You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Malik AmmariMA

Malik Ammari

Expert Cloud Network and Security Engineer

€600/day
Paris, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Malik

Expert in Network and Security infrastructures with over 15 years of experience, I work on the design (Build) and operational maintenance (Run) of critical environments. My background, forged with operators (SFR, Free) and in the Defense sector (EADS), has allowed me to develop in-depth mastery of Level 3 troubleshooting and complex flow security.

Today, I support large companies in their digital transformation through:

  • Cloud & Hybrid Engineering: Design and deployment of architectures on AWS, Azure, and SDN architectures (VMware NSX).
  • Multi-vendor Security: Advanced expertise on Fortinet, Check Point, Palo Alto, and sovereign solutions (Arkoon/Stormshield).
  • Performance Optimization (ADC): Mastery of F5 (LTM/APM) and Zscaler solutions to ensure the availability and security of access.
  • Technical Lead: Ability to manage complex projects (DAT/DEX) and technically supervise engineering teams.

Certified PRINCE2, I combine methodological rigor and cutting-edge expertise to ensure a resilient and highly available infrastructure (99.99% SLA).
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • Neurones IT
    Cloud Network and Security Engineer (Build & Run) – ISO27001 Environments
    TECH
    February 2016 - February 2026 (10 years)
    Nanterre, Île-de-France, France

    Engineering & Architecture (Build)

    • Secure Architectures Design and Deployment: Design, configuration, and commissioning of critical foundations including Firewalls, Switching, and Loadbalancing.
    • Cloud & SD-WAN Migration Expertise: Technical management of the implementation of Cloud solutions (Private Cloud (80%), Azure (5%), AWS (10%), OVH (5%)) and deployment of VPN/SD-WAN solutions.
    • High-Fidelity Engineering Documentation: Production of Technical Architecture Dossiers (DAT) and operational procedures (DEX) to ensure infrastructure sustainability.
    • Segmentation & Micro-segmentation: Implementation of complex network segmentation projects and integration of VMware NSX type solutions.

    Operational Maintenance (Run) & L3 Expertise

    • Last Level Support (L3): In-depth diagnosis and resolution of critical incidents (P1/P2) on parks of +500 equipment (Cisco Nexus, Fortinet, F5).
    • Critical Change Management: Technical impact analysis and execution of complex modifications in high-availability production environments (99.99% SLA).
    • Cyber-resilience & Hardening: Continuous vulnerability analysis (CVE), application of patching plans, and advanced optimization of filtering rules (Firewalling & Proxy).
    • Content Security & ADC Expertise: Administration and optimization of Zscaler, Cisco Ironport, F5 LTM/APM solutions, and Proxy solutions (Bluecoat).

    Major Technical Achievements

    • Security Standardization: Automation of network equipment hardening to meet security audits.
    • Technical Lead: Technical referent for a team of 10 to 15 engineers, ensuring technical arbitration on complex Build projects.
    Cybersecurity Firewalls Cisco Systems Products VPN F5 BigIP
  • EADS Defence & Security
    Security & Network Engineer – Critical Environments
    DEFENSE AND MILITARY
    January 2012 - January 2016 (4 years)
    Les Mureaux

    Engineering & Secure Design (Build)

    • Trusted Architectures Design: Design and deployment of hardened network foundations (high-security DMZ segmentation, dynamic routing, switching) for the protection of sensitive databases.
    • Sovereign Solutions Integration: Expertise in deploying state security technologies (Arkoon/Stormshield Firewalls) within regulated environments.
    • Complex Flow Architecture: Implementation and security of partner interconnections and granular management of critical application flows.
    • Access Solutions Deployment: Integration and configuration of Bluecoat filtering solutions (Proxy SG) and secure remote SSL VPN Juniper access.

    Operational Expertise & MCO (Run)

    • Operational Maintenance (MCO): Supervision and administration of a park of +100 critical equipment in a "Secret Defense" environment.
    • VPN & Encryption Expertise: Advanced administration of IPsec and SSL VPN tunnels to ensure the integrity and confidentiality of data exchanges.
    • High-Level Support (L3): Diagnosis and resolution of complex incidents on dynamic routing and switching infrastructures (Cisco, HP).
    • Continuous Optimization: Performance analysis and hardening of security policies to meet the high availability requirements of the Defense sector.

    Key Achievements

    • Referent Expert: Technical guarantor of network infrastructure compliance with contractual and security requirements on client sites.
    • Technical Governance: Technical lead during operational committees to translate business needs into secure network architecture solutions.
    Cisco Systems Products Firewall F5 BigIP Fortinet VPN
  • SFR
    Network & Security Engineer – CAP5 Contract (SFR / BT)
    TELECOMMUNICATIONS
    January 2009 - January 2012 (3 years)
    La Defense
    Within the CAP5 contract, BT provided SFR with network and security infrastructure engineering, integration, and maintenance (flow opening, routing, switching, VPN, proxy, DNS).

    Non-compliance and project management:

    • Analysis and treatment of network and security non-compliance issues
    • Management of corrective action plans in a production environment
    • Management of non-compliant requirements
    • Diagnosis, analysis, and troubleshooting of technical incidents
    • Implementation of definitive corrective and workaround solutions

    Network and security engineering:

    • Needs assessment for setting up secure flows to databases and service platforms
    • Design of optimized network architectures
    • Implementation of fixes on affected equipment
    • Unification of employee remote access via a single secure access point

    Security projects:

    • Update of the firewall park on the SFR perimeter (SFR Fixed, SFR Mobile, DCN, CASE)
    • Migration of partner flows to a single entry platform

    Operation and support:

    • Resolution of level 3 network and security incidents
    • Validation and implementation of flow openings and routing rules
    • Debugging of encrypted flows (IPSEC, SFTP)
    • Analysis of security issues: antispoofing, NAT, VRRP, SNMP, tunneling
    • Technical support, telephone assistance, and security on-call

    Technical environment:

    • Network equipment: Cisco routers and switches
    • Firewalls: FWSM, CheckPoint, PIX, ASA, Fortigate, Juniper
    • Proxy and VPN 3000 concentrators
    Cisco Systems Products F5 BigIP Firewall VPN Checkpoint

Recommendations

Be the first to recommend Malik

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • PRINCE 2 Certification (project management).
    PRINCE 2 Certification
    2011
  • Master's degree
    Telecom ParisTech
    2002

Certifications

  • Prince 2
    bt
    project management
  • Fortigate NSE3
    Globale Knowlege
    Network Administration

Skill set

Categories