انس بطاينه, Information and Cybersecurity Senior Manager

انس بطاينه

Information and Cybersecurity Senior Manager

AL Rajhi Bank

البلد
الأردن - عمان
التعليم
ماجستير, Computer Engineering / Industrial Automation Engineering
الخبرات
11 years, 3 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :11 years, 3 أشهر

Information and Cybersecurity Senior Manager في AL Rajhi Bank
  • الأردن - عمان
  • أشغل هذه الوظيفة منذ مارس 2024
Information Security Manager في Cairo Amman Bank
  • الأردن - عمان
  • يونيو 2022 إلى فبراير 2024

o Establish Information and Cybersecurity policy.
o Establish Information and Cybersecurity program.
o Create and design the security controls in the bank environment especially for new financial systems.
o Management of security approaches for IT system with a networking system.
o Perform time-to-time system and network processing inspection for security updates.
o Manage information and cybersecurity risk assessments, propose mitigation controls and procedures in a business context, and define information and cybersecurity requirements for new and ongoing projects and business activities, as well as managing the process of information and system classification.
o Conduct an audit procedure to initiate the security and safety strategies and measures.
o Measure the performance of the information and cybersecurity program and measure the defined key risk indicators.
o Prepares and implements awareness programs for the Bank's staff on aspects related to combating financial crimes.
o Implement the proper solutions and platforms that will defense and mitigate all security risks coming from internal or external resources.
o Monitor the performance of employees of the job and participate in the assessment of their performance and their training and motivation and career affairs in coordination with the direct responsibility and human resources management.
o Maintain the standard of information security laws, procedure, policy and services.
o Performing standards assessments such as PCI and ISO/IEC 27001 standards.

Security Operation Senior Officer في Housing Bank for Trade and Finance
  • الأردن - عمان
  • سبتمبر 2020 إلى أكتوبر 2022

o Develop and/or maintain appropriate Segregation of Duties within and across applications.
o Install, modify, enhance and maintain security devices or platforms.
o Work on determining acceptable risk levels for the enterprise and ensuring the IT environments are adequately protected from potential risks and threats.
o Participate in development and implementation of the appropriate and effective controls to mitigate identified threats and risks.
o Follow-up on detected security issues and implement solutions to reduce security risks.
o Assist in the research, development, communication, maintaining and working with the operational units on the enforcement of IT security architecture, policies, procedures, solutions and standards.
o Oversee incident response planning as well as the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary.
o Responsible for staying abreast of the latest industry security practices and technologies.
o Meet with Business Owners to analyze, document and define requirements associated with new development or maintenance and enhancements to existing security roles and permissions. Review completed roles/permissions with users to ensure requirements are fully met.
o Deliver services that meet regulatory specifications. Work with internal and external auditors to document and confirm that all security administrative duties are properly performed as well as demonstrate overall compliance.
o Working on the below;
 Firewalls: Palo Alto, Cisco ASA, Cisco FTD, Fortinet, WatchGuard.
 F5: LTM and advance WAF.
 Qualys vulnerability and compliance scanner. Reporting and tracking vulnerabilities’ status with system owners.
 Firemon: Managing firewalls access rules, risk analyzing, access rules optimizing and changes tracker.
 Qradar SIEM solution.
 Level-2 SOC analyst with tracking and reporting incidences.
 ThreatQ TIP solution. Threat intelligence platform.
 IBM Security Guardium Data Protection. Monitoring and controlling databases admins’ activates and permissions.
 Infoblox: Manage, control and optimize secure DNS, DHCP and IPAM.
 Arbor. Mitigating DDOs attacks.
 Microsoft Intune for securing mobile devices - MDM.
 SWIFT-DFA.
 Symantec email security gateway.
 Vectra; AI cybersecurity that detects and responds to hidden cyber attackers inside enterprise networks.
 Review PCI maturity level in all security devices and platforms.
 Review and resolve audit and risk notes.
 Review and hardening OWASP top 10 applications security risk in the environment.

System/Network Administrator and Information Security Officer-CEH في Anti-Money Laundering and Counter Terrorism Financing Unit (FIU-JORDAN, AMLU)
  • الأردن - عمان
  • مايو 2017 إلى مايو 2020

- Information Security Officer. Driving the IT security strategy and implementation forward whilst protecting the business from security threats and cyber-hacking.
- Vulnerabilities tester.
- Ethical Hacker.
- Unified Thread Managements.
- Installation, Storage, and Compute with Windows Server.
- Networking with Windows Server.
- Identity with Windows Server.
- DHCP, DNS and IPAM installation and configuration.
- Failover Clustering.
- Back-up plans (Veeam and Veritas).
- Exchange Server Installation and Configuration.
- Managing Office 365 Identities and Requirements.
- Administer servers, desktop computers, printers, routers, switches, firewalls, phones, personal digital assistants, smartphones, software deployment, security updates and patches.
- Maintain system efficiency.
- Ensure design of system allows all components to work properly together.
- Troubleshoot problems reported by users.
- Make recommendations for future upgrades.
- Maintain network and system security.
- Analyze and isolate issues.
- Monitor networks to ensure security and availability to specific users.
- Evaluate and modify system's performance.
- Identify user needs.
- Maintain integrity of the network, server deployment, and security.
- Support LANs, WANs, network segments, Internet, and intranet systems.
- Ensure network connectivity throughout a company's LAN/WAN infrastructure is on par with technical considerations.
- Perform network address assignment.
- Assign configuration of authentication and authorization of directory services.
- Maintain network facilities in individual machines, such as drivers and settings of personal computers as well as printers.
- Maintain network servers such as file servers, VPN gateways, intrusion detection systems.
- Any technical related issues.

