عامر محمود, IT Security Consultant

عامر محمود

IT Security Consultant

it security & training solutions

البلد
المملكة العربية السعودية - الرياض
التعليم
ماجستير, Information System Security
الخبرات
20 years, 3 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :20 years, 3 أشهر

IT Security Consultant في it security & training solutions
  • المملكة العربية السعودية - الرياض
  • أشغل هذه الوظيفة منذ مارس 2012

•Preparing and Performing ISO 27001 Gap Analysis
•Working in SABIC CoE-IT Security team, performing ISO 27001 Gap Analysis globally Europe, America, Asia (Singapore) MEA regions.
•Communicating with SABIC Europe, MEA, AMERIC and ASIA region IT teams and reviewing and assessing their IT Procedure, providing recommendations and guideline to update their documentation,
•Gathering all IT Procedure and performing off-line audit.
•Providing guideline to all regions to follow the SABIC recommended standards for procedures implementation.

IT Security Consultant في it security training & solutions - i(ts)2
  • المملكة العربية السعودية - الرياض
  • مارس 2011 إلى مارس 2012

•Providing end to end guideline for to achieve ISO 20000 standard.
•Developing and creating Service catalogs.
•Developing Service Level Agreement (SLA) and Operation Level Agreement (OLA)
•Fully performing the quality audits on existing processes and procedures of RSADF.
•Creating and developing Change Management, Incident Management, Configuration Management, Service Request fulfilment procedures and related policies.
•Review, update and implementation of ISO 27001 Policies and procedure.
•Providing end to end guideline for the implementation of Disaster Recovery and contingency planning policy at RSADF.

Project Manager/IT Consultant في al khaleej computers & electronic systems (STC Project)
  • المملكة العربية السعودية - الرياض
  • مايو 2009 إلى مارس 2011

•Responsible to manage End to End Implementation of BMC/ITSM Remedy tool Implementation Project.
•Communicating, Scheduling meetings with Devoteam team Consultants for initial design and assessment phase.
•Conducting and attending BMC ITSM Remedy meetings and Presentations.
•Coordinating Devoteam Project manager and team to manage the project.
•Providing assessment reports and feedback to STC higher management.
IT Consultant:
•Worked as IT Consultant on COBIT implementation Project.
•Reporting directly to Director and General Manager of the respective departments.
•Performing Internal/Self audit of COBIT Processes.
•Create Process audit reports for higher management.
•Create and generate process activities reports on monthly basis.
•Doing all assessments for Configuration Management (DS9) and Change Management (AI6) processes.
•Align IT processes with Business requirement and other processes.
•Implementing Configuration and Release process under the umbrella of COBIT implementation project.
•IT service Management tool evaluation and analysis.
•Create and develop the Manage Quality Process (PO8) flow diagram and documents.
•Create and Develop ME2 and ME3 Processes (Internal Audit Control and External requirements with third party)
•Make sure that all project activities are executed according to the adopted methodology.
•Overall monitoring the Project plans and its implementation.

IT Security Consultant في it security training & solutions - i(ts)2
  • المملكة العربية السعودية - الرياض
  • مايو 2008 إلى أبريل 2009

•Worked on Dammam Municipality Project and King Fahad Security College Project (KFSC).
•Developed policies, procedures and Risk Management Plan for Dammam Municipality.
•Designed, established process flow for King Fahad Security college project.
August 2008-November 2008 Watheeqa Capital Company
•Developing and maintaining comprehensive Watheeqa Capital Company -wide information security strategy, plans and policy.
•Manage the development, implementation, and maintenance of WCC information security policy, standards, and guidelines
•Monitor report and work with WCC Internal Audit as appropriate on required security audits and compliance requirements like TADAWUL Compliance requirements.
•Serve as an expert advisor to WCC in the development, implementation, and maintenance of an information security infrastructure

May 2008-August 2008 Rana Investment Company Riyadh, KSA
•Creating action plan to implement IT security in RIC IT infrastructure.
•Identify security gaps with the help of checklists and provide the best possible solution.
•Review email security, host security, servers security parameter security and configuration settings.
•Performing network vulnerability assessment routers, switches and firewalls.
•Review system updates and patches.
•Planning and implementing IT security cost effective solutions.
•Documenting the IT security related documents
•Identify possible technologies and products to use in security solutions.

