Summary
Overview
Work History
Education
Skills
Software
Certification
Achievements
Interests
Timeline
Generic

Hesham Alsuwilem

Cybersecurity Risk Management
Saudi Arabia - Riyadh

Summary

Passionate about establishing a committed strategy for designing and implementing cybersecurity controls and processes to meet cybersecurity regulations and business objectives. Practical experience in building and implementing security solutions in accordance with the SAMA/NCA Framework. Competent in Cybersecurity Risk Management.

Overview

2026
2026
years of professional experience
4
4
years of post-secondary education
21
21
Certifications
2
2
Languages

Work History

Cyber Risk Team Lead

Confidential
Riyadh, Riyadh Region
12.2023 - Current

#Cyber Security Risk Management:

Acting as Risk Manager, assisting the Director of the GRC Department in establishing and executing Cybersecurity Risk Dept. in terms of both risk governance and technical development to achieve organizational objectives.

#Responsibility:

- Risk Management:

  • Building a Risk Management Strategy.
  • Building a Cyber Security Risk Management Framework.
  • Building a Cyber Security Risk Management Methodology.
  • Building a Risk Management Criteria.
  • Building a Risk Management Appetite and Tolerance.
  • Building an intelligent/dynamic Cybersecurity Gap Assessment tool to assess the organization's cybersecurity readiness and current risk posture, and which threat may be affected based on MITRE ATT&CK®.
  • Building Cyber Risk Register.
  • Building Change Management Processes.
  • Building an automated tool for risk assessment in change management.
  • Develop risk assessments for different scenarios and phases.
  • Develop an automated mathematical formula to reclassify vulnerabilities according to several internal criteria, similar to the worldwide rating CVSS.
  • Conduct +80 Cyber Risk Assessments.
  • Conduct Cyber Gap Assessments.
  • Managed risks and mitigated potential issues through proactive planning, monitoring, and timely decisionmaking.

- Oversee Technical Functions of Risk Management:

  • Vulnerability Management.
  • Penetration Testing.
  • Security Source Code Review.
  • Security Configurations Review.

Senior Consultant, VAPT

Technology Control Company Limited (tcc)
Riyadh, Riyadh Region
2 2022 - 11.2023

#Responsibility:

- Red Teaming:

  • Advanced Technologies such as Breach and attack simulation (BAS) to validate cyber defense controls.

- Penetration Testing and Source Code Review activities periodically:

  • Static application security testing (SAST).
  • Dynamic application security testing (DAST).

- Vulnerability Management:

  • Lead the VM team.
  • Redesigned the VM architecture to be more compatible with the facility environment to achieve better performance, feasibility, and vulnerability outcomes.

PInformation Security Officer/pp/p

Al-Amthal Financing Co.
07.2020 - 02.2022

I had started the Cybersecurity operation unit, I’ve been assigned to take the lead for executing from scratch, operating, and administrating the below Cybersecurity control solutions:
- Vulnerability Management (VM).
- Privileged Access Management (PAM).
- Multi-Factor Authentication (MFA).
- Identity and Access Management (IAM).
Moreover, I was Managing a Penetration Testing and Configuration Review engagement.

Backend Software Engineer Trainee

Elm Company - Absher Division.
02.2020 - 06.2020

I worked as an assistant to a software engineer on projects related to developing Absher system services that are provided to citizens and residents.

Education

Bachelor of Science - Information Technology

College OfComputer And Information Sciences At Imam Muhammed Ibn Saud Islamic University
Riyadh
09.2016 - 05.2020

Graduation Project:  Sentiment Live: Measure The Public SatisfactionBased On Sentiment Analysis of Arabic Tweets. 
08.2019 - 04.2020

Skills

Risk Assessment

Gap Assessment

Change Management

Technical Expertise

Footprinting & Scanning

Vulnerability Assessment

Data Exfiltration

Python

Swift

Java

JSF Framework

Software

Wireshark

Immunity Debugger

Burp Suite

Nmap

Nessus

DirBuster

Sqlmap

Metasploit

Xcode

PyCharm

AttackIQ

Fortify WebInspect DAST (Dynamic Application Security Testing)

Fortify SCA (Static Code Analyzer)

Archer GRC tool

Certification

Information Security Awareness.

Achievements

Interests

Vulnerability Management

Multi-factor Authentication (MFA)

Managing a Penetration Testing engagement with an out-sourcing company

Privileged Access Management (PAM)

Identity and Access Management (IAM)

Data loss prevention (DLP)

Data Classification

Timeline

IS2 CISSP - Certified Information Systems Security Professional.

02-2025

SANS LDR514: GIAC Security Strategic Planning, Policy and Leadership.

07-2024

ISACA CISA - Certified Information Systems Auditor (CISA)

04-2024

Cyber Risk Team Lead

Confidential
12.2023 - Current

PECB - ISO/IEC 27001 Lead Implementer.

04-2023

NCA: CTF exercise.

11-2022

Alert Triage with Trellix Malware Analysis.

08-2022

NCA: VAPT - Technical Cyber Security Exercise

08-2022

WAPT - eLearnSecurity Web Application Penetration Tester Course.

12-2021

Qualys Vulnerability Management Detection & Response (VMDR).

10-2021

Privileged access management (PAM) solution - Administration Training of One Identity Safeguard Product .

09-2021

eCPPTv2 - eLearnSecurity Certified Professional Penetration Tester.

07-2021

Multi-Factor Authentication solution - Administration Training of One Identity Defender Product .

06-2021

Vulnerability Management - Tenable.sc Scanning and Analysis .

12-2020

Vulnerability Management - Tenable.sc View Event Analysis and Reporting.

12-2020

PInformation Security Officer/pp/p

Al-Amthal Financing Co.
07.2020 - 02.2022

eJPT - eLearnSecurity Junior Penetration Tester

06-2020

Backend Software Engineer Trainee

Elm Company - Absher Division.
02.2020 - 06.2020

Security+.

09-2019

Graduation Project:  Sentiment Live: Measure The Public SatisfactionBased On Sentiment Analysis of Arabic Tweets. 
08.2019 - 04.2020

iOS App Development Bootcamp using : AI , AR.

07-2019

Cybersecurity- Future Challenge & Network Defenses.

03-2019

Linux.

03-2019

Google cloud : DevRel Study Jams/TOT.

01-2019

Information Security Awareness.

01-2018

Bachelor of Science - Information Technology

College OfComputer And Information Sciences At Imam Muhammed Ibn Saud Islamic University
09.2016 - 05.2020

Senior Consultant, VAPT

Technology Control Company Limited (tcc)
2 2022 - 11.2023
Hesham AlsuwilemCybersecurity Risk Management