أحمد حسن عبدالله باروم, Chief Information Security Officer

أحمد حسن عبدالله باروم

Chief Information Security Officer

Taajeer Finance

البلد
المملكة العربية السعودية - جدة
التعليم
ماجستير, Electronic And Information Engineering
الخبرات
11 years, 0 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :11 years, 0 أشهر

Chief Information Security Officer في Taajeer Finance
  • المملكة العربية السعودية - جدة
  • أشغل هذه الوظيفة منذ أبريل 2022

Developing and maintaining:
o Cybersecurity strategy.
o Cybersecurity Policies and Procedures.
o Cybersecurity architecture.
o Cybersecurity risk management process/methodology.
o Cybersecurity Awareness Programs and Campaigns..
• Providing risk-based Cybersecurity solutions and recommendations that address people, process, and technology on the orgnaizsion .
• Initiate security operation center (SOC) and build, manage, and enhance SOC rules.
• Ensure and maintain monitoring of the Cybersecurity activities (SOC monitoring) through red teaming activities.
• Overseeing the investigation of Cybersecurity incidents and initiate appropriate actions for Cybersecurity incidents and violations then to wrap it up with lessons learned documentations.
• Gathering and analyzing threat intelligence from internal and external sources.
• Performing Cybersecurity reviews.
• Regularly conducting Cybersecurity risk assessments on information assets.
• Proactively supporting other functions on Cybersecurity, including:
o Performing information and system classifications.
o Determining Cybersecurity requirements for important projects.
o Performing Cybersecurity reviews.
o Conducting security threats checks on the organization assets and systems.
• Brand Protection and Monitoring administrator.
• Migration of E-mails into MSSP with evaluationg the security mail getway rules and setup.
• Developing skills and experience of Cybersecurity staff to deliver Cybersecurity solutions in a business context.
• VAPT reports evaluation and suggestions on remediation process.
• Security Controls and IT evaluation.

Head of Monitoring and Analysis, SOC dep في General Authority of Civil Aviation (GACA)
  • المملكة العربية السعودية - جدة
  • يناير 2021 إلى مارس 2022

• Performed threat analysis in a 24/7 environment, mitigating and managing all threat and risks to the company.
• Analyzing and identify potential threats to fine tune the existing security monitoring platforms.
• Assist in the enhancement of delivery and management of key technology security platforms including SIEM and DLP.
• Develop specific content necessary to implement Security Use Cases and transform into correlation queries, templates, reports, rules, alerts, dashboards, and workflow.
• Assist with real-time security incident handling and tracking (e.g., intrusion correlation/tracking, threat analysis, and direct system remediation) tasks to support Incident Response Team.
• SIEM use cases incidents from inception, through to tuning.

Cyber Security Operation Manager (Act) في (General Authority of Civil Aviation (GACA
  • المملكة العربية السعودية - جدة
  • نوفمبر 2020 إلى يناير 2022

• Leading and managing the Security Operations and team of security operational staff members.
• Dealing with End point security.
• Create, maintain, and review security policies and controls across the business and the need.
• Support the technical implementation of ongoing security requirements, including access control and technical audits.
• Conduct testing of security controls to identify and close gaps.
• Leading network and application security personnel, developing strategy, setting goals, and providing performance and professional development feedback.
• Provide oversight and guidance during security incidents and investigations, ensure root cause analysis is undertaken and input suggested approaches to deal with lessons identified.

Information Security Analyst L2, SOC dep. في General Authority of Civil Aviation (GACA)
  • المملكة العربية السعودية - جدة
  • مايو 2017 إلى يناير 2021

• Monitors security events from the various SOC entry channels \[SIEM solutions, Ticketing system, and multiple of Email Protection Solutions\], based on the security event severity, escalate to IR team for any incident accrued after investigation on the case.
• Analyzing security breaches to identify the root causes.
• Provide Incident Response (IR) support when analysis confirms actionable incident.
• Provide threat and vulnerability analysis as well as security advisory services.
• Dealing with End point security tasks.
• Recommend enhancements to SOC security process, procedures, and policies.

Senior System Engineer, E-Services dep. في General Authority of Civil Aviation (GACA)
  • المملكة العربية السعودية - جدة
  • أكتوبر 2015 إلى مايو 2017

• Manage application projects life cycle through analysis design. Develop, Install, Configure, and Test.
• Communicate with vendors and other IT personnel for problem resolutions.
• Trainer for new systems and applications and prepare manuals for both technical and users.
• Products Manger to collect the required features from end user and finalize these requirements.
• Manage and monitor installed applications.
• Coordinate and perform tests, including end user reviews for any modified or new systems.
• Monitor and test systems performance.

