Amr Hegazy

IT Infrastructure & DevOps Tech Lead

Architecting scalable, secure, and automated cloud infrastructure across AWS, Azure & hybrid environments

15+Years Experience
100+Projects Delivered
7Companies Served
3Cloud Platforms
AWS Azure GCP Kubernetes Terraform Cloudflare
Amr Hegazy

Amr Hegazy

IT Infrastructure & DevOps Tech Lead

About Me

With over 15 years of progressive experience in IT infrastructure, network engineering, and DevOps leadership, I have successfully driven enterprise-scale projects from conception to delivery across multiple industries and regions.

I excel at translating complex technical challenges into streamlined, scalable solutions — always with a focus on reliability, security, and innovation. My expertise spans multi-cloud architecture (AWS, Azure, GCP), Infrastructure as Code (Terraform, CloudFormation), container orchestration (Kubernetes, Docker), CI/CD pipelines, and Microsoft 365 security administration.

Guided by ITIL principles, I bring hands-on experience in designing Cloudflare security architectures (WAF, TLS, DNS, origin rules) entirely through Terraform modules, managing Kubernetes workloads via Helm, implementing observability stacks with Datadog, Grafana, and SigNoz, and securing enterprise environments with Microsoft Defender XDR, Intune, and Entra ID conditional access policies.

LocationRiyadh, Saudi Arabia
NationalityEgyptian
LanguagesArabic (Native), English (Professional)
StatusOpen to Opportunities

Work Experience

Technical Services Leader

Saudi Edarah Group
Jan 2025 – Present

Leading a cross-functional technical team, overseeing cloud infrastructure strategy, service delivery, and DevOps transformation across the group's portfolio. Managing project workflows through Jira (Epics, Sprints, Kanban boards) and Confluence for documentation and knowledge sharing. Defining RTO/RPO targets for disaster recovery planning, measuring ROI on cloud migration initiatives, and establishing SLA frameworks for internal and external service commitments. Driving adoption of IaC practices using Terraform for Cloudflare security modules (WAF, DNS, TLS, origin rules, bulk redirects), managing Kubernetes workloads with Helm-based deployments on AWS (EKS, EC2, RDS, S3, CloudFront, Route53), and implementing Microsoft 365 security policies including Intune device management, Defender for Endpoint, and Entra ID conditional access. Mentoring engineers, conducting capacity planning reviews, and aligning infrastructure roadmaps with business objectives.

AWSTerraformCloudflareKubernetesHelmM365IntuneDatadogJiraRTO/RPO

Senior IT Infrastructure Engineer

Sana Software (Egypt)
Nov 2020 – Dec 2024

As a Senior Infrastructure Engineer, I bring extensive expertise in networking, VoIP, cloud solutions, security, firewall management, Linux servers, virtualization, and IT automation. I specialize in designing, implementing, and maintaining secure, high-performance, and scalable IT infrastructures that support business growth and operational efficiency. My experience extends to cloud platforms (Azure, AWS), where I design infrastructure solutions, implement Infrastructure as Code (IaC), and ensure application scalability and reliability. My skill set includes virtualization technologies, Docker, Kubernetes, and cloud-native applications, enabling seamless deployment and orchestration of modern workloads. I have a strong background in firewall and network security management, ensuring IT environments remain resilient against cyber threats. Additionally, I leverage automation tools and scripting to optimize IT operations, reduce manual overhead, and enhance system reliability. With a deep understanding of cybersecurity, cloud computing, and modern infrastructure solutions, I drive strategic IT initiatives that align with business objectives, focusing on innovation, performance optimization, and proactive security.

AWS EKSDockerJenkinsGitLab CIGrafanaCrowdStrikeAzure ADSonarQube

AVL/GPS Service Director

Al‑Bassami Group (KSA)
Jun 2020 – Aug 2020

Directed GPS/AVL service operations and coordinated between technical teams to enhance fleet management solutions across the organisation's transportation network.

