Ahmed OUESLATI, IT Risk Manager | Auditor | Security Consultant | Quality Manager

Ahmed OUESLATI

IT Risk Manager | Auditor | Security Consultant | Quality Manager

National Digital Certification Autority (Certified ISO 9001:2008 by TUV Rheinland)

Lieu
Tunisie
Éducation
Diplôme supérieur, Telecommunications Network Engineer
Expérience
14 years, 9 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :14 years, 9 Mois

IT Risk Manager | Auditor | Security Consultant | Quality Manager à National Digital Certification Autority (Certified ISO 9001:2008 by TUV Rheinland)
  • Tunisie - Tunis
  • Je travaille ici depuis janvier 2011

*** Quality Manager System : ISO 9001 ***
- Project manager: Implementation of the Quality Management System (QMS) within the National Public Key Infrastructure “PKI” - Tunisia
- Scope definition
- Internal Audit of the Quality Management System: ISO 19011
- Risk Process Analysis (AMDEC)
- Writing and managing Quality documents (policies, processes, procedures...)
- Corrective and preventative actions
- Staff quality awareness training
- Generate and present Quality KPI and Dashboard to CEO

·*** IT Risk Manager and internal Auditor
- Plan, Design and implement risk assessment processes, procedures, policies…
- Develop Risk Management Framework;
- Conduct risk assessment and control effectiveness review for high risky processes
- Develop risk management strategies. Avoidance- Mitigation- Transfer- Retention risks
- Prepare and maintain the Inventory of Key Risk Indicators, KRI
- Control risk treatment;
- Risk reporting in an appropriate way for different audiences;
- Conduct audits of policy and compliance to standards, including liaison with internal and external auditors;
- Manage the external audit and manage the audit recommendation;
- Create risk management awareness program;
- Provide support, education and training to staff to build risk awareness within the organization.
- Internal and external penetration testing assessments including networks vulnerabilities scanning (Nessus) Application security testing, social engineering, log management (SEIM)

· *** Chairman of the Chief Information Security Officer Committee ***
- Evaluation of the security services offered by the NDCA according to the European standards ETSI
- Information security and information assurance
- Incident handling
- Policy and Standards Management, development of the security policies and operational procedures, Business Continuity Management, Disaster Recovery Plan...
- Developement and implementation of the security programs to protect and control the company assets..

Technico-commercial Engineer à Hits Way
  • Tunisie
  • février 2010 à décembre 2010
Teacher à Economic and Commercial Higher School of Tunis
  • Tunisie - Tunis
  • septembre 2009 à janvier 2010

Éducation

Diplôme supérieur, Telecommunications Network Engineer
  • à High Institute for Computer Science
  • juin 2009

Specialties & Skills

Auditing
Risk Assessment
Security
ISO 27001
CRYPTOGRAPHY
ENCRYPTION
RISK ANALYSIS
SECURITY
ISO 9001
ISO 27005
ISO 19011
Quality Control
auditing
Engineering
ISO 27001

Langues

Anglais
Expert
Français
Expert
Allemand
Moyen
Arabe
Langue Maternelle

Formation et Diplômes

ISO 27001 Lead Auditor IRCA (Certificat)
Date de la formation:
December 2016
Valide jusqu'à:
December 2019
ISO 27001 Lead Auditor IRCA (Certificat)
Date de la formation:
December 2016
Valide jusqu'à:
December 2019
CEH v8 (Formation)
Institut de formation:
CIFODE COM
Date de la formation:
October 2015
Durée:
40 heures
ISO 27005 (Formation)
Institut de formation:
CIFODE COM
Date de la formation:
January 2015
Durée:
40 heures
ESCA v8 (Formation)
Institut de formation:
Online Security Network
Date de la formation:
September 2014
Durée:
40 heures
MEHARI 2010 (Formation)
Institut de formation:
BULL
Date de la formation:
January 2012
ISO 19011 (Formation)
Institut de formation:
TEIGE CONSULTING
Date de la formation:
December 2013
Durée:
20 heures
Data Communication and IP Technology (Formation)
Institut de formation:
MTNL India
Date de la formation:
January 2014
ISO 9001 (Formation)
Institut de formation:
TEIGE CONSULTING
Durée:
100 heures
Business English 3C (Certificat)
Date de la formation:
January 2013
ICND 1 (Formation)
Institut de formation:
CIFODE
Date de la formation:
May 2014
CISA (Formation)
Institut de formation:
Cifode Com
Date de la formation:
June 2014
Microsoft Certified IT Professional MCTS SQL Server 2008(MCITP) Server Administrator (Certificat)
Date de la formation:
May 2012

Loisirs

  • Théatre
  • Sport
  • Voyage
  • Natation