HelpDesk, Operation Specialist في Saudi Electricity Company
  • المملكة العربية السعودية - جدة
  • فبراير 2009 إلى مايو 2011

• Act as a single point of contact for phone calls and emails from staff regarding IT issues and queries.
• Receiving, logging, and managing calls from internal staff via telephone and email.
• 1st and 2nd line support - troubleshooting of IT related problems from in-house software to hardware, such as PCs, Laptops, Scanners and Printers.
• Basic Active Directory knowledge. Creating user accounts, reset passwords, create groups etc.
• Install new PCs, Applications, and Devices as per user or management requests.

الخلفية التعليمية

ماجستير, Electronic And Information Engineering
  • في Indiana State University
  • يوليو 2015
بكالوريوس, Bachelor of Science in Computer Information Technology
  • في Northern Kentucky University
  • مايو 2014
دبلوم, Diploma of Science, Computer Information Technology
  • في Yanbu Industrial College
  • يونيو 2011

Specialties & Skills

Incident Management
Cyber Security
Time Management
ISO 27001
Corrective Actions and Plan
INCIDENT RESPONSE
OPERATIONS
MANAGEMENT
RISK MANAGEMENT
DIGITAL TRANSFORMATION
SECURITY CONTROLS
Cybersecurity Awareness
Budgeting
Risk Assessment Cycle
Compliance Assessments
Auditor
PDPL Management
Network Hardening
SECURITY POLICIES and PROCEDURES
ISO 27001_ISMS
ISO 22301_BCMS
Defining cybersecurity Policies and Procedures
Defining cybersecurity strategy
SAMA Regulations Expert
Defining cybersecurity Architecture
Cybersecurity Solutions
NCA and SAMA Assessments
Mitigation Strategies
Security Compliance
Technical Investigation
Auditing
Problem Solving
Leadership

حسابات مواقع التواصل الاجتماعي

الموقع الشخصي
الموقع الشخصي

لقد تم حذف الرابط بسبب انتهاكه لسياسة الموقع. يرجى التواصل مع قسم الدعم لمزيد من المعلومات.

اللغات

العربية
اللغة الأم
الانجليزية
متمرّس

العضويات

دروع للأمن السيبراني
  • Volunteer
  • March 2022
Hemaya GRC Committee
  • Volunteer
  • September 2022
Cybersecurity, NDMO, and PDPL Community Groups
  • Volunteer
  • February 2023

التدريب و الشهادات

Leadership Training Verification (الشهادة)
تاريخ الدورة:
May 2012
Strategic and Financial Management Training Verification (الشهادة)
تاريخ الدورة:
May 2012
Leadership diploma (الشهادة)
تاريخ الدورة:
February 2014
Actual and assessed Course in Incident Response (تدريب)
معهد التدريب:
KASPERSKY
تاريخ الدورة:
November 2018
McAfee Application Control and McAfee Change Control Administration (تدريب)
معهد التدريب:
McAfee
تاريخ الدورة:
March 2019
McAfee Endpoint Security Administration (تدريب)
معهد التدريب:
McAfee
تاريخ الدورة:
March 2019
Cybersecurity Intermediate training course organized by the NCA (تدريب)
معهد التدريب:
National Cybersecurity Authority
تاريخ الدورة:
August 2019
Cybersecurity Basic training course organized by the NCA (تدريب)
معهد التدريب:
National Cybersecurity Authority
تاريخ الدورة:
April 2019
Cyber Hacker Certified – CHCv2 by TechCampus (الشهادة)
تاريخ الدورة:
May 2020
Internal Auditing Training Based on ISO 19011:2011 (تدريب)
معهد التدريب:
RICI
تاريخ الدورة:
September 2022
Cyber Resilience (Global) (تدريب)
معهد التدريب:
Thomson Reuters
تاريخ الدورة:
September 2022
Froud Awareness (MENA) (تدريب)
معهد التدريب:
Thomson Reuters
تاريخ الدورة:
August 2022
Certified Business Cotinuity Management System (BCMS) (الشهادة)
تاريخ الدورة:
July 2023
Certified Information Security Management System (ISMS) (الشهادة)
تاريخ الدورة:
October 2022
Security + training course (تدريب)
معهد التدريب:
Udemy
تاريخ الدورة:
June 2021
CISM training course (تدريب)
معهد التدريب:
IT security
تاريخ الدورة:
July 2022

الهوايات

  • Cybersecurity Awareness
    ,Cybersecurity Awareness Program ,Events ,Workshops Cybersecurity campaigns
  • Cybersecurity
    CISO of the Year by Arab Security Conference Award 2023 7th Round