Abdullah Tolbah, Cyber Security GRC Manager

Abdullah Tolbah

Cyber Security GRC Manager

Advanced Electronics Company

Location
Saudi Arabia - Riyadh
Education
Diploma, ISO9001 Internal Auditor
Experience
13 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :13 years, 4 Months

Cyber Security GRC Manager at Advanced Electronics Company
  • Saudi Arabia
  • February 2017 to February 2019

Managing Cybersecurity GRC Consulting Services

Chief Information Security Officer at Saudi Arabian Mining Company - Ma’aden
  • Saudi Arabia
  • October 2016 to February 2017
Head of Information Security at Saudi Arabian Mining Company-Ma'aden
  • Saudi Arabia - Riyadh
  • January 2015 to October 2016
Information Security Officer at Saudi Arabian Mining Company -Ma'aden
  • Saudi Arabia - Riyadh
  • July 2012 to January 2015

-Defining the information security strategy and roadmap for MA’ADEN Corporate and Affiliates.
-Developing the annual information security goals and objectives.
-Lead MA’ADEN Corporate and Affiliates IT security team: plan, organize, assign, supervise and monitor the work of team members.
-Lead the computer emergency response team across MA’ADEN.
-Establishing and maintaining plans to implement the information security governance in Corporate and Affiliates.
-Managing the information security budget in implementing the information security program.
-Leading the execution of Corporate and Affiliates IT security projects.
-Identifying security risks through suitable and recommended methods.
-Defining the information security policies that support business goals and objectives.
-Ensuring IT services provided to business, including outsourced providers are consistent with established information security policies.
-Manage relationship with business units with regard to information security.
-Conducting Information Security awareness campaign in MA’ADEN.
-Responsible to advice management & provide the overall direction on Information Security initiatives across MA’ADEN.
-Participating in ETGAN Program -MA’ADEN Global Transformation Program.
-Participating in defining and building MA’ADEN-IT world-class institutional capabilities.

Cyber Strategic Program - Transformation Prog at Saudi Arabian Mining Company - Ma’aden
  • Saudi Arabia
  • November 2012 to February 2014
Information Security Specialist at advanced electronics company
  • Saudi Arabia - Riyadh
  • December 2011 to July 2012

-Establishing and maintaining plans to implement the information security in AEC
-Leading the execution of IT security projects.
-Manage relationship with business units with regard to information security.

Information Security Analyst & IT QA at Saudi Electricity Company
  • Saudi Arabia - Riyadh
  • November 2005 to December 2011

+Selected for High Potential Program 2010 for future leader.+
+Ideal employee in 2009.+
+Distinguished employee in 2008+
Information security field:
0 Define and Develop Information Security Strategies and Annual Plans.
1 Evaluate and Recommended Information Security Directions such as: Antivirus, Intrusion Prevention System, Encryptions.
2 Prepare Conceptual Scope of Work for Information Security Projects such as: Antivirus, Intrusion Prevention System, Encryptions.
3 Researching and Studying Information Security Systems.
4 Define and review information security policy and standards for business operations and technology implementations.
5 Define and Implement Information Security Policies.
6 Develop and Execute Information Security Awareness Program ( I established a campaign (ten workshops) on 9-13 May 09 to aware ITC employees for approved IT security policies in 2009 and I'm responsible for organizing and presenting this campaign).
IT Audit field (IT Quality Assurance field):
1 Prepare the Annual Internal Audit Plan.
2 Coordinate and monitor external and internal auditing.
3 Prepares audit report including the weaknesses noted in the systems and services.
4 Excellent knowledge of audit methodology and procedures.
5 Identify IT security risks including IT technical implementations or business processes.
6 Member in Auditing Information Security Systems and IT resources.
7 Enhance IT Quality Assurance by Monitoring and Follow up the Implementation of Recommendations of Internal and External Auditors.
8 Attended workshops competent in Information Security and IT Audit.

Education

Diploma, ISO9001 Internal Auditor
  • at Nexcons
  • July 2011

ISO9001 Internal Auditor: Attendance and Completion Course - IRCA Certified Auditor

Diploma, ISO27001 Lead Implementer
  • at I(TS)2
  • February 2010

Attendance and Completion Course - IRCA Certified Implementer

Diploma, CISSP CBK Review Seminar
  • at I(TS)2
  • July 2009

Attendance Course - 5 Days

Diploma, ISO27001 Lead Auditor
  • at I(TS)2
  • November 2008

Attendance and Completion Course - IRCA Certified Auditor

Diploma, Computer Hacking Forensic Investigation
  • at Techzonecs
  • May 2008

Attendance Course - 5 Days

Diploma, Ethical Hacking And Countermeasures
  • at Techzonecs
  • April 2008

Attendance Course - 5 Days

High school or equivalent, Report and Business Writing
  • at SEC Partner
  • November 2007

Attendance Course - 3 Days

Diploma, Learning English Language
  • at LSI
  • June 2007

Attendance and Completion Course - 3 Months

Diploma, Security +
  • at Techzonecs
  • May 2007

Attendance Course - 5 Days

Diploma, Network and Host Security
  • at I(TS)2
  • April 2007

Attendance and Completion Course - 5 Days

Diploma, Security Principles
  • at I(TS)2
  • February 2007

Attendance and Completion Course - 3 Days

Diploma, Designing Security for Microsoft Network
  • at New Horizons
  • November 2006

Attendance Course - 3 Days

Diploma, Photoshop
  • at Hasib Institute for Technical Training
  • November 2006

Attendance Course - 5 Days

High school or equivalent, Symantec Client Security
  • at Symantec Training Center
  • October 2006

Attendance Course dedicated in Symantec Endpoint Protection - 5 Days

Diploma, Fundamentals of Incident Handling
  • at I(TS)2
  • June 2006

Attendance Course - 5 Days

Bachelor's degree, Information Systems
  • at King Saud University
  • May 2005

Bachelor degree in Information Systems with GPA 3,51 King Saud University , College of Computer Sciences & Information - Riyadh, Saudi Arabia 2002 - 2005

Specialties & Skills

Adobe Photoshop
Attendance
Host Security
Prevention
Quality Assurance
System Analysis and Design, Software Engineering
Fast and self-learning
Microsoft Office
Programming Language: ASSEMBLEY, C, Java, XML and Visual Basic .NET
SQL, Oracle DBA, Data warehousing and Data Mining
ERP system, DSS, E-Commerce
Planner in Information Security Strategies
Lead Auditor and managing auditing program
Excellent communication & interpersonal skills
Self-motivated, positive attitude and a team player
Project Management

Languages

Arabic
Expert
English
Expert