CTO · Cybersecurity Architect

Gerhard Mourani

24+ years building secure, high-availability infrastructure — aligning cybersecurity strategy with business outcomes. Zero Trust, SIEM/SOAR, EDR/XDR, ISO 27001 / NIST.

Scroll
24+Years experience
99.999%Uptime delivered
−50%Mean time to repair
6,000+Devices monitored
−85%Risk exposure cut
About

Who I am


Photo of Gerhard Mourani

I'm a CTO and cybersecurity architect based in Montréal, with over two decades dedicated to securing and scaling mission-critical infrastructure. My focus is the intersection of security strategy and business outcomes — leading detection & response programs, cutting MTTR by 50%, and sustaining 99.999% availability across critical environments.

I'm an expert in network & security architecture (NGFW, WAF, SIEM/SOAR, EDR/XDR, IAM/PAM) and compliance (ISO 27001, NIST, PCI-DSS). As an R&D leader I designed blësk, a proprietary monitoring platform competing with SolarWinds, deployed across many client sites. I lead a multidisciplinary team — engineers, marketing and account managers — and partner with leading technology vendors (Fortinet, Cisco, Microsoft, Securitas, Dell, Veeam).

The value I bring: lower risk, optimized OpEx/CapEx, and standardization through automation (IaC / DevSecOps).

Zero Trust SIEM / SOAR EDR / XDR IAM / PAM ISO 27001 NIST PCI-DSS DevSecOps
What I do

Expertise


From hands-on security architecture to fully managed services — what I cover for client organizations.

Cybersecurity Architecture

Zero Trust segmentation, NGFW & WAF deployments, SIEM/SOAR, EDR/XDR and IAM/PAM. Designed stacks that cut major incidents by 80% and brought MTTR down 90%.

OS-level Micro-segmentation

Advanced micro-segmentation at the host / OS layer with agent-based, application-aware policies. Lateral-movement containment that goes beyond traditional network segmentation — true Zero Trust enforcement workload to workload.

Shadow AI Governance

Discovery and governance of unauthorized AI use across the organization. Inventory, risk scoring, data-leak controls and policy enforcement — bringing AI usage in line with ISO 27001 and data-protection requirements.

Risk & Compliance

Risk-aware governance and audits aligned to ISO 27001, NIST and PCI-DSS. IR playbooks, crisis drills, phishing simulations — including an 80% drop in malicious-click rate in four months.

Network Monitoring

blësk — a proprietary, Linux-based monitoring platform that tracks 6,000+ devices in real time. A direct, cost-effective alternative to SolarWinds & WhatsUp Gold.

Linux Publications

Three full-length books on hardening and optimizing Linux servers — used in academic and professional settings, translated into multiple languages. Free PDFs, no signup.

Managed Security Services (MSSP)

End-to-end managed services for client organizations — we operate the full stack on your behalf, freeing your teams to focus on the business.

  • Infrastructure monitoring
  • Cybersecurity operations
  • Network device management
  • Antivirus & endpoint protection
  • Backup & disaster recovery
  • Patching, updates & optimization
Career

Experience


Two decades of hands-on engineering and leadership across security, monitoring and infrastructure.

2019 — Present

Chief Technology Officer (CTO)

Prival ODC Inc. · Montréal, Canada
  • Defined the cyber strategy and target architecture (Zero Trust, network segmentation), reducing risk exposure by 85%.
  • Led a multidisciplinary team; cut OpEx by 35% through vendor and tooling optimization.
  • Directed incident response and crisis exercises (IR playbooks), keeping RTO/RPO inside SLA.
  • Embedded a risk culture via training and phishing simulations — 80% drop in malicious clicks within 4 months.
2011 — 2018

Risk & Monitoring Architect

Prival ODC Inc. · Montréal, Canada
  • Designed an Elastic-based SIEM + SOAR stack with SentinelOne EDR/XDR, lowering MTTR by 90% and major incidents by 80%.
  • Built an HA/DR infrastructure (FortiGate cluster, Brocade load-balancing, VMware) hitting 99.999% on critical systems.
  • Led R&D on a proprietary Linux monitoring platform (SolarWinds alternative) covering up to 6,000 devices — false-positive rate down 90%, NOC efficiency up 60%.
2004 — 2010

Lead Engineer & Network Monitoring

Prival ODC Inc. · Montréal, Canada
  • Designed and deployed a Linux network monitoring server combining open source and proprietary code — direct competitor to SolarWinds / WhatsUp Gold.
  • Drove R&D and integration of advanced monitoring software, lifting anomaly detection by 70%.
  • Supervised on-site and remote incident response, cutting average MTTR by 50% and pushing CSAT to 95%.
  • Built automation and custom dashboards holding critical-service availability at ≥99.95%.
2000 — 2004

Linux Systems Designer

Open Network Architecture, Inc. · Montréal, Canada
  • Designed and shipped OpenNA Linux — a hardened, performance-tuned proprietary distribution; cut critical vulnerabilities by 75%.
  • Built a secure e-commerce platform with strong cryptography, improving trust and PCI-DSS posture.
  • Ran the full IT estate and Tier-3 24/7 support for major US clients, halving MTTR on critical incidents.
  • Developed network & email security (GIPtables firewall, SMTP anti-spam/anti-relay/AV, pen-tests), strengthening overall protection by 70%.
Toolkit

Skills & Certifications


Technologies, vendors and frameworks I work with day-to-day, plus the certifications that back them.

Operating Systems

  • Linux (Red Hat, Debian, Ubuntu)
  • Windows Server
  • UNIX (Solaris, AIX, HP-UX)

Cybersecurity

  • Zero Trust
  • SASE
  • SIEM
  • SOAR
  • EDR / XDR
  • DLP
  • IAM / PAM
  • Micro-segmentation
  • Shadow AI Governance
  • Security Audits
  • ITIL Compliance

Security Vendors

  • Fortinet
  • SentinelOne
  • Netskope
  • BeyondTrust
  • Mimecast
  • Netwrix
  • Qohash
  • Ninjio

Networking

  • Cisco
  • Brocade
  • HPE
  • Aruba
  • Dell
  • VLAN
  • OSPF
  • BGP
  • QoS
  • MPLS
  • Wi-Fi (Cisco, Fortinet, Ruckus)

Virtualization & Cloud

  • VMware ESXi
  • Proxmox
  • Xen
  • Microsoft Azure

Backup & DR

  • Veeam
  • Datto
  • DRP
  • Asset management

Databases

  • MySQL
  • PostgreSQL
  • Microsoft SQL Server
  • Oracle
  • Elasticsearch

Programming & Automation

  • Bash
  • JavaScript
  • Perl
  • PHP
  • C
  • HTML
  • Internal R&D tooling

Frameworks & Compliance

  • ISO 27001
  • NIST
  • PCI-DSS
  • DevSecOps
  • IaC
  • IR Playbooks
  • Risk Management

Certifications

Selected Projects

Engagements that mattered


Public Sector

Advanced monitoring across hospitals, schools and municipalities

Deployed and tuned monitoring environments for healthcare networks, school boards, CÉGEPs and city services. Result: 60% fewer false alerts, 24/7 visibility on 3,000+ critical devices, and proactive anomaly detection before service impact.

blëskSIEMCustom dashboards
Retail

Redundant network for online transactions & loyalty

Designed a high-availability network securing online transactions and loyalty programs for a major retail group. 99.999% SLA delivered, fault tolerance across 100+ devices, and downtime kept under 5 minutes per year on critical flows.

FortiGate clusterBrocade ADXVMwareDell EqualLogic
Transportation

MPLS network monitoring for a metropolitan backbone

Full-stack monitoring of an MPLS backbone covering a major metropolitan area — L2/L3 supervision (VRRPE, CE, PE). 95% of critical anomalies detected and resolved before service impact; 99.97% backbone availability.

Brocade Super-XRuggedComIBM Tivoli10 GbE redundant
Aviation

Secure Linux infrastructure for global ITS services

Hardened, highly-available Linux estate powering airport ITS services worldwide for an international aviation organization. 99.99% uptime, full DR documentation halving RTO, and consistent dev/staging/production environments across continents.

RHEL 4 ES/ASHP bladesSANFailover

Free Linux Security Books

Three full-length books on hardening, optimizing and operating Linux — used in academic and professional settings, translated into multiple languages. Free PDFs, no signup required.

Browse the Library
Contact

Let's get in touch


Have a question, an architecture review to scope, or an engagement to discuss? Reach out — I'll get back to you as soon as possible.