IoTFleet ManagementGPS/AVL

Senior System Engineer

MaxMedia (STC Partner) — KSA
2017 – Jun 2020

Delivered enterprise infrastructure solutions for telecom clients. Managed Azure and on-premises hybrid environments (Azure AD Connect, Exchange Online migration), virtualised infrastructure (VMware vSphere, Hyper-V), implemented backup strategies with Veeam, and maintained firewall/VPN configurations across Fortinet, Sophos, and Mikrotik platforms. Administered Microsoft 365 tenants including Exchange Online, SharePoint, and Teams.

AzureVMwareM365FortinetVeeamExchange Online

Senior Network/VoIP Engineer

O2run Systems (KSA)
2014 – 2017

Engineered and maintained enterprise VoIP infrastructure including Asterisk/FreeSWITCH PBX systems, SIP trunking, and contact centre platforms (Xcally, 3CX). Designed network security architectures and QoS policies for voice traffic optimisation.

AsteriskFreeSWITCHSIPKamailioCisco3CX

Technical Support Engineer

Ministry of Labour (Libya)
Jan 2012 – 2014

Provided technical support and resolved network issues within the ministry's IT infrastructure, managing Active Directory, DNS, DHCP, Group Policy, and endpoint security across 500+ users.

Active DirectoryWindows ServerGPONetworking

System Administrator

Delta System Integrator
Jun 2009 – 2012

Administered systems and networks for multiple clients, managing server infrastructure, performing hardware maintenance, and ensuring uptime across Windows and Linux environments.

LinuxWindowsNetworkingHardware

Technical Skills

DevOps & Automation

  • Infrastructure as Code: Terraform (modules, state, workspaces, Cloudflare/AWS/Azure providers), CloudFormation, Ansible
  • Container orchestration: Kubernetes (EKS, AKS, self-managed), Docker, Docker Swarm, Rancher
  • Helm chart management for production workloads (Datadog, Grafana, Jenkins, SigNoz, CrowdStrike)
  • CI/CD: Jenkins (Declarative Pipelines, Jenkinsfile), GitLab CI, GitHub Actions, ArgoCD
  • GitOps workflows, Git branching strategies, code review automation
  • Scripting & automation: Bash, PowerShell, Python

Observability & Monitoring

  • Datadog: Agent, APM, Log Management, Synthetics, Infrastructure Monitoring
  • Grafana + Prometheus: Dashboards, alerting, PromQL, service discovery
  • SigNoz: Open-source APM and distributed tracing
  • ELK Stack: Elasticsearch, Logstash, Kibana for log aggregation
  • ITOM: ManageEngine (OpManager, Site24x7), SolarWinds Orion, Zabbix
  • CloudWatch, Azure Monitor, Log Analytics

System & Infrastructure

  • Linux/Unix (RHEL, CentOS, Debian, Ubuntu) — 10+ years
  • Windows Server (AD, GPO, DFS, WSUS, IIS, ADFS) — 10+ years
  • Virtualisation: Proxmox (KVM/QEMU), VMware vSphere, Hyper-V, Citrix Xen
  • Storage: SAN/NAS, iSCSI, NFS, Ceph, ZFS, LVM, RAID
  • Backup & DR: Veeam Backup & Replication, UrBackup, Duplicati
  • HA & Load Balancing: HAProxy, Nginx, Envoy, Keepalived, AWS ALB/NLB
  • Database: MySQL, PostgreSQL (replication, backup, tuning)

Security & Compliance

  • CrowdStrike: Falcon Sensor, KAC (Kubernetes Admission Control), LogScale SIEM
  • Microsoft Defender XDR: Defender for Endpoint, Identity, Cloud Apps, Office 365
  • Cloudflare WAF: OWASP Core Ruleset, managed rules, rate limiting, bot management, Page Shield
  • ZTNA & SASE: Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), Cloudflare Zero Trust Access, Tailscale
  • PKI/X.509 certificate lifecycle, SSL/TLS termination
  • Vulnerability scanning, compliance auditing, SonarQube code analysis
  • Web application security: Imperva WAF, Cloudflare DDoS protection

