Ahmed OUESLATI, IT Risk Manager | Auditor | Security Consultant | Quality Manager

Ahmed OUESLATI

IT Risk Manager | Auditor | Security Consultant | Quality Manager

National Digital Certification Autority (Certified ISO 9001:2008 by TUV Rheinland)

Location
Tunisia
Education
Higher diploma, Telecommunications Network Engineer
Experience
14 years, 8 Months

Share My Profile

Block User


Work Experience

Total years of experience :14 years, 8 Months

IT Risk Manager | Auditor | Security Consultant | Quality Manager at National Digital Certification Autority (Certified ISO 9001:2008 by TUV Rheinland)
  • Tunisia - Tunis
  • My current job since January 2011

*** Quality Manager System : ISO 9001 ***
- Project manager: Implementation of the Quality Management System (QMS) within the National Public Key Infrastructure “PKI” - Tunisia
- Scope definition
- Internal Audit of the Quality Management System: ISO 19011
- Risk Process Analysis (AMDEC)
- Writing and managing Quality documents (policies, processes, procedures...)
- Corrective and preventative actions
- Staff quality awareness training
- Generate and present Quality KPI and Dashboard to CEO

·*** IT Risk Manager and internal Auditor
- Plan, Design and implement risk assessment processes, procedures, policies…
- Develop Risk Management Framework;
- Conduct risk assessment and control effectiveness review for high risky processes
- Develop risk management strategies. Avoidance- Mitigation- Transfer- Retention risks
- Prepare and maintain the Inventory of Key Risk Indicators, KRI
- Control risk treatment;
- Risk reporting in an appropriate way for different audiences;
- Conduct audits of policy and compliance to standards, including liaison with internal and external auditors;
- Manage the external audit and manage the audit recommendation;
- Create risk management awareness program;
- Provide support, education and training to staff to build risk awareness within the organization.
- Internal and external penetration testing assessments including networks vulnerabilities scanning (Nessus) Application security testing, social engineering, log management (SEIM)

· *** Chairman of the Chief Information Security Officer Committee ***
- Evaluation of the security services offered by the NDCA according to the European standards ETSI
- Information security and information assurance
- Incident handling
- Policy and Standards Management, development of the security policies and operational procedures, Business Continuity Management, Disaster Recovery Plan...
- Developement and implementation of the security programs to protect and control the company assets..

Technico-commercial Engineer at Hits Way
  • Tunisia
  • February 2010 to December 2010
Teacher at Economic and Commercial Higher School of Tunis
  • Tunisia - Tunis
  • September 2009 to January 2010

Education

Higher diploma, Telecommunications Network Engineer
  • at High Institute for Computer Science
  • June 2009

Specialties & Skills

Auditing
Risk Assessment
Security
ISO 27001
CRYPTOGRAPHY
ENCRYPTION
RISK ANALYSIS
SECURITY
ISO 9001
ISO 27005
ISO 19011
Quality Control
auditing
Engineering
ISO 27001

Languages

English
Expert
French
Expert
German
Intermediate
Arabic
Native Speaker

Training and Certifications

ISO 27001 Lead Auditor IRCA (Certificate)
Date Attended:
December 2016
Valid Until:
December 2019
ISO 27001 Lead Auditor IRCA (Certificate)
Date Attended:
December 2016
Valid Until:
December 2019
CEH v8 (Training)
Training Institute:
CIFODE COM
Date Attended:
October 2015
Duration:
40 hours
ISO 27005 (Training)
Training Institute:
CIFODE COM
Date Attended:
January 2015
Duration:
40 hours
ESCA v8 (Training)
Training Institute:
Online Security Network
Date Attended:
September 2014
Duration:
40 hours
MEHARI 2010 (Training)
Training Institute:
BULL
Date Attended:
January 2012
ISO 19011 (Training)
Training Institute:
TEIGE CONSULTING
Date Attended:
December 2013
Duration:
20 hours
Data Communication and IP Technology (Training)
Training Institute:
MTNL India
Date Attended:
January 2014
ISO 9001 (Training)
Training Institute:
TEIGE CONSULTING
Duration:
100 hours
Business English 3C (Certificate)
Date Attended:
January 2013
ICND 1 (Training)
Training Institute:
CIFODE
Date Attended:
May 2014
CISA (Training)
Training Institute:
Cifode Com
Date Attended:
June 2014
Microsoft Certified IT Professional MCTS SQL Server 2008(MCITP) Server Administrator (Certificate)
Date Attended:
May 2012

Hobbies

  • Théatre
  • Sport
  • Voyage
  • Natation