سرفراز kazi, Manager - Information Security

سرفراز kazi

Manager - Information Security

National Bank of Kuwait

البلد
الكويت
التعليم
بكالوريوس, Business and Commerce
الخبرات
22 years, 4 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :22 years, 4 أشهر

Manager - Information Security في National Bank of Kuwait
  • الكويت - الكويت
  • أشغل هذه الوظيفة منذ أغسطس 2015

Security Operations Centers (SOC)
 Security Operations Center (SOC) Manager
• Manage the team roster and oversee the daily operation.
• Ensure the team responds to the alerts on predefined SLAs.
• Guide the team on how to perform investigations and suggest resolutions.
• Work with change management team to identify new systems being pushed to production so that we ensure the system is integrated with the SIEM solution.
• Monthly Dashboard reporting to CISO/CIO for SOC KPIs.
Monitoring & Compliance • Developed and implemented database monitoring for Critical Banking Databases & Applications using Infosphere Guardium. • Manage compliance metrics and dashboard reporting to CISO. • Conduct internal ISMS 27001 audits and security reviews for ISO 27001 compliance and re-certification. • Ensure sensitive data protection, review and report any compliance violations as per PCI, ISO 27001 & internal policies. • Assist in maintaining compliance for PCI, ISO 27001 and internal policies.  Incident Management • Ensure proactive monitoring for incident identification and reporting as per NBK Incident Management Framework.  Access Control • Ensure regular user access reviews are conducted across critical NBK IT Infrastructure and user access is provided based on valid business justification.  Audit Support • Assist and extend support for internal and external audits. • Assist Business & IT in remediation of audit findings.  Project Management • Assist with key security projects and extend support on IT & Business projects.  Governance and Advisory • Review and assist in developing security policies, processes and procedures based on industry standard.

Sr. Information Security Specialist في National Bank Of Kuwait
  • الكويت - الكويت
  • أبريل 2011 إلى يوليو 2015

 • Liaise and advise different business units to identify security in business and processes and support them with remediation to secure business information.  Security Operations • Facilitate and coordinate internal and external vulnerability assessments and reporting. • Liaise with IT for patch management to ensure timely closure of high risk issues. • Perform system audits & security reviews for NBK & NBK Capital IT Infrastructure. • Evaluate new technologies and conduct POC. • Manage relationship with vendors for timely maintenance and ensure efficient SLA implementation. • Review and approve firewall requests to access critical banking infrastructure. • Managed Technologies & Tools such as InfoSphere Guardium, Nessus 5.2, Cisco DLP, Acunetix Web application Scanner, Control Case PCI Card Data Scanner.  Achievements • Developed monitoring compliance framework for NBK ISO Dept. • Key player in recertification of ISO 27001 for NBK ISO Dept. • Streamlined internal patch management and External VA tracking process for ISO.

IT Security Manager في The Sultan Center
  • الكويت - الفراوانية
  • أكتوبر 2010 إلى أبريل 2011

 Developed a security strategy based on ITIL, using the PDCA lifecycle framework.
 Developed security policies for various domains.
 Developed a semi-qualitative Risk Assessment template for TSC (Pending approval).
 Initiated a security awareness program for the TSC group.
 Integrating security approval in the change management process.
 Initiated Business Dependency analysis for critical assets.
- Disaster Recovery Planning for the datacenter.

Infrastructure Manager في The Sultan Center - ITG
  • الكويت - الكويت
  • أبريل 2008 إلى سبتمبر 2010

 Responsible for the IT Infrastructure of ITG (Kuwait, Dubai, Jordan).
 Designing, planning and proposing cost effective LAN/WAN network solutions for the Head office & Remote sites.
 Responsible for secure connectivity from head office to remote sites.
 Responsible for smooth operation of the Corporate servers.
 Planning the networks and Systems for the security over Firewall rules, Windows Group Policies and Anti-virus deployments.
 Setting up secure access to application server from remote sites through VPN.
 Reviewing access request forms, server logs & network usage.
 Assist in ITIL implementation initiative; operational level;
 Review and recommend hardware based on business requirements.
 Ensuring correct setting up of hardware standards for SDLC.
 Managing the operation of data integrity (disaster recovery, data, systems and equipment security)
 Creating test environments and conducting post implementation technical reviews.
 Review various IT quotations for procuring new hardware/software.

