Over 18 years of experience in Information and Cybersecurity, specializing in IT Risk and Governance Management, IT Audit and Compliance, and IT Software Quality Assurance. Proven track record of enhancing organizational security posture and ensuring compliance with industry standards. Expertise in leading teams to achieve high-performance outcomes and drive continuous improvement initiatives.
· Engagement manager and project delivery lead for cybersecurity projects:
~ Developed the Technical and commercial Proposal and presentations w.r.t client requirements.
~ Actively participated and engaged on engagement letter for the project engagement with clients.
~ Actively participated and engaged on project scope of work (SOW) and Master service agreement.
~ Developed the project charter, project plan and kick-off meeting presentation.
~ Developed the weekly project status report for client status meeting.
~ Actively engaged with senior management in the project status tracking report and supported in their decision by developing the project status reports.
~ Performed project management and team management activities for on-time delivery of the tasks.
~ Drive and lead the Cybersecurity Maturity Assessment (CMA) as per industry best practices (NCA, NIST and ISO 27001 ISMS) and presented & delivered the CMA report to the stakeholders.
~ Drive and lead the NCA: ECC, CSCC, DCC, TCC, CCC, OSMACC, SAMA CSF and ISO/IEC 27001 ISMS and TISAX standards implementation and compliances assessment. Developed, presented & delivered the compliance dashboard and reports to the stakeholders.
~ Drive and lead the development of Cybersecurity Strategy and Target Operating Model (TOM).
~ Drive and lead Cybersecurity risk assessment as per SAMA CSF, NCA: ECC, CSCC, DCC, TCC, CCC, OSMACC and ISO/IEC 27001 ISMS standards.
~ Drive and lead the development, enhancement and review of Job description for Cybersecurity workforce as per industry best practices (NCA, NIST and ISO 27001)
~ Create, review, and enhanced the documentations as per SAMA CSF, NCA, NIST and ISO 27001 standards.
~ Performed cyber security risk assessment on a scope of information technology systems &/ business process. Scheduling, conducting, and tracking risk assessment activities with the stakeholders.
~ Developed threat & vulnerability database, risk control sheet, risk register and risk report.
~ Review and approval of risk report with stakeholders.
~ Preparation for a senior management and stakeholders presentation monthly, for the high-level progress, risk identified and related enterprise recommendation as applicable.
~ Actively participated and engaged on ISMS implementation and certification accreditation.
~ Developed and reviewed the policies, procedure, standard, ISMS management review, cybersecurity committee Charter, Training plan/materials and Statement of Applicability (SOA), Master list of documents and policies compliance review activity plan & checklist.
~ Actively participated and engaged on tabletop exercise (TTX) and supported senior management in delivering the cyber crisis-ransomware report.
~ Developed the cybersecurity KPI and KRIs measurement matrix based on cybersecurity risk landscape mapping SAMA, ISO 27001 and NCA framework.
~ Developed ISMS Internal Audit program, Audit report, Action plan for any observations raised during the Pre-certification audit and External Certification Audit Support
~ Developed Cybersecurity awareness and trainings program plans / materials / records to minimize information security incidents.
Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), ISO27001 Lead Auditor Certification, ISO 22301 Lead Auditor Certification, ITIL Foundation (V3) Certification, Management Development Program, Supervisory Skills Development Program, Self-Development and Team Building Program, Effective Meetings and Communication, Emotional Intelligence Skills: Self-awareness Management, Leading Teams: Dealing with Conflict