كلما زادت طلبات التقديم التي ترسلينها، زادت فرصك في الحصول على وظيفة!

إليك لمحة عن معدل نشاط الباحثات عن عمل خلال الشهر الماضي:

عدد الفرص التي تم تصفحها

عدد الطلبات التي تم تقديمها

استمري في التصفح والتقديم لزيادة فرصك في الحصول على وظيفة!

هل تبحثين عن جهات توظيف لها سجل مثبت في دعم وتمكين النساء؟

اضغطي هنا لاكتشاف الفرص المتاحة الآن!
نُقدّر رأيكِ

ندعوكِ للمشاركة في استطلاع مصمّم لمساعدة الباحثين على فهم أفضل الطرق لربط الباحثات عن عمل بالوظائف التي يبحثن عنها.

هل ترغبين في المشاركة؟

في حال تم اختياركِ، سنتواصل معكِ عبر البريد الإلكتروني لتزويدكِ بالتفاصيل والتعليمات الخاصة بالمشاركة.

ستحصلين على مبلغ 7 دولارات مقابل إجابتك على الاستطلاع.


تم إلغاء حظر المستخدم بنجاح
Abdullah Albaqami, Head of cybersecurity GRC

Abdullah Albaqami

Head of cybersecurity GRC·Confidential

المملكة العربية السعودية

بكالوريوس, Information Systems

الخبرة العملية

مجموع سنوات الخبرة: 13 سنوات, 2 أشهر

Head of cybersecurity GRC

أبريل 2024 - حتى الآن

Confidential

الرياض، المملكة العربية السعودية

أبريل 2024 - حتى الآن

Develop and implement cybersecurity governance frameworks aligned with NIST, ISO 27001,
and NCA.
• Ensure policies and procedures support business objectives and regulatory requirements.
• Identify, assess, and mitigate cyber risks across the organization, including emerging threats and
vulnerabilities.
• Develop the vendor risk management framework to assess third-party cybersecurity risks and
ensure alignment with organizational security policies.
• Ensure adherence to regulatory frameworks (e.g., ISO, NCA) and lead cybersecurity audits.
• Oversee employee training programs, including phishing simulations.

مجال الشركة:
أمن المعلومات و الشبكات
الدور الوظيفي:
الحماية

cybersecurity manager

أبريل 2023 - أبريل 2024

Wttco

الرياض، المملكة العربية السعودية

أبريل 2023 - أبريل 2024

Conducted comprehensive cybersecurity risk assessments and provided recommendations for
mitigation strategies.
• Developed and implemented security awareness training programs for employees and
stakeholders.
• Assisted in the development and implementation of cybersecurity policies and procedures.
• Guided compliance activity with relevant cybersecurity regulations and standards.
• Conducted security audits and penetration testing to identify vulnerabilities and weaknesses in
systems and applications.
• Collaborated with IT teams to implement security solutions and improve overall security posture.
• Stayed abreast of emerging cybersecurity threats and vulnerabilities and provided timely updates
and recommendations to clients.
• Assisted in incident response and recovery efforts in the event of a cybersecurity incident.

مجال الشركة:
خدمات المرافق
الدور الوظيفي:
التصنيع

cybersecurity consultant

أبريل 2022 - أبريل 2023

confidential

الرياض، المملكة العربية السعودية

أبريل 2022 - أبريل 2023

Conducted comprehensive cybersecurity risk assessments and provided recommendations for
mitigation strategies.
• Developed and implemented security awareness training programs for employees and
stakeholders.
• Assisted in the development and implementation of cybersecurity policies and procedures.
• Guided compliance activity with relevant cybersecurity regulations and standards.
• Conducted security audits and penetration testing to identify vulnerabilities and weaknesses in
systems and applications.
• Collaborated with IT teams to implement security solutions and improve overall security posture.
• Stayed abreast of emerging cybersecurity threats and vulnerabilities and provided timely updates
and recommendations to clients.
• Assisted in incident response and recovery efforts in the event of a cybersecurity incident.

مجال الشركة:
خدمات الدعم التجاري الأخرى
الدور الوظيفي:
الحماية

Information Security Manager

أبريل 2019 - أبريل 2022

confidential

الرياض، المملكة العربية السعودية

أبريل 2019 - أبريل 2022

- Led number of a security projects.
- Supervise Penetration Testing projects for IT Systems.
- Design, implementation, operation and maintenance of the Information Security Management system (ISMS) ISO 27001:2013.
- supervise and implement national cyber security center (NCSC) cybersecurity framework.
- Perform risk assessments to ensure cyber-risks are well identified and mitigated based on risk mitigation strategies.
- Supervise and implement Periodic compliance reviews against regulatory Information Security requirements and internal Policies, procedures and standards.
- Develop and implement user-training and security awareness programs.
- Supervise security patches process.

