Mohamed Hawas

Sr. Network Consultant

Zoetermeer, Netherlands
Experience
Jan 2024 - Present
1 year 7 months
Netherlands

Sr. Network Consultant

HHR

DC Network Segmentation.

This project focused on DC Network Segmentation during the plan/implement phase. Main expertise included Aruba Pensando, Fortigate, Nutanix, Intune, and scripting.

To align with governmental regulations and adhere to best practices recommended by Gartner's Zero Trust Network Segmentation, HHR's data center must be segmented to enhance security and mitigate risks. Zero Trust principles emphasize that no user or system, whether inside or outside the network, should be automatically trusted. By segmenting the data center, HHR can limit access to critical applications and prevent lateral movement of potential threats across the network. This approach reduces the attack surface, isolates sensitive systems, and ensures stricter access controls, reinforcing the overall security posture of the organization.

Actions taken:

  • HLD network segmentation
  • Implementing Nutanix Flow FW segmentation (IT)
  • Implementing Intune FW segmentation (OT)

Results:

  • Both IT and OT environment has been secured by implementing network macro/micro-segmentation

Used techniques:

  • Fortigate, Aruba Pensando , Intune, Nutanix Flow Security
  • Power shell scripting is used for VM tagging; Postman is used for configuring policies on Pensando; Terraform for Nutanix flow

Financial impact:

  • Secure datacenter network communication which lower possibility of cyber-attack events
Jan 2024 - Dec 2024
1 year
Netherlands

Sr. Network Specialist (Client: SSC-ICT)

SmartNets

DC ACI migration, network automation.

This project involved DC migration and network automation during the plan/implement phase. Main expertise covered SD networking, MPLS/BGP/OSPF, and network automation.

The primary responsibilities for the position involved facilitating the deployment of SDN (Software-Defined Networking) technology within the data center environment and managing the migration to Cisco ACI (Application Centric Infrastructure) technology. A secondary aspect of the role was to address and rectify issues related to network automation that were causing outages and operational disruptions. Additionally, the role required extensive collaboration with the network operation and automation teams to improve integration and performance. The position also entailed active participation in various network integration projects for SSC-ICT clients, leveraging expertise in networking technology planning and design to ensure successful project outcomes.

Actions taken:

  • New DC is built using ACI technology
  • Solve issues and maintain operation for existing shared DCs.
  • Identified and diagnosed problems within the existing network automation framework.
  • Involved in the planning, design, and execution phases of MPLS network integration projects to ensure they meet client requirements and industry standards.
  • Changes in MPLS /BGP were done using Ansible playbooks
  • Changes on CE routers were done using cli
  • Changes on ACI were done using Terraform

Results:

  • DC locations migrated to ACI technology
  • Better performance for automation tooling and less network outages

Used techniques:

  • Cisco DC R&S, ACI, Ansible, Python, Gitlab.

Financial impact:

  • Less outages and better network performance at DC locations
Jan 2022 - Dec 2023
2 years
Netherlands

Solution Architect Networking (Client: KVK, Project: Network solution architecture)

SmartNets

Network guidelines, migrations and upgrade.

This project focused on Network architecture during the Design / Plan phase. Main expertise included Architecture, TOGAF, and SASE.

As a Network Architect, Mohamed was responsible for developing and implementing network architecture and guidelines for the company. The role demanded a thorough understanding of different infrastructure frameworks, and the ability for conceptual thinking. He was expected to collaborate with other architects, including cloud and domain architects, to ensure cohesive and efficient network solutions. Additionally, the role included providing expertise and acting as a knowledge hub for network technology, guiding the architectural team in adopting best practices and innovative solutions.

Actions taken:

  • Developed and wrote comprehensive network architecture and guidelines for the company's network infrastructure.
  • Conducted extensive research to expand and refine the definition of the network services, incorporating new trends and technologies.
  • Collaborated closely with cloud and domain architects, sharing network technology expertise to enhance the overall architecture.
  • Acted as a central knowledge hub, providing guidance and support on network technologies to architect colleagues.
  • Authored a solution architect document detailing the implementation of SD-WAN technology to interconnect data centers and office locations.

