Summary
Overview
Work history
Education
Skills
Certification
Accomplishments
Languages
Personal Information
Timeline
Generic

IQBAL MOHAMMED

Riyadh,Saudi Arabia

Summary

Over 18 years of experience in Information and Cybersecurity, specializing in IT Risk and Governance Management, IT Audit and Compliance, and IT Software Quality Assurance. Proven track record of enhancing organizational security posture and ensuring compliance with industry standards. Expertise in leading teams to achieve high-performance outcomes and drive continuous improvement initiatives.

Overview

20
20
years of professional experience
6
6
years of post-secondary education
1
1
Certification

Work history

Manager, Cybersecurity Advisory

KPMG
Riyadh, KSA
01.2022 - 08.2025

· Engagement manager and project delivery lead for cybersecurity projects:

~ Developed the Technical and commercial Proposal and presentations w.r.t client requirements.

~ Actively participated and engaged on engagement letter for the project engagement with clients.

~ Actively participated and engaged on project scope of work (SOW) and Master service agreement.

~ Developed the project charter, project plan and kick-off meeting presentation.

~ Developed the weekly project status report for client status meeting.

~ Actively engaged with senior management in the project status tracking report and supported in their decision by developing the project status reports.

~ Performed project management and team management activities for on-time delivery of the tasks.

~ Drive and lead the Cybersecurity Maturity Assessment (CMA) as per industry best practices (NCA, NIST and ISO 27001 ISMS) and presented & delivered the CMA report to the stakeholders.

~ Drive and lead the NCA: ECC, CSCC, DCC, TCC, CCC, OSMACC, SAMA CSF and ISO/IEC 27001 ISMS and TISAX standards implementation and compliances assessment. Developed, presented & delivered the compliance dashboard and reports to the stakeholders.

~ Drive and lead the development of Cybersecurity Strategy and Target Operating Model (TOM).

~ Drive and lead Cybersecurity risk assessment as per SAMA CSF, NCA: ECC, CSCC, DCC, TCC, CCC, OSMACC and ISO/IEC 27001 ISMS standards.

~ Drive and lead the development, enhancement and review of Job description for Cybersecurity workforce as per industry best practices (NCA, NIST and ISO 27001)

~ Create, review, and enhanced the documentations as per SAMA CSF, NCA, NIST and ISO 27001 standards.

~ Performed cyber security risk assessment on a scope of information technology systems &/ business process. Scheduling, conducting, and tracking risk assessment activities with the stakeholders.

~ Developed threat & vulnerability database, risk control sheet, risk register and risk report.

~ Review and approval of risk report with stakeholders.

~ Preparation for a senior management and stakeholders presentation monthly, for the high-level progress, risk identified and related enterprise recommendation as applicable.

~ Actively participated and engaged on ISMS implementation and certification accreditation.

~ Developed and reviewed the policies, procedure, standard, ISMS management review, cybersecurity committee Charter, Training plan/materials and Statement of Applicability (SOA), Master list of documents and policies compliance review activity plan & checklist.

~ Actively participated and engaged on tabletop exercise (TTX) and supported senior management in delivering the cyber crisis-ransomware report.

~ Developed the cybersecurity KPI and KRIs measurement matrix based on cybersecurity risk landscape mapping SAMA, ISO 27001 and NCA framework.

~ Developed ISMS Internal Audit program, Audit report, Action plan for any observations raised during the Pre-certification audit and External Certification Audit Support

~ Developed Cybersecurity awareness and trainings program plans / materials / records to minimize information security incidents.

