Overview
Work history
Education
Skills
Accomplishments
Additional Information
Certification
Timeline
Generic

REHAM A. ALMOHAIA

RIYADH

Overview

4
4
years of professional experience
1
1
Certification

Work history

Cyber security engineer

Security Matterz (in Government Sector)
Riyadh
09.2023 - Current
  • Penetration Test

+ Identify vulnerabilities across web, mobile, and API platforms.

+ Internal and external critical systems were tested to identify vulnerabilities and assess security posture.

+ Used manual techniques and automated tools for vulnerability discovery and exploitation.

+ Collaborated with development and security teams to prioritize fixes and validate remediation.

+ Developed detailed test plans including scope definition, attack vectors, and timelines.

+ Worked on a Penetration Testing project covering sensitive systems and applications.


  • Vulnerability Analysis by Tenable.sc.

+ Developed and implemented an annual scanning plan covering all organizational assets.

+ Scheduled regular scans and ensured scan coverage across all relevant systems.

+ Utilized YARA rules to detect and analyze malware patterns and suspicious files across systems.

+ Generated detailed vulnerability reports to support remediation efforts.

  • IAM Sailpoint IdentityIQ.

+ Analyzed business and technical requirements for identity and access management

+ Integrated with key systems (AD, HR,etc.)

+ Developed RBAC, lifecycle workflows, access policies, and lifecycle event workflows (Joiner, Mover, Leaver).

+ Managed provisioning, access reviews, and compliance

+ build system notification (SMTP, SMS).



  • Symantec DLP.

+ Deployed and configured Symantec DLP for data protection.

+ Created policies to detect and prevent sensitive data leaks.

+ Monitored incidents and fine-tuned detection rules.

+ Supported compliance and regulatory requirements (e.g., GDPR, HIPAA).


  • IBM Guardium.

+ Deployed and configured IBM Guardium for database activity monitoring.

+ Implemented policies for real-time monitoring and threat detection.

+Managed alerts, audit logs, and compliance reporting, and Integrated with key databases.













Application Developer

NATCOM (in Government Sector)
03.2021 - 09.2023

· Work Flow System | System Admin - In-house Software

+ Built more than 20 processes and workflow

+ Using BPM Tool (Ultimus).

+ Using MVC technology.

+ Using Telerik for the system report.

+ Integrated with all internal systems.

+ Dealing with more than 100 tables (SQL server).


· Communications Management System (CMS) |System Admin

+ In-house software.

+ Integrated with other government agencies through Murasalt Service.

+ Built system interfaces by vue js.


Archive System | Project Manager & System Admin



Education

Bachelor of Computer Science -

Jubail Industrial City.Imam Abdulrahman bin Faisal University
2019

Skills

  • Fast Learner
  • Leadership
  • Teamwork
  • Multitasking
  • Collaboration
  • Communication Skills
  • Problem Solving


  • Technical Skills:

  • Identity Access Management
  • Identity governance and administration
  • Scripting (PowerShell, SQL, Java)
  • Penetration testing
  • Vulnerability analysis




Accomplishments

  • Offsec web Assessor (OSWA) | Offsec - On progress.
  • Junior Penetration Tester (eJPT v2) | INE Security - Jan 2024
  • Certified Ethical Hacker (CEH v12) | EC-Council - Nov 2022
  • Information Technical Infrastructure Library( ITIL4) |ALEXON- Oct 2022

Additional Information

  • “Web Application Tester Common Tools Skill Path”, Offsec, Jan 2025.
  • “Cloud Computing Security” (5 days), National Cybersecurity Academy, Jan 2025.
  • “Fidelis Security Network & Deception” (16 hours), Fidelis Security, Dec 2024.
  • “Cortex XSOAR Automation and Orchestration” (32 hours), Paloalto ,May 2024.
  • “IBM Guardium data Protection Foundation” (3 days), STARLINK, Oct 2024.
  • "Tenable Security Center Specialist" (16 hours) .Tenable . Dec 2023.
  • "Cyber Threat Intelligence - CTI" (16 hours). National Cybersecurity Academy. Dec 2023.
  • "Penetration Test and Vulnerability Assessment - PTVA" (16 hours). National Cybersecurity Academy. Nov 2023.
  • "Digital Forensics and Incident Response - DFIR" (16 hours). National Cybersecurity Academy. Nov 2023.
  • "Attack Life Cycle" (24 hours). National Cybersecurity Academy. Oct 2023.
  • "DevOps Foundation" (16 hours) , Ministry of communications and Information Technology , Mar-2023.
  • "Certified Network Defender" (25 hours) , Ministry of communications and Information Technology , Dec-2022.
  • "Azure Cloud Fundamentals" (15 hours) , Ministry of communications and Information Technology , Dec-2022.
  • "Ethical Hacker" (25 hours) , Ministry of communications and Information Technology , Nov-2022.
  • "Information Technology Infrastructure Library (ITIL)" (20 hours) , Abad Network for training , Sep-2022.
  • "Java Programming Basics"learning path (7 hours) , Oracle University , Online – 2022

Certification

  • Arabic
  • English

Timeline

Cyber security engineer

Security Matterz (in Government Sector)
09.2023 - Current

Application Developer

NATCOM (in Government Sector)
03.2021 - 09.2023

Bachelor of Computer Science -

Jubail Industrial City.Imam Abdulrahman bin Faisal University
REHAM A. ALMOHAIA