Results:

  • Successfully delivered a detailed and robust network architecture and guidelines document that was adopted company-wide
  • Produced a high-quality solution architect document that effectively outlined the SD-WAN interconnection strategy, resulting in a seamless integration of data centers and office locations.

Used techniques:

  • Cisco DC R&S, SDWAN, ACI, TOGAF 9.2, Zero Trust, Micro segmentation

Financial impact:

  • Less MPLS bandwidth usage (less OPEX) , better SaaS performance due to introduction of local internet lines (higher client satisfaction),well defined network service architecture.
Jan 2021 - Dec 2022
2 years
Netherlands

Solution Architect Networking (Client: Police, Project: Call Center Migration)

SmartNets

Design of alarm Centre locations.

This project involved Alarm central location migration during the Design / Plan phase. Main expertise covered Campus networking BGP/OSPF.

Building highly secure and robust campus network.

Jan 2020 - Dec 2021
2 years
Germany

Sr. Network Specialist (Client: Allianz Germany, Project: DC migration AZT)

Cognizant Technology Solutions

DC Migration from Cisco fabric path to ACI.

This project focused on DC migration during the Design / Implement phase. Main expertise included R&S, Wireless, Voice ACI, Netscaler, BGP/OSPF, and ISP.

The workload encompassed coordinating the network migration implementation among various involved parties, specifically Cisco Advanced Services and Accenture. This task required effective communication and collaboration with these external teams to ensure the seamless execution of the migration plan. The engineer was also responsible for creating detailed micro designs for different system migrations within the data center. This involved a meticulous approach to ensure that the designs were consistent across different network zones, maintaining uniformity and coherence in the overall network architecture. The engineer had to address any discrepancies and ensure that all designs aligned with the project's objectives and standards. Additionally, the role required the engineer to oversee the implementation process, monitor progress, troubleshoot issues, and provide regular updates to stakeholders.

Actions taken:

  • As SME, provide network consultancy service for Allianz Technology clients and business units.
  • Implement different migration projects from Fabric Path into ACI
  • Solve issues and implement changes on external connections (BGP/OSPF).
  • Provide migration plan for Citrix SDX load balancers and help management taking migration decision.
  • Migration of OOB network from cisco 2901 to Perle terminal servers, redesign the network to allow high redundancy and better security
  • Working with ISP on implementing changes

Results:

  • As a result of network migration, Allianz business units have better application experience and higher user satisfaction rate.

Used techniques:

  • Cisco DC R&S, Citrix load balancers, IPv6, Python, ACI, microsegmentation. Python scripts were used to gather inventory from network devices

Financial impact:

  • ACI allowed for micro segmentation of different business unit applications, which provided higher security and faster time to market for new applications. Automation tools allowed for less change lifecycle time.
Jan 2018 - Dec 2020
3 years
Remote

Sr. Network Specialist (Client: ERIKS, Project: Network LCM)

Cognizant Technology Solutions

Design and engineering for wireless and wired remote office network.

This project involved upgrading campus and remote locations during the Design / Implement phase. Main expertise covered R&S, Wireless, Voice ACI, Paloalto, and ASA.

ERIKS is a specialized industrial service provider that offers a wide range of technical products, co-engineering and customization solutions, as well as related services. Due to large acquisitions, network redesign for office locations was needed.

Actions taken:

  • As network solutions specialist, lead the migration project teams and provide necessary guidelines and instructions.
  • Provide HLD and LLD documents, as standard for global locations migration.
  • Provide onsite technical implementation during and after migration.
  • Liaise with architecture team to be sure that design complies with business guidelines.

Results:

  • 67 locations in Europe and NA was migrated to the new infrastructure seamlessly without interruption

Used techniques:

  • Cisco R&S, Python, ACI Python was used to push configurations to large number of switches

Financial impact:

  • Connectivity issues has been resolved and users could get access to better performed business applications.
Jan 2018 - Dec 2019
2 years
Remote

Sr. Network Specialist (Client: ABN AMRO Clearing Bank, Project: ABN AMRO Network Design)

Cognizant Technology Solutions

Design and engineering for wireless and wired remote office network.