Process Specailist في al khaleej computers & electronic systems (STC Project)
  • المملكة العربية السعودية - الرياض
  • يناير 2003 إلى يناير 2005

•Configuration and Release Management Supervision
•Configuration and Release Management Work Procedures implementations
•Participated in the Manage other ITIL modules in STC
•Active participation in ITIL system testing (SQT, PAT), integration and roll-out
•Establish and administrative function for the upkeep of CMDB
•Supervision day-to-day activities involving check in/checkout of Assets from Configuration Management tools.
•Filtration and follow up (Request for Change) RFC for Release Management
•Delivery of ITIL awareness presentations to STC Higher Managements
•Vendor Coordination for the implementation of new Configure Items (CI’s) and giving proper update to the Configuration Management to maintain the accuracy of CMDB.
•Giving proper feedback to the Change Management to close RFC.

Customer Support Analyst في ufone (an etisalat company)
  • باكستان - إسلام أباد
  • يناير 2001 إلى ديسمبر 2002

•Value Added Technical Support/Management: Management of all Value Added Services including Activation and Deactivation i.e. GPRS, MMS, Voice Mail, SMS, Call Waiting, Call Conferencing, Call Barring, International Roaming (IR) etc.
•General Administrative tasks.
•Scheduling and planning of task for the management of all value added services team.
•Providing guidance on tasks to the team.
•Supervision of daily, weekly and monthly status report of tasks.
•Supervision of team meetings on weekly and monthly basis to resolve pending issues and problems to improve department performance.
•Coordination with Vendors and providing feedback to Higher Management.
•Providing support for Value added, billing and other offered services and reporting about churn blocking team to reduce/avoid churn.
•Reporting and Correspondence with Higher Management.

الخلفية التعليمية

ماجستير, Information System Security
  • في Sheffield Hallam University (UK)
  • يوليو 2007

Introduction to Security Network Security, Web Application Security, System Application Security, Risk Management, ISO 27001 Project Management,

ماجستير, Computer Sceinces
  • في Preston University
  • ديسمبر 2000

Masters In computer Sciences, Covered all major Computer Sciences subject.

Specialties & Skills

IT Security
ISO 27001 (ISMS), ISO20000, ITIL Implementatio, IT Security Auditing, Policies Procedure writing

اللغات

الانجليزية
متمرّس
الأوردو
متمرّس
العربية
مبتدئ

العضويات

ISACA
  • Professional
  • December 2009

التدريب و الشهادات

Attendance Certificate (الشهادة)
تاريخ الدورة:
January 2009
صالحة لغاية:
January 2009
Training Certificate (الشهادة)
تاريخ الدورة:
April 2003
صالحة لغاية:
April 2003
ITIL V3 (الشهادة)
تاريخ الدورة:
July 2011
صالحة لغاية:
July 2011
ISO 27001 Lead Auditor (الشهادة)
تاريخ الدورة:
December 2006
صالحة لغاية:
December 2006
ISO 20000 (الشهادة)
تاريخ الدورة:
February 2011
صالحة لغاية:
March 2011
ITIL V2 Foundation (الشهادة)
تاريخ الدورة:
April 2003
صالحة لغاية:
April 2003
COBIT Foundation (الشهادة)
تاريخ الدورة:
December 2009
صالحة لغاية:
December 2009
Attendance Certificate, Customer Care Excellence Certificate (الشهادة)
تاريخ الدورة:
January 2001
صالحة لغاية:
January 2001