Snr. Consultant – Cybersecurity GRC

AESSCO
Riyadh, KSA
03.2020 - 12.2021
  • Client#1: Princess Noura University (PNU)
  • Client#2: Ministry of Defense, Riyadh Saudi Air Force (RSAF)
  • Maintained integrated management system (NIST SP.800-53 R4, ISO 27001, NCA ECC, CSCC and ISO 22301) certification accreditation status for the client.
  • Conducted IT Security Audit at client site w.r.t ISO27001, ISO 22301 certification.
  • Information security audit management (external and internal audits). Develop and rollout of annual Information security roadmap and audits plans.
  • Developed NIST, ISMS and BCMS policies, standards, procedures, and guidelines to ensure the protection of confidential, integrity and availability of information.
  • Developed and conducted developed formal process system for business impact analysis, business continuity plan and test, IT security incident and changes management, etc.
  • Identifying and exploring new security trends and performing quality review, RFP, vendor evaluation, cost benefit analysis of latest security tools in the market.
  • Information security metrics reporting to support key decision makers.
  • Project lead for all IT security projects Key projects: IT Risk management, ISMS management review program, IT security incident management and compliance management.
  • IT business continuity plan (BCP) drill test, Tabletop exercise (TTX), report results and follow-up action points.
  • Information security controls assessment for to meet the company requirements.
  • IT security audit management (external and internal audits)
  • IT security audit, assessment, and compliance management for information security controls.
  • Information security awareness and trainings program plans/ records to minimize information security incidents.
  • Developed and lead information system audit (data center, firewall, routers, wi-fi, network and remote access control, active directory, servers, antivirus compliance, privileged users access control, etc.) management.

Consultant - IT Security and Compliance

alfanar
Riyadh, KSA
06.2015 - 03.2020
  • Maintained integrated management system (ISO 27001, ISO 22301, ISO 20000) certification accreditation status.
  • Developed and implemented integrated management system (IMS) policies, standards, and procedures to ensure the protection of confidential, integrity and availability of information.
  • Developed and conducted developed formal process system for business impact analysis, business continuity plan and test, IT security incident management, IT changes management, IT service catalogue, IT service improvement plan, IT customer satisfaction survey etc.
  • Project lead for all IT security projects Key projects: IT Risk management, IMS management review program, Vulnerability assessments and penetration tests (VAPT), IT security incident management, SIEM management, legal and compliance management.
  • Data classification, Rights management, and Data leakage prevention program.
  • IT business continuity plan (BCP) drill test, report results and follow-up action points.
  • Information security controls audit and assessment on vendor site for to meet the company outsourcing requirements.
  • IT security audit management (external and internal audits)
  • IT security audit, assessment and compliance management for firewall, routers, antivirus, wi-fi, data center, active directory, servers, and system security patches, privileged user access control, etc.
  • Information security awareness and trainings and phishing campaign to minimize information security incidents.
  • Subscribed to information security forums/bulletins/tips to be updated in latest information security and cyber security threats.

Sr. Software Engineer, Security Domain

C.A Technology
Hyd, India
03.2014 - 06.2015
  • Analysed functional requirements to ensure compliance with information security and software quality standards.
  • Executed product certification across various platforms, including Windows and UNIX.
  • Developed and reviewed test plans, conditions, scenarios, and cases using HP Quality Center.
  • Conducted multiple testing types, such as functional, regression, installation, and stress testing.
  • Tracked issues and generated reports using RTC tool for effective resolution management.
  • Managed virtual machines on VMware ESX servers while supporting system activities.
  • Configured operating systems and databases for lab machines alongside MS virtual and cluster setups.
  • Facilitated product training sessions and team meetings, delivering formal reports and minutes of meetings.

Manager - Information Security

Almarai
Riyadh, KSA
06.2011 - 03.2014
  • As an Information Security Manager at Almarai, I am responsible to lead the information security team, achieving tactical and strategic information security and business objectives.
  • Maintained ISO27001 (Information Security Management System) certification accreditation status.
  • Developed and implemented Information security policies standards and procedures.
  • Project Manager for all IT security projects. Key Projects: Managed the integration of IT security and infrastructure controls and aligned information security policy, standards, procedures for Almarai new acquisition companies.
  • IT Risk management, ISMS management review program, Vulnerability assessments and penetration tests (VAPT), IT security incident management, SIEM management, legal and compliance management, Information Security Awareness and Training.
  • IT disaster recovery (DR) drill test, report results and follow-up action points.
  • Information security audit management (external and internal audits). Develop and rollout of annual Information security audits plans.
  • IT Security Infrastructure Implementation and Management (Internet security and Email Anti-spam Gateway, Enterprise Anti-Virus, Proxy, DLP, SIEM, Endpoint Encryption, Backup & Recovery tool, and Security tools).
  • Information System Audit for firewall, routers, Wi-Fi, data center, active directory, servers, antivirus compliance, privileged users access control, UNIX, etc.
  • Identifying and exploring new security trends and performing quality review, RFP, vendor evaluation, cost benefit analysis of latest security tools in the market.
  • Information security metrics reporting to support key decision makers.

Software Engineer, Security Domain

Applabs Technology (CSC)
Hyd, India
05.2005 - 06.2006
  • Analysed functional requirements to ensure project objectives were met.
  • Developed and executed comprehensive test plans, scenarios, and cases.
  • Conducted functional, regression, and stress testing for diverse applications.
  • Maintained bug tracking systems for efficient issue resolution.
  • Supported system operations throughout entire project lifecycle.
  • Installed software on Windows servers, Solaris, HP-UX, and SUSE environments.
  • Configured Active Directory, DNS, DHCP, IIS, and FTP servers.
  • Installed operating systems, databases, Citrix applications, and virtual machines on VMware.

Education

Bachelor of Computer Science - Computer Science

Osmania University
Hyderabad/India
03.1997 - 04.2000

Master’s in Computer Applications - Computer Science

Osmania University
Hyderabad/India
03.2000 - 05.2003

Skills

  • Cybersecurity operations
  • IT risk management
  • Incident response management
  • IT and Cyber audit and compliance
  • Cybersecurity awareness training
  • Identity management
  • SIEM solutions
  • Business continuity planning
  • Project coordination
  • Vendor oversight
  • Threat management
  • Vulnerability assessment
  • Team leadership
  • Software quality assurance
  • IT service management

Certification

Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), ISO27001 Lead Auditor Certification, ISO 22301 Lead Auditor Certification, ITIL Foundation (V3) Certification, Management Development Program, Supervisory Skills Development Program, Self-Development and Team Building Program, Effective Meetings and Communication, Emotional Intelligence Skills: Self-awareness Management, Leading Teams: Dealing with Conflict

Accomplishments

  • Successfully led Cybersecurity risk assessment, implementation and compliance assessment as per SAMA CSF, NCA: ECC, CSCC and ISO/IEC 27001 ISMS standards.
  • Successfully led the Cybersecurity Maturity Assessment (CMA) as per industry best practices (NCA, NIST and ISO 27001) and presented & delivered the CMA report to the stakeholders.
  • Successfully led the NCA: ECC, CSCC, DCC, TCC, CCC, OSMACC, SAMA CSF, ISO/IEC 27001 ISMS and TISAX standards implementation and compliance assessment.
  • Developed, presented & delivered the compliance dashboard and reports to the stakeholders.
  • Successfully led and maintained the ISO information security standards certification accreditation status.
  • Developed Policies, Standards, Procedures, Guidelines as per SAMA CSF, NCA: ECC, CSCC, CCC, DCC, OSMACC, TCC, NIST and ISO/IEC 27001 ISMS standards.
  • Drove and led the development of Cybersecurity Strategy and Target Operating Model (TOM) for clients.
  • Led the IT risk management with a risk register and risk treatment plan to report risk metrics.
  • Identified, developed, measured, and ensured maintenance of Information security and compliance objectives, reporting KPI and KRIs metrics to senior management.
  • Managed information security audit (external and internal audits) and developed annual Information security audits plans.
  • Conducted ISO audit at client site for ISO 27001 ISMS, ISO 22301 BCMS standard certification.

Languages

English
Hindi
Telugu

Personal Information

  • Iqama Status: Transferable
  • Date of birth: 07/30/79
  • Visa status: Transferable

Timeline

Manager, Cybersecurity Advisory

KPMG
01.2022 - 08.2025

Snr. Consultant – Cybersecurity GRC

AESSCO
03.2020 - 12.2021

Consultant - IT Security and Compliance

alfanar
06.2015 - 03.2020

Sr. Software Engineer, Security Domain

C.A Technology
03.2014 - 06.2015

Manager - Information Security

Almarai
06.2011 - 03.2014

Software Engineer, Security Domain

Applabs Technology (CSC)
05.2005 - 06.2006

Master’s in Computer Applications - Computer Science

Osmania University
03.2000 - 05.2003

Bachelor of Computer Science - Computer Science

Osmania University
03.1997 - 04.2000
IQBAL MOHAMMED