This project involved the design and implementation of LAN/WLAN during the Design/ Implement phase. Main expertise covered R&S, Wireless, Voice, and ISE.

ABN AMRO Clearance bank is doing clear and finance over 16 million trades per day and covers 90 of the world’s leading exchanges across Europe, the Americas and Asia Pacific. Network design for LAN and WiFi network for remote offices was needed.

Actions taken:

  • Design and implement guest Wi-Fi network and remote office network for Europe and APAC locations
  • Work with ISP implementing changes

Results:

  • Secure mobility for guest users
  • Secure and reliable data communication for end users
  • Simplified network landscape

Used techniques:

  • Cisco Unified CM, VRFs, MPLS, OSPF,WLC 5508, WLC3504,AP SSO HA

Financial impact:

  • Easier managed and secure network allowed for higher business continuity and deployment of agile applications.
Jan 2016 - Dec 2018
3 years
Netherlands

Sr. Network Specialist (Client: FNV, Project: FNV Network migration)

Routz

DC and HQ network migration.

This project involved the design and implementation for the migration of IT landscape to new domain during the Design/ Implement phase. Main expertise covered R&S, ASA, Wireless, VOIP, Python, and OSPF.

FNV (Federatie Nederlandse Vakbeweging) is the labor union of the Netherlands. Around one million people are member of this union. The federation in the past contained several sub-unions each had its own IT infrastructure (data center/ wireless/ voice/ ISP/network). Different IT islands were connected and had dependency among each other. The network was complex and difficult to manage or maintain. Therefore, it has been decided to merge different domains into one standardized domain.

Actions taken:

  • Prepare and plan changes
  • Migration of 3X DCs to new location at Equinix
  • Implement data coupling with Azure
  • Liaise with different parties (system admins/ ISP/ vendors) during and after the change for test and validation
  • In the planning phase a network design has been introduced
  • During the operation phase all issues and problems were resolved
  • Work with ISP implementing changes

Results:

  • Five main locations have been migrated to the new domain (Aruba WiFi, Aruba network infrastructure, Skype for business) and they are interconnected via L2 MPLS (VPLS)
  • New twin datacenter has been built which provides manageability, high availability and flexibility for applications

Used techniques:

  • Checkpoint, Aruba switching, Aruba wireless, VRFs, MPLS, L2 switching

Financial impact:

  • A new IT domain which is efficient and easy to manage enabled cost saving and ROI.
Jan 2014 - Dec 2016
3 years
United Kingdom

Cybersecurity Consultant (Client: Shell, Project: Shell ICS security)

CGI

Design and implementation of secure network solutions for upstream locations at Shell (NL&UK).

This project involved designing and implementing secure network solution for industrial control systems (ICS) during the Design/ Implement/ Maintain phase. Main expertise covered R&S, Fortigate, traffic analysis, and ISA99.

Main responsibility of ICS security team is to enable secure operation for all upstream gas locations belonging to the NAM (Nederlandse Aardolie Maatschappij). Tasks are divided in two categories: run & maintain which includes: Support incident response activities and central coordination with IT and IRM stakeholders, Managing and maintaining a secure ICS in an operational facility and ensuring compliance to applicable standards (Shell DEP,ISA99), Deliver solutions to ensure that all assets and projects within the defined domain/scope are meeting the expected cyber risk management activities and reporting status/posture/compliance to the central technical and global leadership teams, Contribute to the central strategic direction and program objectives and communicating expectations in region, Collect technical solutions from regional stakeholders and communicate to the central team, Provide technical leadership and consulting to improvement, remediation projects. projects: Designing, developing and deploying resilient ICS architectures and system configurations during innovation and capital projects, Interfacing with operations when planned activities impact site operations, Integrating system security and robustness requirements into procurement specifications and contract agreements.