Project Manager في Smartlink Telecom
  • الكويت
  • سبتمبر 2005 إلى أبريل 2008

 Represented Wataniya Telecom as the Project Head on the US Army Hotspot Project.
 Planning, Design & Deployment of wireless mesh network for the US Army camps.
 Planning, Design and Deployment of MOH IP network for Microwave and FSO.
 Implemented a Radius Server (AAA) for prepaid internet access for the US Army.
 Responsible for Smartlink Telecom’s Core network and planning hotspots across Kuwait.
 Project Manager for migration of existing AAA server to the new server.
 Setup NOC escalation and reporting procedures for efficient customer support.
 Evaluating new technologies for prospective future deployments.
 Designed and Setup a complete Network Operations Center for Smartlink Telecom
 Datacenter setup, planning and equipment security.
 Availability monitoring of entire core, distribution, and edge network services and H/Ws, through centralized NMS tools.
 Evaluating, lab testing, analyzing, and reporting of new protocols, IT Technologies, and vendors.

Network Operations Supervisor في KUIX(MINISTRY OF COMMUNICATIONS)
  • الكويت - الكويت
  • يناير 2003 إلى يونيو 2005

* Monitor the Kuwait - Network Gateway, WAN links for Optical Carriers and customers.

* Trained on the latest Cisco 12000 series routers for monitoring, configuring and administration purposes.

* Interact with Flag Telecom-UK, Teleglobe-Canada incase of outages and network issues.

* RIPENCC Administrator: Maintaining, Registering IP ranges, DNS and Autonomous System (AS) with RIPENCC. (Regional Registry for the Middle East)

* Supervise and train a team of five members, prepare shifts; prepare various NOC documents, prepare Service Order forms for registered customers.

* Troubleshoot customer’s network using various network tools.

* Assigned the task of completing the Technical and Floor Diagram at the customer site.

* Documentation of the whole IP network using VLSM.

Network Supervisor/Customer Service Associate في AfaqNet
  • الكويت
  • نوفمبر 2001 إلى ديسمبر 2002

*Providing Technical support to customers with issues relating to PC’s and Internet.

*Monitoring the Bandwidth assigned to the customers per T1 line.

*System Administration and maintenance on Win XP/Win 98 platform.

*Updating the Technical Support and providing documentation for new issues.

*Supervising the Internet and Network Traffic.

*Thorough knowledge of the various technical resources available on the net.

*Developed content for the company’s site : http://www.afaqnet.net

*Corresponding with Qualitynet incase of network failures and high internet traffic.

*Installed different operating systems, software and hardware as per requirement.

الخلفية التعليمية

بكالوريوس, Business and Commerce
  • في Mumbai University
  • يونيو 2001

Specialties & Skills

ISO 27001
ISO Auditor
Compliance
PCI DSS
Project Management
Project Management
PCI-DSS
Information Security Management Systems  ISO 27001  Security Assessments Project Management  IS

اللغات

الانجليزية
متوسط
العربية
مبتدئ

العضويات

ISACA
  • Member
  • October 2011
(ISC)2 Kuwait Chapter
  • Vice President
  • September 2012

التدريب و الشهادات

ITIL V3 (الشهادة)
تاريخ الدورة:
May 2010
صالحة لغاية:
June 2010
ISO 27001 Lead Auditor (الشهادة)
تاريخ الدورة:
August 2011
صالحة لغاية:
September 2011
CISA (الشهادة)
تاريخ الدورة:
June 2012
صالحة لغاية:
July 2012
Certified Ethical Hacker v7 (الشهادة)
تاريخ الدورة:
May 2013
صالحة لغاية:
May 2013
Certified Information Security Manager (الشهادة)
تاريخ الدورة:
June 2010
صالحة لغاية:
July 2010
Certified Information Systems Security Professional (الشهادة)
تاريخ الدورة:
January 2011
صالحة لغاية:
February 2011