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

Information Security Analyst

أبريل 2016 - أبريل 2019

Advanced Electronics Company

الرياض، المملكة العربية السعودية

أبريل 2016 - أبريل 2019

- Supervise AEC Penetration Testing projects for IT Systems.
- Manage AEC’s ISO 27001:2013 Information Security Management System and ensuring continual compliance and ongoing eligibility for annual re-certification.
- Supervise and implement NIST cybersecurity framework.
- supervise and implement national cyber security center (NCSC) cybersecurity framework.
- Review System Security Plan (SSP) to verify that NIST 800-171 requirements map to the corresponding NIST 800-53 controls.
- Perform risk assessments to ensure cyber-risks are well identified and mitigated based on risk mitigation strategies.
- Supervise and implement Periodic compliance reviews against regulatory Information Security requirements and internal Policies, procedures and standards.
- Develop and implement user-training and security awareness programs.
- Supervise security patches process.
- Scan AEC environment for vulnerabilities and report findings to AEC system owners to mitigate security findings.

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

Information security analyst

أبريل 2013 - أبريل 2016

STC

الرياض، المملكة العربية السعودية

أبريل 2013 - أبريل 2016

- Implemented Qualys private cloud platform as the first security scan environment in Saudi Arabia.
- Responsible for the execution of Detailed Risk Assessment for IT Systems.
- Responsible for maintaining PCI DSS compliance for Saudi Telecom ePayment channel.
- Responsible for approval of insecure ports through firewalls.
- Perform ad-hoc risk assessment for newly go live projects and for major enhancements in the existing systems.
- Participate in the software security patches process for known STC software.
- Participate in maintaining ISO 27001 certificate for STC.
- Participate in implementing GRC Archer for IT Systems.

مجال الشركة:
الاتصالات والشبكات
الدور الوظيفي:
تكنولوجيا المعلومات

التعليم

College of Computer and Information Sciences, Imam Muhammad ibn Saud Islamic University

يوليو 2012

يوليو 2012

بكالوريوس، Information Systems

المملكة العربية السعودية

المعدل التراكمي (نقاط): 3.75 من 5

المعدل التراكمي (نقاط): 3.75 من 5

- Apply the knowledge of computing and mathematics appropriate to the program’s student outcomes and to the discipline. - Analyze a problem and identify and define the computing requirements appropriate to its solution. - Design, implement, and evaluate a computer and communication based system, process, component, or program to meet desired needs. - Function effectively on teams to accomplish a common goal. - Understand professional, ethical, legal, security and social issues and responsibilities. - Communicate effectively with a range of audiences. - Analyze the local and global impact of computing on individuals, organizations, and the society. - Recognize the needs for and an ability to engage in continuing professional development. - Use current techniques, skills, and tools necessary for the computing practice. - Understand processes that support the delivery and management of information systems within a specific application environment.​
عرض المرفق

Skills

Penetration Testing
Expert
Penetration Testing
Expert
IT Governance
Expert
IT Governance
Expert
IT Security
Expert
IT Security
Expert
IT Risk
Expert
IT Risk
Expert
ISO 27001
Expert
ISO 27001
Expert
Technical Support.
Intermediate
Technical Support.
Intermediate
troubleshooting.
Intermediate
troubleshooting.
Intermediate
Microsoft Office.
Intermediate
Microsoft Office.
Intermediate
Computer Security
Expert
Computer Security
Expert
information security
Expert
information security
Expert
IT Risk
Expert
IT Risk
Expert
Penetration Testing
Expert
Penetration Testing
Expert
IT Governance
Expert
IT Governance
Expert
IT Security
Expert
IT Security
Expert
ISO 27001
Expert
ISO 27001
Expert

اللغات

الانجليزية
متمرّس
العربية
اللغة الأم

التدريب و الشهادات

الشهادات
ISO/IEC 27001 Lead Implementer
Computer Hacking Forensic Investigator v8
Mar 2015 - Mar 2019
عرض الشهادات
EC-Council Certified Security Analyst v8
CompTIA Security+ (Security+)
Jun 2014 - Jun 2017
عرض الشهادات
Ec-council Certified Ethical Hacker (CEH)
Mar 2019 - Mar 2018
عرض الشهادات

الهوايات

  • Sport
  • Information security
  • Reading
  • traveling