Summary
Overview
Work History
Education
Skills
Audit Committee Memberships
Certification
Professional Training
Timeline
Generic
Bader AL-Mazroa

Bader AL-Mazroa

Internal Audit General Manager
Riyadh

Summary

Audit Committee Member and Internal Audit Executive with over 20 years of leadership in risk management, regulatory compliance, corporate governance, technology, cybersecurity, and data privacy. Demonstrated expertise in establishing and leading high-performing audit and GRC functions, driving operational excellence, and strengthening internal controls across complex and highly regulated environments. Recognized as a strategic technology leader with deep expertise in aligning digital transformation initiatives with business goals, enhancing enterprise resilience, and supporting executive decision-making through data-driven insights. A trusted advisor with active roles in steering governance frameworks and ensuring accountability, transparency, and long-term value creation.

Overview

24
24
years of professional experience
2
2
Certifications
2
2
Languages

Work History

General Manager Corporate Support Units Audit

stc
01.2023 - Current
  • Audit of the following units: Legal, Risk, Compliance, Governance, strategy, sustainability, shared services, HR, Business continuity.

General Manager Technology Audit

stc
Riyadh, Riyadh Region
10.2017 - 12.2022
  • Audit of the following units: Information technology, Core network, Wireless Network, Cyber security, Data Governance and Privacy.

Director Infrastructure Design and implementation

stc
11.2015 - 10.2017
  • Manage the design and implementation of internal infrastructure including servers, storage and private cloud.

Director IT Security

stc
01.2012 - 11.2015
  • Manage the design, implementation and operation of IT security solutions and controls.

Director Data Network Services

stc
01.2009 - 12.2011
  • Manage the design and implementation of data network services.

Section Manager Network implementation

stc
11.2007 - 12.2008
  • Manage the implementation of data network services.

Project Manager IT security project manager

stc
01.2001 - 10.2007
  • Implement IT security project and services.

Education

Bachelor of Computer And Information Science - Information Systems

King Saud University
Riyadh, Saudi Arabia
04.2001 -

Skills

  • Audit Management

  • Governance

  • Risk Management

  • Compliance

  • Development & leadership

  • Visionary Technology Leadership

  • Strategy development & Execution

  • Digitization

  • Stress Management

  • Business Process Re-engineering

  • Planning & Budgeting

  • Successful negotiation

  • Team building

  • Resilience and Crisis Management

  • Client & relationship Management

  • Program & Project Management

Audit Committee Memberships

  • The Saudi Investment Bank (SAIB)
  • TAWAL
  • Sirar by stc
  • Intigral
  • AQALAT
  • stc Smart Zone

Certification

ITIL (Information Technology Infrastructure Library)

Professional Training

Governance & Internal Audit:

Certified Internal Auditor (CIA Part1 & Part2), Certified Risk Based Audit, Code of Ethics and Rules of Conduct, Understanding Board Committees workshop, Information Security Management Systems introduction Course, Information Security Management Systems Internal auditor Course, Introduction to ISO/IEC27002 ISMS, ISO/IEC27001 Internal Auditor, IFRS for Senior Executives.

Leadership & Management:

 IT Project Management, PM Framework & Processes For Project Managers & Project Teams, Advanced Project management (PMBOK 3rd Edition), Microsoft Project Enterprise, Teamwork building & management, Planning & execution, Strategy, Risks, Negotiation & Leadership, Effective management, Strategic thinking & Visionary leadership, Feasibility studies, Culture Journey Leadership Readiness, Emotional intelligence Management, Developing People & Teams, Developing Executive Leadership Skills, Improving your project management skills, Strategy implementation for leaders.

Technology and Cyber Security:

Symantec ESM & ITA, Advanced Enterprise Implementation & Rollout, Symantec Enterprise Security Manager, Symantec Intruder Alert 3.6, Symantec Hacking Exposed, Managing Cisco Network Security (MCNS), Cisco Secure PIX Firewall Advanced (CSPFA), PKI, Entrust Authority Bootcamp, RSA SecurID Administration 5.1, RSA SecurID Installation and Configuration 5.1, Introduction to System and Network Security, Certified Information Systems Security Professional (CISSP), Encase Incident Response, Forensic Analysis And Discovery, Foundations of ACL concepts And Practices, ACL data analysis and Techniques, Securing wireless Networks, IP Cyber Security, Big data and advanced analytics.

Timeline

General Manager Corporate Support Units Audit

stc
01.2023 - Current

General Manager Technology Audit

stc
10.2017 - 12.2022

Director Infrastructure Design and implementation

stc
11.2015 - 10.2017

Director IT Security

stc
01.2012 - 11.2015

Director Data Network Services

stc
01.2009 - 12.2011

Section Manager Network implementation

stc
11.2007 - 12.2008

Bachelor of Computer And Information Science - Information Systems

King Saud University
04.2001 -

Project Manager IT security project manager

stc
01.2001 - 10.2007
Bader AL-MazroaInternal Audit General Manager