Actions taken:

  • Design and implementation of security and networking solutions to integrate new subsystems into network infrastructure
  • Real-time network and traffic auditing using network monitoring and event logging tools
  • Ensure system availability and integrity
  • Delivering project documentation

Results:

  • Integration of new ICS subsystems for different vendors (YOKOGAWA, Schneider Electric, Honeywell, and Siemens) into existing infrastructure met business needs and was successful without interruption.
  • No security incident has been recorded due to professional way of operation

Used techniques:

  • PCAD portal, Whatsup Gold, Infoblox IPM, WSUS, ePO, Symantec, Cisco, Fortigate, Fortianalyzer, Fortimanager, Checkpoint, KiWi

Financial impact:

  • ICS systems were secure at all upstream locations and worked continuously without interruption of gas production.
Jan 2012 - Dec 2014
3 years
Rotterdam, Netherlands

Lead Engineer (Client: Rijkswaterstaat, Project: CS-A15 Fiber backbone Rotterdam)

Croon B.V.

This project focused on building a communication network for traffic systems during the Implementation phase. Main expertise included Fiber optics and L2 switching.

The extension of the A15 (Maasvlakte - Vaanplein) was needed to increase capacity of the road, improve traffic flow and optimize safety. As a lead engineer, Mohamed was responsible for design and implementation of the backbone network, which will serve all traffic management subsystems along the highway (43 kilometer long). Mohamed used Cisco switches and fiber optical connections to implement the network.

Actions taken:

  • HLD was translated into LLD and implemented
  • Appointments were taken with different system custodians in order to provide the right network requirements for each system during all project delivery stages
  • In each stage liaison with RWS was done to deliver the equipment to the maintenance department according to agreements
  • Working closely with project phasing department was important to ensure no downtime

Results:

  • Old backbone network was decommissioned and new traffic systems were connected to the new one
  • Extra dark fibers were available to be sold to 3rd parties

Used techniques:

  • Cisco L2 Switching, AutoCAD, Visio, Whatsup Gold, making of fiber optic batching design, Wireshark, Cisco Catalyst IE300, Cisco 3750

Financial impact:

  • Traffic flow and safety were improved which led to less accidents and lower delay.
Jan 2011 - Dec 2012
2 years
Amsterdam, Netherlands

Network Engineer (Client: Rijkswaterstaat, Project: Coentunnel Amsterdam)

Croon B.V.

This project involved the rejuvenation of Coen tunnel in Amsterdam during the Design and implementation phase. Main expertise included Fiber optics and L2 switching.

The second “Coentunnel” and “Westrandweg” highway have been constructed to improve traffic flow and accessibility of Amsterdam city. Mohamed was responsible for design and implementation of layer 2 backbone network which backhauls traffic for all subsystems inside the tunnel. The network is coupled with the traffic management system for the Dutch government. Redundancy and low latency were key design requirements for this network and have been optimally achieved. Cisco switches and optical fiber connections were used in building the network. The network was successfully implemented and all functionalities were successfully verified against requirements.

Actions taken:

  • HLD was translated into LLD and implemented
  • Appointments were taken with different system custodians in order to provide the right network requirements for each system
  • Old infrastructure ring were decommissioned and replaced by new one

Results:

  • The network infrastructure was operationally delivered to RWS according to agreed specifications and system functional requirements

Used techniques:

  • Cisco L2 Switching, AutoCAD, Visio, Whatsup Gold, making of fiber optic batching design, Wireshark, Cisco Catalyst IE300, Cisco 3750, C50 encoder

Financial impact:

  • The tunnel was operational again and new installed systems increased safety and improved traffic flow.
Jan 2010 - Dec 2011
2 years
Netherlands

Network Engineer (Client: Rijkswaterstaat)

Croon B.V.

LLD and implementation of backbone fiber network for traffic systems.

Jan 2010 - Dec 2011
2 years
Netherlands

AVAYA System Engineer

KPN B.V.

Implementation, migration and troubleshooting of telephony infrastructure.

