Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Timeline
Courses

Abdulaziz Alsuraya

Cybersecurity Team Lead
Saudi Arabia

Summary

Cybersecurity Team Lead with extensive experience in multiple cybersecurity areas within the banking industry such as of Security Operation Center (SOC), Digital Forensics and Incident Response (DFIR), Cyber Threat Management & Intelligence (CTMI) and Cyber & Digital Crimes / Cyber-Fraud.

Adaptable and versatile individual whom led multiple initiatives and developed, executed strategic objectives within the cybersecurity defense. Had various training experiences and certifications, which were applied back to achieve organizational objectives.

Overview

6
6
years of professional experience
5
5
years of post-secondary education
8
8
Certificates
2
2
Languages

Work History

Cyber & Digital Crimes Lead

Banque Saudi Fransi
01.2023 - Current
  • Developed and managed the Cyber & Digital Crimes (known as Cyber-Fraud) function, which consists of the governance, compliance, detection and prevention of Cyber-crimes, as well as designing, implementing and executing strategic requirements and initiatives.
  • Assessed, planned, managed and implemented cyber-fraud controls, whether the controls were compliance (i.e. SAMA CFF) or Risk oriented in alignment with IT, Anti-Fraud and business units, handled all cybersecurity-specific external / internal audit matters.
  • Developed the function's strategy, charter, processes and procedures, including set of KPIs and KRIs to measure effectiveness and risk regarding technological and operational cyber-fraud aspects. Ensured the delivery of top management requirements and assisted / participated in cyber-fraud projects (e.g. Group-IB deployment, Integrations with fraud management systems, etc.
  • Provided directions and managed operational requirements, assigned activities to reportees and administrate performance goals and priorities, ensured continuous enhancements are conducted.
  • Development of SLAs, managing joint engagements with internal and external business stakeholders, preparing and presenting executive management / committees presentations & proposals.

Senior Cybersecurity Defense Officer

Banque Saudi Fransi
03.2021 - 01.2023
  • Shown deep understanding and performance in cybersecurity defense fields through following and performing DFIR activities and initiatives, which consists and not limited to:
  • Managing governance and compliance requirements, which included development and authoring of DFIR documentations.
  • Conducting advanced investigation on escalated cases within the organization.
  • Incident Response activities following defined processes and best practices as part of Incident Management Lifecycle.
  • Digital Forensics examination and Malware Analysis.
  • Involvement in DFIR projects (Proposals, BRD developments, budgeting acquisition, etc.) whether they're technology related (e.g. EDR, Packet Capturing, etc.) or not, such as DFIR lab development.
  • Handling Audit requirements and inbound requests related to DFIR.
  • Continuous enhancements of DFIR processes and toolsets, and coordinating requirements with different stakeholders (e.g. HR, Operational Risk, Audit, Legal, etc.).

Cybersecurity Defense Officer

Banque Saudi Fransi
05.2019 - 03.2021

Experienced in Security Operations (e.g. Monitoring, Incident Response, etc.). Which includes:


  • L1 Analyst: Logs Analysis, Intrusion Analysis, Escalation of incidents.
  • L2 Analyst: Participates in engagements (Integrations with SIEM, Security Controls Effectiveness reviews, initial response activities, and advanced cybersecurity investigations, use cases and rules developments, coordinating with business units regarding monitoring requirements).
  • Involved in multiple requirements (Governance, Compliance and Audit related).


Information Security Analyst

IT Security Training & Solutions - I(TS)²
05.2019 - 09.2019
  • Monitoring, analyzing and escalating cybersecurity events and potential incidents, which includes but not limited to (Email analysis, identification of data leakage, detection of web-based, DDOS and network attacks, database and web application attacks monitoring, etc.).

Summer Training

CIT's Wing At King Abdullah's Airbase
06.2017 - 08.2017
  • Networking, Cybersecurity, IT support, web development & design. 200h

Education

Bachelor Of Science - Information Systems

King Abdulaziz University, Jeddah
02.2013 - 05.2018

Skills

Security Operations

undefined

Certification

Critical Controls Certification (GCCC)

Accomplishments

  • Successfully developed the Cyber Fraud function in BSF and established all its relevant management, strategic, operational and tactical requirements.
  • Designed, managed and delivered all SAMA CFF cybersecurity requirements, which was verified by the enterprise Internal Audit.
  • Authoring various cybersecurity documentations (Strategies, Policies, Charters, Processes, Procedures, and guidelines)
  • Involvement in various initiatives and activities (e.g. gab assessments, risk assessments, compliance reviews, security controls and technology reviews).
  • Managing the business requirements of multiple cybersecurity projects and ensuring their delivery in alignment with PMs.
  • Multiple personal achievements (e.g. GIAC Advisory Board, SANS DFIR NetWars Champion, FOR500 Challenge Coin Winner, etc.).

Timeline

Cyber & Digital Crimes Lead - Banque Saudi Fransi
01.2023 - Current

Certified Forensics Examiner (GCFE)

08-2022

Security Essentials Certification (GSEC)

07-2022

Cyber Threat Intelligence (GCTI)

02-2022

Network Forensics Analyst (GNFA)

01-2022

Certified Forensics Analyst (GCFA)

10-2021
Senior Cybersecurity Defense Officer - Banque Saudi Fransi
03.2021 - 01.2023

Certified Incident Handler (GCIH)

01-2021

Critical Controls Certification (GCCC)

06-2020
Cybersecurity Defense Officer - Banque Saudi Fransi
05.2019 - 03.2021
Information Security Analyst - IT Security Training & Solutions - I(TS)²
05.2019 - 09.2019
Summer Training - CIT's Wing At King Abdullah's Airbase
06.2017 - 08.2017
King Abdulaziz University - Bachelor Of Science, Information Systems
02.2013 - 05.2018

Courses

Attended in multiple cybersecurity and management courses:


  • Technology trainings (e.g. ArcSight, Ixia, Guardium, Splunk, Kaspersky, Group-IB, etc.).
  • Leadership and Management courses (e.g. Leadership and Innovations, Negotiations, SMART OKRs, Cybersecurity Management, etc.).
  • Cybersecurity courses such as SANS (SEC401, FOR500, FOR508, FOR572, FOR578, SEC504, SEC566, FOR608, FOR610, FOR509). Other security courses (e.g. Kaspersky IR & DF, Linux, Cyber-Crimes, UEBA, etc.).
Abdulaziz AlsurayaCybersecurity Team Lead