عمار Chaudhary, Information Security Analyst

عمار Chaudhary

Information Security Analyst

McKesson

البلد
قطر
التعليم
ماجستير, Business
الخبرات
22 years, 4 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :22 years, 4 أشهر

Information Security Analyst في McKesson
  • الولايات المتحدة
  • أشغل هذه الوظيفة منذ ديسمبر 2012

Responsible for Information Security and Risk Management throughout the entire security lifecycle, including but not limited to the following:
Incident Response
Threat and Vulnerability Management (OS, Application and Database layers)
Performing cross-functional risk assessments and developing remediation strategies
Conducting HIPAA assessment reviews across all points that contain PHI (protected health information)
Responsible for third-party vendor assurance reviews
Coordinate with Project Management teams on new security initiatives

IT Audit Manager, Internal Audit Directorate في Qatar Foundation
  • قطر - الدوحة
  • أبريل 2007 إلى ديسمبر 2012

Developed (from the ground up) the IT Internal Audit function in Qatar Foundation

Established audit schedule based on IT risk assessment (COBIT framework)

Conduct technology audits including applications, security, governance, project management

Created a strategy to provide enterprise-wide audit coverage for the domain of information technology

Developed a framework for information security compliance testing including:
-Vulnerability/Penetration audits on all critical infrastructure and applications on a quarterly schedule
-Firewall reviews
-User access and user provisioning reviews
-Application and Database layer assessments

Developed a standard framework to perform pre and post-application implementation reviews based on COBIT, ITIL and ISO

Assisted in the design strategy to implement an integrated audit methodology within the internal audit department, enabling the most thorough, comprehensive and efficient audits from a business risk perspective

Developed strategy for the enablement of the continuous auditing platform (i.e. fraud analytics)

IT Security Analyst في LexisNexis
  • الولايات المتحدة
  • يناير 2005 إلى مارس 2007

Performed gap analysis of system deficiencies against standardized configuration, corporate & industry security standards, recommended and applied system updates & performed follow-up scans to verify updates

Drafted formal documentation of Corporate Information Security Policies, Procedures, Guidelines and Baselines in accordance to ISO 17799/27001

Served as a liaison between business units, corporate Information Technology (IT), finance & accounting, and the external auditors in all aspects of SOX

Key contributor to a unique security audit conducted as a result of Federal Trade Commission (FTC) order. The audit entailed delivering a documented control framework and providing documentation to support control testing

Managed corporate information systems vulnerability assessment and remediation program in accordance to regulatory compliance including PCI, SOX, and SAS70

Information Security Analyst في SilverSky (formerly Perimeter E- Security)
  • الولايات المتحدة
  • فبراير 2002 إلى يناير 2005

Assisted clients with establishment of effective IT Security and Compliance Programs in order to achieve effective IT governance

Performed business and IT audit testing for clients conducting SOX 404, GLBA, HIPPA

Executed audit projects utilizing principals established within the Committee of Sponsoring Organizations’ (COSO) report on internal controls and Control Objectives for Information Technology (COBIT)

Provided vulnerability assessment remediation strategies and recommendations as well as consulting in preparation for regulatory and compliance audits.

Served as a fieldwork leader to assist clients in employing proper information systems, resources, and controls to maximize efficiencies and minimize risk

Worked with client personnel to analyze, evaluate, and enhance information systems facilitating the business internal control processes

Assisted clients and other team members in performing information technology control and security engagements

الخلفية التعليمية

ماجستير, Business
  • في MBA
  • يوليو 2013

MBA - Edinburgh Business School (in progress)

ماجستير, Masters Degree in Management Information Systems (MIS)
  • في Nova Southeast University
  • مارس 2005

Graduated with Honors 03/05 - 3.67 GPA

بكالوريوس, Bachelor in Information Technology
  • في American Intercontinental University
  • مارس 2003

Graduated with Honors

Specialties & Skills

Vulnerability Assessment
ISO 27001
System Audits
Application Audits
COBIT Framework
Vulnerability & Penetration Testing
Compliance Audits (SOX, PCI)

اللغات

الانجليزية
متمرّس
العربية
متوسط

العضويات

ISACA (Information Systems Audit and Control Association)
  • Information Systems Audit and Control Association
  • August 2007
IIA
  • Institute of Internal Auditors Qatar
  • January 2008

التدريب و الشهادات

CISA (الشهادة)
تاريخ الدورة:
January 2012
صالحة لغاية:
January 2012
CISSP (الشهادة)
تاريخ الدورة:
November 2005
صالحة لغاية:
November 2005