Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Abdulkarim Alsowaygh, Information Security Risk Senior Specialist

Abdulkarim Alsowaygh

Information Security Risk Senior Specialist·Tahakom

Saudi Arabia

Bachelor's degree, Networking and Security

Work experience

Total years of experience: 10 years, 11 months

Information Security Risk Senior Specialist

September 2020 - Present

Tahakom

Riyadh, Saudi Arabia

September 2020 - Present

- Develop information security risk management methodology and ensure alignment with ERM function.
- Identify, evaluate, and manage information security risks and controls of all information assets (people, processes, and technologies).
- Maintain an up-to-date information security risk register, and oversee the implementation of identified mitigation plans with relative teams.
- Conduct an information security Business Impact Analysis for asset valuation and data sensitivity.
- Establish the data classification and handling guidelines.
- Develop, review, and communicate of all information security policies, procedures, standards, and guidelines, and ensure alignment with the organization's strategy.
- Develop and update of the information security governance and operating model (processes, roles, and responsibilities).
- Conduct compliance assessment with regulatory requirements (NCA ECC: 2018) and ensure its adherence.
- Incorporate information security requirements in all 3rd-party technological projects.
- Participate in reviewing and update of the information security architecture.

Company industry:
IT Services
Job role:
Information Technology

Security Governance Engineer (Consultant)

April 2020 - July 2020

Advanced Electronics Company

Riyadh, Saudi Arabia

April 2020 - July 2020

- Assist in developing and enhancing cyber security programs to meet clients requirements.
- Build a stand-alone cyber security controls framework to meet the requirements of the client and its sector.
- Participate in drafting RFPs as per the project requirements.
- Enhance the vulnerability management and incident response function from a governance perspective.
- Develop and enhance client's cyber security policies and standards.

Company industry:
IT Services
Job role:
Consulting

Cyber Security Analyst

April 2019 - April 2020

Public Pension Agency

Riyadh, Saudi Arabia

April 2019 - April 2020

- Manage the implementation of a full top-down cybersecurity program, being its project manager.
- Review and update all cyber security policies, procedures, and standards.
- Participate in the creation of KPIs and balanced scorecards related to the cyber security function.
- Participate in NCA's compliance audit (as an auditee) against NCA ECC: 2018.
- Conduct a cyber security Business Impact Analysis to identify criticality/sensitivity of PPA's data.
- Implement a data classification exercise as part of the data governance program.
- Oversee the enhancement of SOC operations, and implementation of Minimum Security Baselines for systems hardening efforts.

Company industry:
Public Administration
Job role:
Security

Information Security Officer

September 2018 - April 2019

Industrial and Commercial Bank of China

Riyadh, Saudi Arabia

September 2018 - April 2019

- Establish the governance and management of the information security function within the branch.
- Establish and manage the information security committee.
- Develop and update the information security strategy and policies.
- Conduct gap compliance assessment against SAMA Cyber Security Framework and ensure its implementation.
- Conduct branch-wide BIA as part of the business continuity efforts.
- Implement and manage all information security awareness programs.
- Enhance internal IT and banking procedures from a security perspective.

Company industry:
Banking
Job role:
Security

Information Security Officer

August 2016 - August 2018

MetLife (AIG) ANB

Riyadh, Saudi Arabia

August 2016 - August 2018

- Responsible for patch management of the organization's technological assets (laptops/desktops).
- Monitor email traffic of Office 365 for any unknown communications to block/filter.
- Participate in information security risk assessments exercises.
- Monitor and remediate any security flaws related to technological assets (e.g., Antiviruses, DLP, Encryption, Recovery, etc., ).
- Participate in the overall compliance implementation of SAMA Cyber Security Framework.

Company industry:
Insurance & TPA
Job role:
Information Technology

Network Security Administrator

January 2014 - February 2015

Integrated Telecom Company

Riyadh, Saudi Arabia

January 2014 - February 2015

- Manage cooperate-wide VoIP services.
- Manage and maintaining technological assets inventory.
- Participate in ISO/IEC 27001 certification audit.
- Participate on IT security policies reviews.

Company industry:
Internet & E-commerce
Job role:
Engineering

Education

Al-Yamamah University

January 2014

January 2014

Bachelor's degree, Networking and Security

Saudi Arabia

GPA (point): 2.97 out of 4

GPA (point): 2.97 out of 4

In my senior graduation project, we developed an ARP Cache Poisoning Detector which indicate if an intruder was successful in changing a device MAC address. Took general courses related to Design, configuration and maintenance of LAN and WAN. Took courses in wireless local area network and wide area network transmission technologies. The study of computer forensics, computer crimes, response to security incidents, Cybercrime investigation and prosecution.
View attachment

Skills

Impact Analysis
Expert
Impact Analysis
Expert
Risk Assessment
Expert
Risk Assessment
Expert
Risk Management
Expert
Risk Management
Expert
Cyber Security
Expert
Cyber Security
Expert
Information Security
Expert
Information Security
Expert
Impact Analysis
Expert
Impact Analysis
Expert
Risk Assessment
Expert
Risk Assessment
Expert
Risk Management
Expert
Risk Management
Expert
Cyber Security
Expert
Cyber Security
Expert
Information Security
Expert
Information Security
Expert

Languages

English

Expert

Arabic

Expert

Training and Certifications

Certifications
Certified Data Privacy Solutions Engineer (CDPSE)
Jul 2020 - Jan 2024
Certified in Risk & Information Systems Control (CRISC)
Aug 2020 - Jan 2024
Certified Information Security Manager (CISM)
Nov 2019 - Jan 2023

Training
CompTIA Security+
Share Knowledge
Mar 2018
PECB ISO 27001 Lead Implementer
Share Knowledge
Feb 2018