System Administrator Trainer في Technical and Vocational Training Corporation
  • المملكة العربية السعودية - القصيم
  • نوفمبر 2013 إلى فبراير 2017

Training the following Subjects:

Plans, develops, installs, troubleshoots, maintains and supports an operating system and associated server hardware, software and databases ensuring optimum system integrity, security, backup and performance.

- MS Windows Server 2008, 12, 16.
- MS Windows XP, 7, 8, 10.
- MS Windows Exchange server 2010, 13, 16.
- MS Office 2007, 10, 13, 16.
- Active Directory and Domain Controller.
- DHCP, DNS.
- Backups and Storage Systems.
- Network Printers and Scanners.
- Cloud Storage and Printers.
- Computer Maintenance and Architecture.
- Virtual Machines.
- Technical Support Strategies.
- Mobile Phones Maintenance (iPhone, iPad, Samsung).

IT Manager في Ayla Aviation Academy
  • الأردن - العقبة
  • سبتمبر 2011 إلى يونيو 2012

-Firewall Server.
-Exchange Server 2010, 2013, 2016.
-Digital Video Recorder Server.
-Flightlog Server-Aviation Industry.
-Central Database Server, SQL Server.
-Windows Server 2012, 2016.
-VoIP-Nortel Switching System-BCM4.0.
-Technical Support.
-Maintenance (PCs, Laptops and Servers).
-Apple Systems as AirPort, Apple TVs, iPads, iTunes and MacBooks.
-Network Management and Securing of both Wi-Fi and Wired networks.
-Time Attendance System.
-Network Storage System and Backup Systems.
-lD Cards-Printer-Matica Chica.
-Online Conferences.
-Network devices, Printers and Scanners.
-Mobile, iPhone and Blackberry technical support.

Instructor-Part Time and TA في Yarmouk University
  • الأردن - اربد
  • يونيو 2010 إلى أغسطس 2010

1- Maintenance Computers, networking, backup and Ghosts-2008/2009.
2- Microprocessor programmer-2009/2010 instructor.
3- Digital Logic Instructor-2009/2010 instructor.
4- VHDL instructor-2009/2010 instructor.

الخلفية التعليمية

ماجستير, Computer Engineering / Industrial Automation Engineering
  • في YARMOUK UNIVERSITY
  • أغسطس 2010

-Thesis title: AN EFFICIENT FPGA HARDWARE IMPLEMENTATION OF THE THREEFISH TWEAKABLE BLOCK CIPHER. -Research: AN EFFICIENT FPGA HARDWARE IMPLEMENTATION OF THE THREEFISH TWEAKABLE BLOCK CIPHER. -Research: Arabic-Jawi Scripts Font Recognition Using First-Order Edge Direction Matrix. - Conference: AUTOTESTCON 2010 Conferences, Orlando, Florida, USA.

Specialties & Skills

IT Governance
IT Infrastructure
IT Management
Cyber Security
Ethical Hacking
Backup Systems
COBIT 5 Foundation
Unified Thread Managements
Windows Server , 2008, 2012, 2016
Exchange Server 2007, 2010, 2013, 2016
Network Devices, Printers and Scanners
System Administrator
Reasearch
Data Encryption
Ethical Hacker
Network Security
Information Security Officer
Apple Systems
personal security
pc networking
computer hardware troubleshooting
protection
windows server
microsoft servers
system administration
windows network administration

اللغات

الانجليزية
متمرّس
العربية
متمرّس

العضويات

IEEE
  • Researching
  • August 2010
EC-Council
  • ECE Membership
  • December 2019

التدريب و الشهادات

CCNA (تدريب)
معهد التدريب:
Cyber Technical
تاريخ الدورة:
March 2019
Designing and Deploying Microsoft Exchange Server 2016 (تدريب)
معهد التدريب:
STS
تاريخ الدورة:
November 2018
Administering Microsoft Exchange Server 2016 (تدريب)
معهد التدريب:
Specialized Technical Services (STS)
تاريخ الدورة:
May 2018
COBIT 5 Foundation (تدريب)
معهد التدريب:
Control Risk Consultant
تاريخ الدورة:
January 2018
Network and Systems Administration (تدريب)
معهد التدريب:
Yarmouk University
تاريخ الدورة:
September 2008
Cerified Ethical Hacker-V10 (الشهادة)
تاريخ الدورة:
November 2019
Alcatel Lucent entry training course (تدريب)
معهد التدريب:
AMLU
تاريخ الدورة:
January 2019
Securing a Financial Intelligence Unit-Taiwan (الشهادة)
تاريخ الدورة:
January 2018

الهوايات

  • Skydiving
  • Hiking
  • Ultralight-Flying