Summary
Overview
Work history
Education
Skills
Certification
Timeline
Generic

Bandar Al Ahmadi

Saudi Arabia

Summary

I’m Bandar, a Managing Consultant at IBM with over 5 years of experience and a master’s degree in Cybersecurity. I’m interested in managing IT and security infrastructures to help organizations build secure and resilient environments.

I have experience across multiple services and areas, including Incident Response, Proactive Services (Incident Preparedness), SOC operations, MDR, MSSP, and Consultancy. In my current role, I lead IR and Proactive Service engagements and act as the Global TTX Service Lead for NA, APAC, and EMEA

Overview

6
6
years of professional experience
1
1
Certification

Work history

Managing Incident Response Consultant, X-Force IR

IBM
, Saudi Arabia
08.2025 - Current

Leading Incident Response engagements from scoping and delivery to reporting, closure, and lessons learned.
Leading and supporting triage calls through the XFIR Global Hotline.
Leading proactive service engagements including initiation, scoping, delivery, reporting, closure, and lessons learned.
Globally leading Tabletop Exercise (TTX) services across three regions: NA, APAC, and EMEA.
Developing Incident Response Plans.
Developing Cybersecurity Crisis Management Plans.
Supporting multiple proactive services such as Active Threat Assessments, Cyber Range Experiences, Cyber Wargames, Security First Responder Training.
Acting as the account owner for 10+ clients, acting as the primary point of contact, leading kickoff calls, and conducting quarterly reporting calls, addressing client concerns, managing retainer hours, driving proactive services discussions, and building strong, long-term client relationships.

Senior Incident Response Consultant, X-Force IR

IBM
, Saudi Arabia
01.2024 - 08.2025

Lead Incident Response and Proactive Service engagements.

SOC L3 Analyst (Acting) Technical Lead, X-Force TM

IBM
, Saudi Arabia
07.2023 - 12.2023

Lead technical investigations, perform root cause analysis, and handle alerts escalated by L1/L2 analysts.
Develop SOC processes and playbooks.
Conduct quality checks and review closing reasons, TTD, TTR, false-positive rates, and other key performance metrics.
Deliver knowledge-sharing sessions and mentor junior analysts to enhance team capability.

SOC L2 Analyst, X-Force Threat Management

IBM
, Saudi Arabia
12.2022 - 12.2023

Investigate and respond to security incidents across SIEM, EDR, NTD, XDR, SOAR, and other security controls.
Handle alerts escalated by L1 analysts and ensure accurate triage and response.
Communicate with clients regarding security concerns, incident status, and recommendations.
Respond to incidents requiring digital forensics, malware analysis, and reverse engineering.
Actively hunt for adversaries, perform continuous IOC sweeps, and identify emerging threats.
Review threat reports and contribute to rule development and refinement.
Build, tune, and validate EDR detection rules to improve detection quality.

Professional Engineer, MDR Services (SOC)

Saudi Information Technology Company (SITE)
, Saudi Arabia
01.2022 - 12.2022

Worked as a security operations analyst at the Managed Detection and Response Center, which delivers premium MDR services to tens of subscribed clients from various sectors.

Engineer, Security Operation Center

Saudi Information Technology Company (SITE)
, Saudi Arabia
09.2020 - 01.2022

Investigate and respond to security incidents.
Build, tune, and validate EDR rules.
Utilize SIEM, EDRs, NTD, and SOAR platforms.
Actively hunt for adversaries on the network.
Conduct malware analysis and reverse engineer malware.
Perform digital forensics.

Cyber Security Intern

Saudi Information Technology Company (SITE)
, Saudi Arabia
12.2019 - 09.2020

Education for Employment (E4E)
Completed a 9-month intensive Cybersecurity Program that included job training and more than 15 courses and certifications across multiple IT domains, including networking, infrastructure, cybersecurity, SIEM, endpoint detection and response, network threat detection, and cyber threat intelligence.

Education

Master of Science - Cybersecurity

King Saud University
Saudi Arabia
/2022 - /2024

Bachelor of Science - Information Systems

King Abdulaziz University
Saudi Arabia
/2015 - /2019

Skills

  • Incident Preparedness
  • Proactive Services
  • Incident Response
  • SOC Operations
  • Digital Forensics & Malware Analysis
  • Consultancy
  • Communication & Presentation
  • Collaboration & Team Support
  • Service Delivery Management
  • Client Relationship Management

Certification

  • Certified Information Security Manager CISM (ongoing)
  • Harvard VPAL Cybersecurity: Managing Risk in the Information Age, 2 months program
  • eCRE, eLearn Security Certified Reverse Engineer
  • eCMAP, eLearn Security Certified Malware Analysis Professional
  • eCTHP, eLearn Security Threat Hunting Professional,
  • eCDFP, eLearn Security Certified Digital Forensics Professional
  • eCIR, eLearn Security Certified Incident Response
  • MCSE, Microsoft Certified solution Expert
  • Certified Associated in project management, PMI
  • CompTIA CSA+
  • CompTIA Security+
  • RHCSA, Red hat Certified System Administrator
  • CCNA Routing and Switching
  • CCNA Cyber ops

Timeline

Managing Incident Response Consultant, X-Force IR

IBM
08.2025 - Current

Senior Incident Response Consultant, X-Force IR

IBM
01.2024 - 08.2025

SOC L3 Analyst (Acting) Technical Lead, X-Force TM

IBM
07.2023 - 12.2023

SOC L2 Analyst, X-Force Threat Management

IBM
12.2022 - 12.2023

Professional Engineer, MDR Services (SOC)

Saudi Information Technology Company (SITE)
01.2022 - 12.2022

Engineer, Security Operation Center

Saudi Information Technology Company (SITE)
09.2020 - 01.2022

Cyber Security Intern

Saudi Information Technology Company (SITE)
12.2019 - 09.2020

Master of Science - Cybersecurity

King Saud University
/2022 - /2024

Bachelor of Science - Information Systems

King Abdulaziz University
/2015 - /2019
Bandar Al Ahmadi