Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Timeline
Generic

Islam Elzayat

Delivery Assurance Director
Riyadh,01

Summary

Strategic IT and Cybersecurity Leader with over 16 years of experience driving transformation across IT Governance, Compliance, and Cybersecurity. Proven record of managing large-scale, complex projects and delivering impactful results in both consulting and industry settings, including extensive experience with public sector entities. Skilled in designing and implementing IT frameworks and standards to enhance organizational resilience, improve performance, and meet regulatory requirements. Recognized as a subject matter expert in IT auditing, risk assessment, and governance, adept at fostering high-performing teams, cultivating client relationships, and ensuring sustained impact through continuous improvement and knowledge transfer. Strong communication and problem-solving abilities with a commitment to client satisfaction, fluent in both English and Arabic, and prepared to support Vision 2030 with on-the-ground expertise in Saudi Arabia.

Overview

13
13
years of professional experience
11
11
years of post-secondary education
13
13
Certifications

Work History

Digital Transformaiton, Cybersecurity Practice Lea

Devoteam Middle East
03.2023 - Current
  • Mentored junior team members, providing guidance on best practices, industry trends, and career development opportunities.
  • Contributed to the development of industry best practices by actively participating in professional organizations, attending conferences, and keeping abreast of new research findings.
  • Fostered a culture of innovation within the team by encouraging brainstorming sessions, experimentation with new techniques or tools, and sharing successes and learnings openly.
  • Consistently exceeded revenue targets by effectively managing financial resources and optimizing service offerings.
  • Strategic Consulting: Provided strategic guidance to clients regarding ITIL practices, ISO/IEC 20000 implementation, and Governance, Risk, and Compliance (GRC).
  • Project Leadership: Directed and managed a team of consultants, ensuring timely delivery of project milestones, adherence to specified requirements, and consistent communication with stakeholders.
  • ISO/IEC 20000 Implementation: Led the end-to-end implementation of the ISO/IEC 20000 standard, providing oversight and ensuring alignment with organizational objectives and IT service management best practices.
  • GRC Framework Development: Directed the creation and deployment of robust Governance, Risk, and Compliance frameworks tailored to client needs. Implemented strategies to address potential risks, ensuring compliance with regulatory standards.
  • Continuous Improvement: Conducted post-implementation reviews, gathering feedback and identifying areas for further enhancement. Championed the iterative refinement of processes to ensure superior service delivery.
  • Training & Development: Organized and led training sessions for internal teams and clients on ITIL processes, ISO/IEC 20000 standards, and GRC best practices.
  • Collaboration: Worked closely with cross-functional teams including IT, operations, legal, and finance to ensure a holistic approach to IT service management and GRC.

Key Projects and Achievements:

  • Internal Auditing at Alrajhi Bank: Currently serving as the Internal Auditor, rigorously evaluating the effectiveness of the Essential Cybersecurity Controls (ECC) and SAMA IT Governance frameworks, CSF within Alrajhi Bank, enhancing governance, Cybersecurity and compliance measures.
  • Asset Management Lifecycle Development for Ministry of HRSD: Developed a comprehensive asset management lifecycle process for the Ministry of Human Resources and Social Development (HRSD), optimizing asset utilization and lifecycle management.
  • IT Strategy and Operating Model for Confidential Sector: Formulated and executed a robust IT strategy and operating model tailored for one of the most sensitive sectors, enhancing operational security and efficiency.
  • Internal Audit Preparation for NWC: Prepared and facilitated the internal audit for ISO/IEC 20000 compliance, ensuring adherence to international standards at the National Water Company (NWC).
  • SAMA Framework Development for Vision Bank: Spearheaded the creation of a comprehensive IT governance framework in alignment with the Saudi Arabian Monetary Authority's (SAMA) regulatory standards, significantly advancing Vision Bank's strategic objectives.
  • Digital Transformation for Saudi Tanmiah Program: Pioneered a digital transformation operating model, paving the way for modernized IT governance and streamlined processes within Saudi Arabia's Tanmiah initiative.
  • ISO/IEC 20000 Implementation at Ministry of Transportation: Directed the successful implementation and certification of the ISO/IEC 20000 standard, demonstrating excellence in IT service management practices within the ministry.

Client Manager - Information Security Auditor

BSI
10.2021 - Current
  • Manage portfolio of assigned clients based on location and match of qualifications and client contract requirements
  • Responsible for contacting clients and scheduling visits, planning ISO assessments, making travel plans, conducting assessments and reporting and managing results
  • Monitor client accounts to ensure that records, Point Global information, visit cycle, invoicing and other related matters are properly dealt with to assure client satisfaction is maintained
  • Lead teams, mentor and coach new or inexperienced colleagues as needed to meet business needs
  • Participate in additional training based on future business needs
  • Built client relationships by responding to inquiries, identifying and assessing clients' needs, resolving problems, and following up with potential and existing clients.
  • Closed average of 45 Audit days each quarter

3rd Party IT Auditor

PECB MS
01.2020 - 10.2021
  • Identified control gaps in processes, procedures and systems through in-depth research and assessment and suggested methods for improvement.
  • Responsible for analyzing and assessing company's technological infrastructure to ensure processes and systems run accurately and efficiently while remaining secure and meeting compliance regulations and standards.
  • Process Auditing: examines current technology in organization and future technologies that will need to be adopted.
  • Participated in interviews, performed observations and evaluated pertinent information to supplement audit findings.
  • Conducted compliance audits with ISO 9001, ISO 27001, ISO 20000 Standards.

