Nader Shallabi, Developer in Abu Dhabi, United Arab Emirates
Nader is available for hire
Hire Nader

Nader Shallabi

IT Security Expert and Developer

Abu Dhabi, United Arab Emirates

Toptal member since December 8, 2025

Bio

Nader is a seasoned information security professional with deep expertise in cloud security, enterprise architecture, and security operations. He is skilled in building security programs, modernizing SOC capabilities, and driving secure digital transformation. Nader is skilled at aligning cybersecurity and data protection with business objectives to mitigate risk and enhance operational resilience.

Portfolio

Yahsat (Now Space 42)
Incident Response, Cyber Threat Hunting, Vulnerability Management, SIEM...
Orange
Threat Modeling, Threat Intelligence, Incident Response, Digital Forensics...
LEAD Technologies (LEADTOOLS)
C++, Java, C#.NET, Windows API, Windows Kernel Drivers, Image Processing...

Experience

  • Incident Response - 20 years
  • Digital Forensics - 20 years
  • Security Architecture - 20 years
  • Reverse Engineering - 20 years
  • Malware Analysis - 20 years
  • ISO 27701 - 15 years
  • IT Security - 15 years
  • Azure Cloud Security - 15 years

Preferred Environment

Windows 11, Visual Studio, JetBrains IDE, Visio, Embarcadero RAD Studio

The most amazing...

...things I've modernized are security architecture and SOC operations for high-criticality satellite communications, which protect national infrastructure.

Work Experience

Information Security Manager, Acting VP

2014 - 2023
Yahsat (Now Space 42)
  • Established the full Security Operations and Incident Response (SecOps/IR) framework for proactive threat monitoring, vulnerability management, and continuous exposure reduction, including training and mentoring SOC resources.
  • Designed and implemented the enterprise security architecture (ESA) to modernize endpoint, network, application, cloud, and data protection controls across the hybrid corporate infrastructure.
  • Enabled 24/7 SOC monitoring and response by integrating security telemetry, centralized log management, and threat intelligence pipelines across critical systems and applications.
  • Implemented unified baseline security standards for endpoints, servers, network devices, and enterprise applications, increasing security maturity and reducing configuration drift.
  • Conducted recurring internal and external audits and health checks to maintain compliance obligations and improve security posture across business units.
  • Initiated risk-based information security and data protection programs to identify, prioritize, and eliminate security risks, aligning cyber controls with business objectives.
  • Established and chaired a C-suite–led information security committee, owning reporting and governance of security performance, posture, and risk decisions at the executive level.
  • Led the corporate policy and security governance framework development, including security strategy, standards, and operational procedures.
Technologies: Incident Response, Cyber Threat Hunting, Vulnerability Management, SIEM, Logistics Engineering, Azure Cloud Security, AWS Cloud Security, Zero Trust, Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), CrowdStrike, FortiGate, Azure, Microsoft Defender XDR, ISO 27701, NIST, NESA, General Data Protection Regulation (GDPR), Data Privacy, Security Governance, Darktrace, Risk Management, Web Application Firewall (WAF), Imperva Incapsula, McAfee DLP, McAfee MVISION Endpoint, McAfee Endpoint Security, McAfee ePolicy Orchestrator (ePO), Cisco, Aruba ClearPass, Secure Email Gateways (SEGs), Enterprise Architecture

Security Operations Manager

2004 - 2014
Orange
  • Led 24/7 SOC operations, delivering security monitoring and incident response services for banking, telecom, utilities (OT), and government infrastructures, and ensuring the availability and resilience of national-level systems.
  • Conducted digital forensics and complex cyber investigations, significantly reducing threat containment and recovery time for critical clients.
  • Designed and implemented enterprise security architecture for high-value systems, including VoIP, billing, payment infrastructure, electoral platforms, and nationwide online services.
  • Executed specialized security assessments and vulnerability reduction programs, improving customer cyber-readiness and compliance posture.
  • Developed and enhanced managed security services, enabling Orange Enterprise to scale cybersecurity offerings and improve customer security maturity.
  • Strengthened incident response playbooks, monitoring workflows, and operational KPIs, boosting SOC maturity and efficiency across all security services.
Technologies: Threat Modeling, Threat Intelligence, Incident Response, Digital Forensics, SIEM, Log Analysis, Vulnerability Management, Malware Analysis, Reverse Engineering, Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Firewalls, Cisco, Zero Trust, OT Security, Identity & Access Management (IAM), Data Protection, ISO 27701, IT Security, Security Architecture, Penetration Testing, IT Audits, PCI Compliance, SOC Compliance, Security Policies & Procedures, Managed Security Service Providers (MSSP), Service Design