Project: ING VOIP infrastructure (Client: ING Bank, Netherlands)

  • Purpose: Migrate telephony infrastructure into new version of AVAYA communication manager (Implementation Phase). Main expertise: AVAYA aura communication manager.
  • Management team of ING bank in the Netherlands has approved a plan to enhance the telephony infrastructure owned by the bank nationwide. Within an implementation team, Mohamed has carried out the test and implementation of AVAYA unified communication network on multiple remote locations. All remote locations were able to use uninterrupted voice services and were connected to the main cluster server.
  • Actions taken:
  • Servers and gateways were configured accordingly
  • FAT has been done to ensure correct functionality and business needs have been met
  • For each location, system has been staged and delivered to maintenance department after SAT has been performed.
  • Results:
  • New functionalities have been added to telephony system which allowed more collaboration among workers
  • System capacity has been increased
  • Used techniques: AVAYA Aura Communication Manager 6.1, AVAYA Aura Session Manager,AVAYA Aura System Manager, G series media gateways
  • Financial impact: Obsolete telephony system was replaced by more advanced one with higher capacity. This allowed for higher collaboration.

Project: CAK VOIP infrastructure (Client: CAK, Den Haag, Netherlands)

  • Purpose: Consolidate scattered infrastructure into one central location (Implementation Phase). Main expertise: AVAYA aura communication manager.
  • CAK (Centraal Administratie Kantoor) has a central position in health care by performing financial arrangements and informing citizens on insurance regulations. The company has decided to relocate separate remote locations to one main location in Den Haag. Mohamed has implemented the new telephony infrastructure for the main office, which contains AVAYA communication manager, session manager, session border controller and AVAYA gateways. For mobile users, Mohamed has implemented AVAYA DECT solution to offer robust voice service. The new main office was ready on time at the opening day and offered unified communication services for the new location.
  • Actions taken:
  • New telephony infrastructure has been deployed in new location
  • The system supports DECT telephones for mobile workers
  • Results:
  • After successful SAT , system has delivered to maintenance department on agreed time
  • Used techniques: AVAYA Aura Communication Manager 6.1, AVAYA Aura Session Manager, AVAYA Aura System Manager, G series media gateways
  • Financial impact: Obsolete telephony system was replaced by more advanced one with higher capacity. This allowed for higher user collaboration and better call center performance.
Summary

Mohamed is an experienced Network Specialist with over 17 years in data networking, IT infrastructure, and cybersecurity. He has developed hands-on expertise in building large-scale networks and designing robust data center environments. Throughout his career, Mohamed has gained valuable experience maintaining and operating MPLS core networks, along with implementing migrations using the BGP routing protocol. His skills in network optimization and protocol management were further honed during his work on SSC-ICT projects, where he focused on ensuring high-performance and reliable network operations. Mohamed successfully designed and implemented optical backbone networks for major infrastructure projects for the Dutch government. He also developed security solutions to protect industrial control systems from cyber threats. Mohamed has significant experience managing large-scale network migrations and data center transitions. He led migrations for top clients, creating network designs and leading implementation teams to ensure successful transitions. He also supported clients in migrating their data center infrastructure from Cisco FabricPath to ACI. Beyond network engineering, Mohamed is skilled in automation with Python, Terraform, and Ansible, using these tools to improve network management and efficiency. His ability to streamline processes and automate routine tasks enhances his effectiveness in managing complex network environments. With his solid engineering skills, hands-on experience, and focus on delivering scalable and secure network solutions, Mohamed is well-positioned to contribute to any network and security project. His practical approach and deep knowledge of network infrastructure make him a valuable asset to any organization.

Languages
Dutch
Native
English
Advanced
Education
Oct 2009 - Jun 2009

TU Delft University of Technology

MSc · Mobile and Wireless Communications · Delft, Netherlands

Certifications & licenses

Designing Cisco Enterprise Wireless Networks (ENWLSD)

Cisco

Fortinet Certified Associate Cybersecurity

Fortinet

Aviatrix Certified Engineer (ACE) Multicloud Network Professional

Aviatrix

Implementing Cisco Application Centric Infrastructure – Advanced (DCACIA) v1.1

Cisco

Implementing Cisco Application Centric infrastructure (300-620)

Cisco

CCNP Enterprise

Cisco

ASE Flex Network Integrator

CCNA - Security

Cisco

AVAYA Aura Communication manager

Avaya

CCDP CISCO

Cisco

CCNP Routing & Switching

Cisco

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions