Summary
Overview
Work history
Education
Skills
Certification
Languages
Timeline
Generic

yara abdulaziz alshiban

Summary

Highly motivated and detail-oriented, I have experience in IT Governance/Cybersecurity GRC and am committed to delivering comprehensive support through in-depth analysis and strategic planning.

Overview

5
5
years of professional experience
1
1
Certification

Work history

IT Governance Specialist

Ministry of Culture
Riyadh, Saudi Arabia
06.2023 - Current

Held responsibility for maintaining, reviewing, and updating IT policies and procedures.
Worked on the correction plans and requirements for the IT department's risk register.
Worked on the correction plans for external/internal audits and provided the evidence to close the findings.
Led the development of Business Continuity enhancements (BIA, BCP, DRP) for the IT department.

Monitored and reported on key IT performance indicators (KPIs) to drive continuous improvement and strategic decision-making.

Implemented ISO 38500 principles for IT governance.

GRC Consultant

Devoteam
Riyadh, Saudi Arabia
03.2022 - 06.2023

Write proposals to align with the RFP requirements.

Served as Project Manager for the BCM automation project.

Cyber Security GRC Officer

Saudi Finance Company
Riyadh , Saudi Arabia
10.2021 - 03.2022

Define, review, and edit the Cybersecurity policies based on SAMA requirements.

Maintain RCSA [Risk Control Self-Assessment] document & perform RCSA testing against IT processes.

Managed the risk register - tracking all risks and reviewing them on a quarterly basis.

Cyber Security Analyst

Council of Cooperative Health Insurance
Riyadh , Saudi Arabia
07.2020 - 02.2021

Develop Cybersecurity policies and procedures to align with NCA requirements.

Conduct Cybersecurity compliance self-assessments and audits to comply with NCA-ECC controls.

follow up with CCHI stakeholders to close the findings.

Report to the management the status and the maturity of the compliance.

Conduct self-assessment and collect evidence from different departments.

Develop a Cybersecurity awareness campaign to target all CCHI employees and contractors.

Report to the management about the activities of Cybersecurity awareness.

Education

Faculty of Computer & Information Sciences - Information Systems - GPA: 4.43 out of 5 with Second Class Honor

Princess Nourah Bint Abdulrahman University
Riyadh - Saudi Arabia
05.2019

Skills

Microsoft Office (Word, PowerPoint, Excel)

Teamwork

Multitasking

Communication Skills

Responsibility & Commitment

Certification

ITIL®v4

ISO 27001 Lead Implementer

Languages

Arabic
Native language
English
Advanced
C1

Timeline

IT Governance Specialist

Ministry of Culture
06.2023 - Current

GRC Consultant

Devoteam
03.2022 - 06.2023

Cyber Security GRC Officer

Saudi Finance Company
10.2021 - 03.2022

Cyber Security Analyst

Council of Cooperative Health Insurance
07.2020 - 02.2021

Faculty of Computer & Information Sciences - Information Systems - GPA: 4.43 out of 5 with Second Class Honor

Princess Nourah Bint Abdulrahman University
yara abdulaziz alshiban