Software Engineer

2000 - 2004
LEAD Technologies (LEADTOOLS)
  • Designed and developed high-performance C/C++ imaging libraries using Win32 APIs, SDKs, and driver-level components, improving imaging processing efficiency across enterprise products.
  • Delivered core components that powered imaging solutions for global industry leaders such as Microsoft, Kodak, and Xerox, enhancing product reliability and compatibility.
  • Implemented advanced image manipulation, compression, and device integration features, contributing to multiple commercial product releases under tight delivery timelines.
  • Collaborated with the US engineering teams to optimize software performance and memory utilization, reducing processing latency in critical imaging workflows.
  • Built robust SDK modules that enabled third-party developers to rapidly integrate LEADTOOLS imaging capabilities into .NET and native Windows applications.
  • Established early secure coding practices in C/C++ to reduce memory corruption issues, including buffer management, pointer safety, and exception handling.
  • Contributed to the product maintenance lifecycle, including bug analysis, reverse engineering, and production support, improving software stability and customer satisfaction.
Technologies: C++, Java, C#.NET, Windows API, Windows Kernel Drivers, Image Processing, Color Science, SDK Development

Experience

Enterprise Security Architecture and SOC Enablement

Directed a multi-year transformation to modernize security controls for hybrid cloud and on-premises infrastructure supporting mission-critical communication platforms.

I delivered a unified enterprise security architecture covering endpoints, perimeter, network segmentation, secure access, and cloud workloads. I also integrated advanced logging pipelines, SIEM correlation rules, MDR/NDR sensors, and incident response playbooks to enable 24/7 managed SOC operations. To reduce exposure to modern threats, I established configuration baselines, vulnerability risk scoring, and zero-trust identity enforcement.

Finally, I drove cross-team adoption, vendor alignment, and continuous improvement, resulting in measurable gains in threat visibility, response speed, and overall cyber resilience.

Information Protection Program | Data Security and Compliance

Designed and executed a corporate-wide information protection program to secure sensitive financial, operational, and personal data across a fast-growing organization.

I defined data domains, classification rules, and DLP governance to align with regulatory and business requirements. I also implemented technical enforcement using Microsoft security stack, including AIP labeling, encryption, Cloud App Security policies, and behavioral analytics. Finally, I established governance and monitoring procedures, executive reporting mechanisms, privacy coordination, and staff awareness campaigns to promote responsible data handling.

The program significantly reduced accidental data exposure risks, strengthened audit readiness, and improved cloud compliance maturity.

Education

1996 - 2000

Bachelor's Degree in Computer Science

Applied Science University - Amman, Jordan

Certifications

MAY 2023 - PRESENT

AWS Security Specialty - Security Architect

Amazon Web Services

MARCH 2020 - PRESENT

ISO 27001 Lead Implementer

BSI Group

JANUARY 2020 - PRESENT

GREM - GIAC Reverse Engineering Malware

SANS

FEBRUARY 2014 - PRESENT

CISA - Certified Information Systems Auditor

ISACA

JULY 2013 - PRESENT

CHFI - EC-Council Computer Hacking Forensics Investigator

EC-Council

JULY 2013 - PRESENT

ECSA - EC-Council Certified Security Analyst

EC-Council

JULY 2013 - PRESENT

CEH - Certified Ethical Hacker

EC-Council

JANUARY 2013 - PRESENT

CISSP

ISC2

JANUARY 2006 - PRESENT

Project Management Professional (PMP)

PMI

Skills

Libraries/APIs

Windows API

Tools

Darktrace, McAfee MVISION Endpoint, McAfee Endpoint Security, McAfee ePolicy Orchestrator (ePO), Microsoft AI, IBM QRadar, Azure Information Protection (AIP), Google Vision AI, Microsoft Copilot, Visual Studio, Visio

Languages

C++, Java, C#.NET, Python

Paradigms

Penetration Testing

Platforms

CrowdStrike, Azure, Imperva Incapsula, Aruba ClearPass, AWS IoT

Other

Software Engineering, Programming, Windows Kernel Drivers, Image Processing, Color Science, SDK Development, Threat Modeling, Threat Intelligence, Incident Response, Digital Forensics, SIEM, Log Analysis, Vulnerability Management, Malware Analysis, Reverse Engineering, Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Firewalls, Cisco, Zero Trust, OT Security, Identity & Access Management (IAM), Data Protection, ISO 27701, IT Security, Security Architecture, IT Audits, PCI Compliance, SOC Compliance, Security Policies & Procedures, Managed Security Service Providers (MSSP), Service Design, Cyber Threat Hunting, Logistics Engineering, Azure Cloud Security, AWS Cloud Security, Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), FortiGate, Microsoft Defender XDR, NIST, NESA, General Data Protection Regulation (GDPR), Data Privacy, Security Governance, Risk Management, Web Application Firewall (WAF), McAfee DLP, Secure Email Gateways (SEGs), Enterprise Architecture, Artificial Intelligence (AI), Microsoft Purview, Strategy, Digital Risk, Network Segmentation, Business Continuity & Disaster Recovery (BCDR), Compliance, Security Awareness Training, OpenAI, Windows 11, JetBrains IDE, Embarcadero RAD Studio, Information Security, Security Audits, Ethical Hacking, IT Project Management, Security Operations Centers (SOC), Governance

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring