# Mustafa Yousry
Entrepreneur · CTO · Cyber Security

I build systems that hold up — then I try to break them.

- Location: Cairo, Egypt · Dubai, UAE · Berlin, Germany
- Email: mustafa@mustafayousry.com
- Website: https://mustafayousry.com
- LinkedIn: https://www.linkedin.com/in/mustafa-yousry-63141718a
- YouTube: https://www.youtube.com/@mustafayousry2190

## Summary
Fifteen years in startups, and every one of them with my hands in the code. I founded Cosmos Technologies, Jobatak and Cosmos Community, and I hold the CTO seat at Edura and Aggarly. The part of the job I have never delegated is the architecture itself. What that means in practice is owning the decisions that are expensive to reverse — where the boundaries between systems fall, who holds identity, what an attacker actually reaches when one service gives way — and then making those decisions impossible to drift away from. A domain layer the build rejects if it imports a framework. An identity provider we run rather than rent. Encryption designed so the algorithm can be replaced without touching the data. Architecture that exists only in a document is not architecture. The other half is security, and it came the long way round: a Master's from Cairo University and four years inside the Egyptian Center for Combating Terrorism. Spend that long on how systems come apart and the order of the work changes — threat model first, features after. It is why the layers below read from the bottom up.

## At a glance
- 15+ — Years in startups & business
- 5 — Companies founded or led
- MSc — Cyber security, Cairo University
- 8+ — Years in security practice

## Technical stack
### L4 · Interface
The part people actually touch. Fast, accessible, and built to survive a bad network.
Next.js, React, TypeScript, Server-first rendering, i18n & RTL

### L3 · Application
Where the business logic lives. Clear boundaries, honest data models, no clever tricks.
Django, Python, PostgreSQL, Celery, Redis, OpenAPI contracts, Event-driven workflows

### L2 · Infrastructure
What it all runs on. Reproducible environments, real pipelines, and a way back when something breaks.
AWS, Terraform, Docker, ECS Fargate, Linux, CI/CD pipelines, Observability

### L1 · Security
The layer most teams bolt on last. I start here — threat model first, features after.
Threat modelling, OAuth2 / OIDC, Encryption at rest, Least privilege, Audit trails, Secrets management

### Running through all four
Layers are only worth as much as the rules that keep them apart. These are the practices that enforce them — and the reason a codebase can still be changed safely two years in.
Domain-driven design, Ports & adapters, Architecture decision records, Layering enforced in CI, Infrastructure as code, Automated testing

## Security practice
### OFFENSE · Penetration testing
The only honest way to know whether something holds is to attack it. Scoped, authorised, and written up so your engineers can act on it on Monday.
Kali Linux, Web application testing, Network & infrastructure testing, Vulnerability assessment, Privilege escalation, Actionable reporting

### FORENSICS · Digital forensics
After an incident the questions are always the same: what happened, when, and what left the building. Answering them takes evidence, not guesses.
Disk & file system analysis, Memory analysis, Log & artifact timelines, Evidence handling, Malware triage

### INTEL · Investigations
This is where the counter-terrorism years actually went. Tracing an actor across what they left behind is a different discipline from securing a server, and it changes how you read every system afterwards.
OSINT, Incident investigation, Threat intelligence, Attribution, Case documentation

### DEFENSE · Hardening & response
Everything above is only useful if it changes the system. This is the part that does: closing what was found, then making sure the next one is noticed early.
Linux hardening, Network segmentation, Monitoring & detection, Incident response, Team training

## What I take on
### Build it
You have something to build and no team to build it. I take it from an empty repository to a product running in front of real users, with the architecture decided on purpose rather than by accident.
- Web and mobile products
- APIs and data models
- Cloud setup on AWS

### Secure it
You have something already running and you are not certain it would survive someone trying. I go through it the way an attacker would, then harden what needs hardening.
- Security review and hardening
- Digital forensics
- Incident response and training

### Own it
You have engineers but nobody holding the technical direction. I take that seat part-time: architecture, hiring, delivery — so you can stay on the business.
- Architecture and tech decisions
- Hiring and mentoring engineers
- Delivery process and code quality

## Experience
- **Now** — Chief Technology Officer, Edura — UAE
- **Now** — Chief Technology Officer, Aggarly Inc.
- **2022 →** — Founder, Cosmos Technologies — Software studio — web, mobile and AI products
- **2021 — 2025** — Cyber Security, Egyptian Center for Combating Terrorism — Where I learned to read a system the way an attacker does
- **2018 →** — Security Consulting & Advisory, Independent — Reviews, hardening and incident work, running alongside the building
- **2018 →** — Founder, Jobatak Inc.
- **2018 — 2021** — Software & Business Development, Independent — Berlin — Berlin years — TU Berlin, and building for European clients
- **2015 →** — Founder, Cosmos Community — Social enterprise
- **2005 — 2018** — Administration & Management, Business operations — Running the operation itself — the years that taught me how a business actually holds together

## Education
- **2022 — 2023** — Master's — Cyber Security & Digital Media, Cairo University
- **2020 — 2021** — Professional Diploma — Cyber Security & Computer Forensics, Cairo University
- **2019** — Innovation & Entrepreneurship, Technische Universität Berlin
- **2007 — 2011** — Bachelor's — Social Work & Social Psychology, Banha University

## Certifications
- Cyber Security & Digital Media — Cairo University
- NLP Practitioner — Global NLP Training, Amsterdam
- Motivational Coach — Global NLP Training, Amsterdam

## Languages
- Arabic — Native
- English — Fluent
- German — B1
- Russian — B1
- Italian — A2
- French — A1
