Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Abdullah Albaqami, Head of cybersecurity GRC

Abdullah Albaqami

Head of cybersecurity GRC·Confidential

Saudi Arabia

Bachelor's degree, Information Systems

Work experience

Total years of experience: 13 years, 2 months

Head of cybersecurity GRC

April 2024 - Present

Confidential

Riyadh, Saudi Arabia

April 2024 - Present

Develop and implement cybersecurity governance frameworks aligned with NIST, ISO 27001,
and NCA.
• Ensure policies and procedures support business objectives and regulatory requirements.
• Identify, assess, and mitigate cyber risks across the organization, including emerging threats and
vulnerabilities.
• Develop the vendor risk management framework to assess third-party cybersecurity risks and
ensure alignment with organizational security policies.
• Ensure adherence to regulatory frameworks (e.g., ISO, NCA) and lead cybersecurity audits.
• Oversee employee training programs, including phishing simulations.

Company industry:
Cyber & Network Security
Job role:
Security

cybersecurity manager

April 2023 - April 2024

Wttco

Riyadh, Saudi Arabia

April 2023 - April 2024

Conducted comprehensive cybersecurity risk assessments and provided recommendations for
mitigation strategies.
• Developed and implemented security awareness training programs for employees and
stakeholders.
• Assisted in the development and implementation of cybersecurity policies and procedures.
• Guided compliance activity with relevant cybersecurity regulations and standards.
• Conducted security audits and penetration testing to identify vulnerabilities and weaknesses in
systems and applications.
• Collaborated with IT teams to implement security solutions and improve overall security posture.
• Stayed abreast of emerging cybersecurity threats and vulnerabilities and provided timely updates
and recommendations to clients.
• Assisted in incident response and recovery efforts in the event of a cybersecurity incident.

Company industry:
Utilities
Job role:
Manufacturing

cybersecurity consultant

April 2022 - April 2023

confidential

Riyadh, Saudi Arabia

April 2022 - April 2023

Conducted comprehensive cybersecurity risk assessments and provided recommendations for
mitigation strategies.
• Developed and implemented security awareness training programs for employees and
stakeholders.
• Assisted in the development and implementation of cybersecurity policies and procedures.
• Guided compliance activity with relevant cybersecurity regulations and standards.
• Conducted security audits and penetration testing to identify vulnerabilities and weaknesses in
systems and applications.
• Collaborated with IT teams to implement security solutions and improve overall security posture.
• Stayed abreast of emerging cybersecurity threats and vulnerabilities and provided timely updates
and recommendations to clients.
• Assisted in incident response and recovery efforts in the event of a cybersecurity incident.

Company industry:
Other Business Support Services
Job role:
Security

Information Security Manager

April 2019 - April 2022

confidential

Riyadh, Saudi Arabia

April 2019 - April 2022

- Led number of a security projects.
- Supervise Penetration Testing projects for IT Systems.
- Design, implementation, operation and maintenance of the Information Security Management system (ISMS) ISO 27001:2013.
- supervise and implement national cyber security center (NCSC) cybersecurity framework.
- Perform risk assessments to ensure cyber-risks are well identified and mitigated based on risk mitigation strategies.
- Supervise and implement Periodic compliance reviews against regulatory Information Security requirements and internal Policies, procedures and standards.
- Develop and implement user-training and security awareness programs.
- Supervise security patches process.

Company industry:
IT Services
Job role:
Information Technology

Information Security Analyst

April 2016 - April 2019

Advanced Electronics Company

Riyadh, Saudi Arabia

April 2016 - April 2019

- Supervise AEC Penetration Testing projects for IT Systems.
- Manage AEC’s ISO 27001:2013 Information Security Management System and ensuring continual compliance and ongoing eligibility for annual re-certification.
- Supervise and implement NIST cybersecurity framework.
- supervise and implement national cyber security center (NCSC) cybersecurity framework.
- Review System Security Plan (SSP) to verify that NIST 800-171 requirements map to the corresponding NIST 800-53 controls.
- Perform risk assessments to ensure cyber-risks are well identified and mitigated based on risk mitigation strategies.
- Supervise and implement Periodic compliance reviews against regulatory Information Security requirements and internal Policies, procedures and standards.
- Develop and implement user-training and security awareness programs.
- Supervise security patches process.
- Scan AEC environment for vulnerabilities and report findings to AEC system owners to mitigate security findings.

Company industry:
IT Services
Job role:
Information Technology

Information security analyst

April 2013 - April 2016

STC

Riyadh, Saudi Arabia

April 2013 - April 2016

- Implemented Qualys private cloud platform as the first security scan environment in Saudi Arabia.
- Responsible for the execution of Detailed Risk Assessment for IT Systems.
- Responsible for maintaining PCI DSS compliance for Saudi Telecom ePayment channel.
- Responsible for approval of insecure ports through firewalls.
- Perform ad-hoc risk assessment for newly go live projects and for major enhancements in the existing systems.
- Participate in the software security patches process for known STC software.
- Participate in maintaining ISO 27001 certificate for STC.
- Participate in implementing GRC Archer for IT Systems.

Company industry:
Telecommunications
Job role:
Information Technology

Education

College of Computer and Information Sciences, Imam Muhammad ibn Saud Islamic University

July 2012

July 2012

Bachelor's degree, Information Systems

Saudi Arabia

GPA (point): 3.75 out of 5

GPA (point): 3.75 out of 5

- Apply the knowledge of computing and mathematics appropriate to the program’s student outcomes and to the discipline. - Analyze a problem and identify and define the computing requirements appropriate to its solution. - Design, implement, and evaluate a computer and communication based system, process, component, or program to meet desired needs. - Function effectively on teams to accomplish a common goal. - Understand professional, ethical, legal, security and social issues and responsibilities. - Communicate effectively with a range of audiences. - Analyze the local and global impact of computing on individuals, organizations, and the society. - Recognize the needs for and an ability to engage in continuing professional development. - Use current techniques, skills, and tools necessary for the computing practice. - Understand processes that support the delivery and management of information systems within a specific application environment.​
View attachment

Skills

Penetration Testing
Expert
Penetration Testing
Expert
IT Governance
Expert
IT Governance
Expert
IT Security
Expert
IT Security
Expert
IT Risk
Expert
IT Risk
Expert
ISO 27001
Expert
ISO 27001
Expert
Technical Support.
Intermediate
Technical Support.
Intermediate
troubleshooting.
Intermediate
troubleshooting.
Intermediate
Microsoft Office.
Intermediate
Microsoft Office.
Intermediate
Computer Security
Expert
Computer Security
Expert
information security
Expert
information security
Expert
IT Risk
Expert
IT Risk
Expert
Penetration Testing
Expert
Penetration Testing
Expert
IT Governance
Expert
IT Governance
Expert
IT Security
Expert
IT Security
Expert
ISO 27001
Expert
ISO 27001
Expert

Languages

English
Expert
Arabic
Native Speaker

Training and Certifications

Certifications
ISO/IEC 27001 Lead Implementer
Computer Hacking Forensic Investigator v8
Mar 2015 - Mar 2019
Show credentials
EC-Council Certified Security Analyst v8
CompTIA Security+ (Security+)
Jun 2014 - Jun 2017
Show credentials
Ec-council Certified Ethical Hacker (CEH)
Mar 2019 - Mar 2018
Show credentials

Hobbies

  • Sport
  • Information security
  • Reading
  • traveling