kept explicit rather than pretending unprovisioned infrastructure is running
→ Documentation · Local Runtime Evidence · Repository · v0.7.1
Long-form production details no longer live in this profile. They are separated into sanitized case studies so the engineering decisions are public without publishing a real environment's attack surface.
| Pattern | Focus |
|---|---|
| Multi-tenant SaaS platform | isolation, releases, backups, observability, capacity |
| Cross-site PostgreSQL replication | private connectivity, replication health, rollback |
| Cloud migration with rollback | replication-first cutover, DNS, failback |
| Observability baseline | signals, alerts, runbooks |
| Identity hardening | MFA, mail security, DLP, rollout safety |
| Local-first internal AI | data boundaries, RBAC, RAG, plugin/network risk |
Cloud, platform, automation and security
AWS · OCI · Linux · Terraform · Kubernetes / EKS / K3s · Argo CD · Nginx · Proxmox · VMware
GitHub Actions · Jenkins · Docker / BuildKit · Ansible · Bash · Python · PM2
Microsoft Defender · FortiGate · CodeQL · Gitleaks · Trivy · Cosign · Kyverno · Falco · Tailscale
Prometheus · Grafana · SLO / error-budget alerts · OpenCost · game-day / recovery testing
PostgreSQL · MySQL / MariaDB · SQL Server · Redis · Node.js · NestJS · FastAPI · .NET
Selected certifications and training
| Vendor | Selected credentials |
|---|---|
| Microsoft | SC-100 Cybersecurity Architect Expert · SC-200 Security Operations Analyst |
| AWS | SAA-C03 Solutions Architect Associate · CLF-C02 Cloud Practitioner |
| Cisco | CCNA · CyberOps Associate |
| IBM | Cloud Professional Architect · Cloud SRE · SkillsBuild Cybersecurity |
| IT Support Professional · Security in Google Cloud | |
| NTI / MCIT | DEPI Cisco Cybersecurity Engineer · Post Graduate Diploma AI & Modern Technologies |
30+ verifiable credentials → Credly