Networking & ZTNA

  • Full-stack: L2/L3 switching, routing (OSPF, BGP), VLANs, QoS, SD-WAN
  • Firewalls: Fortinet, Sophos, Palo Alto, Mikrotik, pfSense, OPNsense
  • VPN: IPsec, WireGuard, OpenVPN, SSL VPN, L2TP, SSTP, Site-to-Site
  • Cloud networking: AWS VPC Peering, Transit Gateway (TGW), Azure VNet Peering, Hub-Spoke topologies
  • Reverse proxy: Traefik, Nginx Proxy Manager, HAProxy, Caddy, Envoy
  • ZTNA: Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), Cloudflare Access, Tailscale, Teleport, NetBird, Twingate
  • Network services: DNS, DHCP, NTP, SNMP, NetFlow, Syslog
  • Analysis: Wireshark, tcpdump, Nmap, sngrep
  • Wireless: 802.11ac/ax, controller-based architectures

VoIP & Unified Communications

  • PBX: Asterisk, FreeSWITCH, FreePBX/Issabel, Yeastar, Grandstream
  • SIP infra: Kamailio, OpenSIPS, SBC (Ribbon, Audiocodes)
  • Protocols: SIP, SDP, H.323, IAX2, RTP, SRTP, ZRTP, T.38
  • Contact centres: Xcally (omnichannel), 3CX (IVR, dialer, queues)
  • UCaaS: Microsoft Teams, Zoom — PSTN/SIP integration via SBCs
  • Enterprise: Cisco (CME, CUCM, CUBE), Avaya (IP Office, Aura)
  • Voice security: SIP TLS, SRTP, OpenSSL/Easy-RSA certs

Cloud & Microsoft 365

Amazon Web Services (AWS)

Compute & Containers

EC2EKSECSLambdaAuto ScalingFargate

Networking & CDN

VPCVPC PeeringTransit Gateway (TGW)Route53CloudFrontALB/NLBDirect ConnectPrivateLink

Storage & Database

S3EBSEFSRDSAuroraDynamoDBElastiCache

Security & Identity

IAMKMSSecrets ManagerWAFShieldGuardDutySecurity Hub

End-User Computing

AppStream 2.0WorkSpacesWorkSpaces Web

Management & DevOps

CloudWatchCloudTrailCloudFormationSystems ManagerConfigCodePipeline

Microsoft Azure

Compute & Containers

Virtual MachinesAKSApp ServiceFunctionsContainer Instances

Networking

Virtual NetworkVNet PeeringLoad BalancerApplication GatewayFront DoorExpressRouteDNS ZonesVPN Gateway

Identity & Security

Entra ID (Azure AD)Conditional AccessKey VaultDefender for CloudSentinel

Data & DevOps

Azure SQLBlob StorageAzure DevOpsMonitorLog AnalyticsARM Templates

Microsoft 365 & Security

Endpoint Management

Microsoft IntuneDevice ComplianceApp ProtectionAutopilotConfiguration Profiles

Security & Threat Protection

Defender for EndpointDefender for IdentityDefender for Office 365Defender for Cloud AppsMicrosoft Sentinel

Identity & Access

Entra IDConditional AccessMFAPIMSSOAD ConnectRBAC

Compliance & Governance

DLP PoliciesInformation ProtectionMicrosoft PurviewRetention PolicieseDiscovery

Productivity & Collaboration

Exchange OnlineSharePointTeamsOneDrivePower AutomatePower BI

Education

Bachelor of Industrial Education

Electronics Technology

Focused on electronics, communications, and auto-control systems including microcontroller projects.

Sep 2007 – 2011

Alexandria Advanced Technical School

Electronics Department

Five-year technical education programme concentrating on electronics engineering fundamentals.

Sep 2002 – 2007

Certifications & Courses

MCSE

Microsoft Certified System Engineer

RHCE

Red Hat Certified Engineer

CCNA

Cisco Certified Network Associate

Xcally Certified

Associate Level

3CX ACE

Advanced Certified Engineer

OpenSIPS

Quick Start OpenSIPS 3.2

Continuous Learning

Terraform Advanced Patterns Kubernetes Administration AWS Solutions Architecture Azure Security Engineering Microsoft 365 Security Admin AI-Assisted Development (Kiro) Cloud Security Architecture Zero Trust Networking

Get in Touch

I'm always happy to connect and discuss new opportunities. Feel free to reach out using any of the channels below.