ITSM Configuration Auditor

SAUDI TELECOM COMPANY (STC) ⎯ Riyadh, Saudi Arabia
10.2016 - 10.2018
  • Oversee all CMDB auditing stages, including planning, scheduling and performing audits to validate IT infrastructure; and provide documentation and reporting, demonstrating compliance in scope solutions.
  • Internal Audits ISO 20000, ISO 27001, Support internal and external ISO audits ; Documentations Management (review, update, control) ; Support preparation of awareness program, conduct awareness sessions ; Minimizes IT risk with better understanding of impacts.
  • Configuration Management Database Auditing: Audit (CMDB) using BMC Remedy 7.6 and 9.1, including CMDB process design; Participated in Change (CAB) and Release board meetings.
  • Developed and implemented performance improvement strategies and plans to promote continuous improvement.

ITSM Consultant

QYADAT⎯ Riyadh, Saudi Arabia
06.2015 - 09.2016
  • Maintained SMS requirement for ISO 20000 and designed all CMDB auditing stages, including planning, scheduling and performing audits to validate IT infrastructure; and provide documentation and reporting, demonstrating compliance in scope solutions.
  • Internal Audits: Audit configuration management database (CMDB) using Microsoft Service Manager.
  • Quality Standards: Reviewed 26 ITIL processes and maintained ITIL design processes in line with ISO 20000 standards.
  • Reviewed and assessed architecture design, implementation, testing and deployment needs to identify project requirements and costs.

Systems Analyst

IMZ WEB
05.2012 - 05.2015
  • Configured and provided operational and technical support for applications, resolving technical problems and application performance issues; and supported optimization and enhancement efforts.
  • Defined system requirements, determining priorities and gathering design documents and dataflow diagrams.
  • Managed and tracked requirements' status throughout project lifecycle, ensuring all user stories aligned with project requirements and specifications.
  • Supervised 20+member team of Systems Analysts; and liaised with stakeholders, communication project stages, and gathering business requirements.
  • Systems Analysis: Performed troubleshooting and analysis of reported issues, identifying root cause and determining resolution, and translated explanation into actionable items.

Education

Interdisciplinary Studies - Information Technology - Cybersecurity

University of New Brunswick
Fredericton, NB
05.2019 - 10.2021

MBA - Project Management

ARAB ACADEMY FOR Science, AND TECHNOLOGY
Egypt
05.2013 - 06.2015

Bachelor of Engineering - Electrical And Computer Engineering

Arab Academy For Science And Technology
Cairo, Egypt
09.2002 - 07.2009

Skills

Consulting Skills

Auditing Skills

Organizational Development

Innovation management

People Management

Performance Management

Coaching

Client Relationship

Accomplishments

  • Completed 120+ Audit-days third-party Audits with PECB-MS and Bsi North America.
  • Support in getting the Ministry of Labor in Saudi Arabia Certified ISO 20000 /ISO 27001.
  • Maintained Saudi Telecom Company compliance with ISO 20000 and ISO 27001 standards.
  • Trained more than 250+ on ITIL Foundation, ISO and Intermediate.
  • Successfully get 8+ IT Compliance Projects delivered within the scope, cost, and time.

Certification

ITIL Master

Timeline

ITIL Master

10-2024

AIMS ISO/IEC 42001 Lead Implementer

04-2024

Digital Transformation Officer

11-2023

GRC Professional Certification

10-2023

Digital Transformaiton, Cybersecurity Practice Lea

Devoteam Middle East
03.2023 - Current

ISO/IEC 38500 Lead IT Corporate Governance Manager

03-2023

ISO 22301 Business Continuity Management Systems

10-2022

Client Manager - Information Security Auditor

BSI
10.2021 - Current

ISO/IEC 20000 IT Service Management Lead Auditor

08-2021

CISA

07-2021

ISO/IEC 27001 Lead Auditor (PECB)

12-2020

3rd Party IT Auditor

PECB MS
01.2020 - 10.2021

Interdisciplinary Studies - Information Technology - Cybersecurity

University of New Brunswick
05.2019 - 10.2021

COBIT 5

02-2017

ITSM Configuration Auditor

SAUDI TELECOM COMPANY (STC) ⎯ Riyadh, Saudi Arabia
10.2016 - 10.2018

ISO/IEC 9001 Lead Auditor

03-2016

ITSM Consultant

QYADAT⎯ Riyadh, Saudi Arabia
06.2015 - 09.2016

MBA - Project Management

ARAB ACADEMY FOR Science, AND TECHNOLOGY
05.2013 - 06.2015

Systems Analyst

IMZ WEB
05.2012 - 05.2015

Microsoft Certified Trainer (MCT)

01-2011

Bachelor of Engineering - Electrical And Computer Engineering

Arab Academy For Science And Technology
09.2002 - 07.2009

NSE2 Network Security Associate

Islam ElzayatDelivery Assurance Director