كلما زادت طلبات التقديم التي ترسلينها، زادت فرصك في الحصول على وظيفة!

إليك لمحة عن معدل نشاط الباحثات عن عمل خلال الشهر الماضي:

عدد الفرص التي تم تصفحها

عدد الطلبات التي تم تقديمها

استمري في التصفح والتقديم لزيادة فرصك في الحصول على وظيفة!

هل تبحثين عن جهات توظيف لها سجل مثبت في دعم وتمكين النساء؟

اضغطي هنا لاكتشاف الفرص المتاحة الآن!
نُقدّر رأيكِ

ندعوكِ للمشاركة في استطلاع مصمّم لمساعدة الباحثين على فهم أفضل الطرق لربط الباحثات عن عمل بالوظائف التي يبحثن عنها.

هل ترغبين في المشاركة؟

في حال تم اختياركِ، سنتواصل معكِ عبر البريد الإلكتروني لتزويدكِ بالتفاصيل والتعليمات الخاصة بالمشاركة.

ستحصلين على مبلغ 7 دولارات مقابل إجابتك على الاستطلاع.


تم إلغاء حظر المستخدم بنجاح
شكراً لك، تم إرسال بلاغك وسيتم مراجعته قريباً.
أنيس شيخ, Manager Governance, Risk & Compliance

أنيس شيخ

Manager Governance, Risk & Compliance·E& Enterprise IoT & AI LLC

الإمارات العربية المتحدة

دبلوم عالي, computer Technology

الخبرة العملية

مجموع سنوات الخبرة: 25 سنوات, 7 أشهر

Manager Governance, Risk & Compliance

أبريل 2015 - حتى الآن

E& Enterprise IoT & AI LLC

دبي، الإمارات العربية المتحدة

أبريل 2015 - حتى الآن

Role: Manager Quality Assurance & Compliance
Project: UAE FEDERAL Government Project

 Experience in information security strategy and planning (strategies, roadmaps, maturity assessments, governance organization design, roles and responsibilities), defining KPIs/KRIs and measurement.
 Developing IS policies, standards, guidelines, processes and procedures
 Managed and delivered large-scale information security projects like implementation of ITIL Process, ISO 27001 ISMS, ISO 20000 Service Management, ISO 22301 BCMS and ISO 27017 Cloud security standard implementation to achieve certification
 Conducting assessments for NIST SP 800-53, COBIT, CIS, National Electronic Security Authority (NESA), National Security National Emergency Crisis and Disasters Management Authority (NCEMA), ISR (Dubai Government Information Security Resolution), Abu Dhabi Government Data Management Standards.
 Served as the designated Management Representative and liaison to 3rd party auditors.
 Performed Internal Audit and maintained all controlled documents and forms and was responsible for continuous maintenance of standards.
 Ensured efficient and effective completion of all audit requirements.
 Managed all related internal audit programs and issued corrective actions.
 Provided recommendations for business process and internal control improvements.
 Risk Management-Identifying opportunities to improve risk posture, developing solutions for remediating or mitigating risks and assessing the residual risk. Escalated potentially significant risks and exposures. Review and update the Risk register for the department.
 Developed management reports to communicate progress.
 Conduct review of security audit reports and agree with management team on actions to be taken.
 Accountable for developing effective information security and ensure continuous quality improvement for organizational operational excellence by developing, implementing and conducting comprehensive organizational quality assessments

مجال الشركة:
الاتصالات والشبكات
الدور الوظيفي:
الإدارة

Manager Quality Assurance & Compliance

يناير 2015 - حتى الآن

E& Enterprise IoT & AI LLC-

دبي، الإمارات العربية المتحدة

يناير 2015 - حتى الآن

• Implemented and governed compliance across business units for ISO 20000 (ITSM), ISO 27001/27017
(Information & Cloud Security), ISO 22301 (BCM), and ITIL frameworks, ensuring alignment with
global best practices and regulatory requirements.
• Oversaw compliance with UAE regulatory mandates, including NESA, NCEMA as well as internal TDRA
cybersecurity policies and standards.
• Served as the Single Point of Contact (SPOC) for external auditors -BSI audits, internal TDRA audits,
and regulatory engagements—managing end-to-end audit coordination, evidence collection,
stakeholder communication, and timely closure of compliance findings.
• Designed and implemented an Enterprise Risk Management (ERM) framework; maintained a
comprehensive risk register across stakeholders, conducted monthly risk reviews, and ensured
alignment with ISO standard requirements (ISO 27001, ISO 22301, ISO 20000).
• Led weekly operational meetings with cross-functional stakeholders, including aeCERT, Cloud, and
NOC teams, and facilitated Change Control Board (CCB) sessions to assess major changes, conduct
risk and impact analysis, and ensure seamless implementation.
• Managed multiple IT security projects, including DDoS deployment, SIEM integration (LogRhythm),
Forcepoint DLP implementation, and infrastructure hardening using CIS benchmarks coordinating
closely with vendors and suppliers to ensure timely delivery and adherence to security standards
• Delivered weekly and monthly reports on security posture and SLA performance to TDRA
management, supporting proactive governance and compliance monitoring.
• Drive Continuous Improvement Plans (CIP) to maintain compliance posture and adapt to evolving
standards and regulatory requirements
• Acted as Internal Auditor, conducting audits to ensure compliance with applicable standards such as
ISO 27001/27017, ISO 22301, and ISO 20000, and driving continual improvement across business
processes.

مجال الشركة:
الاتصالات والشبكات

Manager Governance, Risk and Compliance

يناير 2011 - مارس 2015

Wipro

دبي، الإمارات العربية المتحدة

يناير 2011 - مارس 2015

Role: Consulting Manager - Governance, Risk & Compliance
Projects:

Projects: Audit Assignments

 Carry out major audit projects assignments for ISO 27001 Information security, ISO 20000, BS 25999, PCI DSS, GDPR and ISO 22301 standards.
 Perform all phases of an audit, including risk assessment, planning, identification of internal controls, audit - programs, fieldwork, and reporting in accordance with standards.
 Evaluate the significance of audit findings, and review findings, recommendations, and corrective action with Internal Audit management and audit client.
 Monitor corrective actions for adequacy and effectiveness.
 Analyze a complete risk assessment for business function / unit issues and ways on how to reduce the risks through preventive and corrective actions.
 Has recommended the industry best practices in order to further strengthen the existing information security.

Project Management & Implementation of GRC Solution
Management for Archer implementation for all the solutions for Oil Company in Abu Dhabi Implementation of solutions for a leading bank in Bahrain and India

Key responsibilities
 Implementing ARCHER in various SLDC stages including Analysis, Design, Development, Enhancement, Testing, Migration, Documentation and implementation of applications.
 Designing Workflow, High Level and Low Level diagram for all the GRC Solutions like Enterprise, Policy, Risk, Compliance, Audit and Threat Management.
 Data Feed / Import from the existing process of client within Archer Solutions
 Configured access control, record permissions, events and notifications in Archer.
 Involved in content mapping from industry best practices like ISO, NIST... etc. to Archer standards to upgrade authoritative sources for RSA Archer.
 Designing iView’s, Dashboard and Reports in Archer
 Creation of Archer User Manual as per the Business requirement.

Quality Assurance Manager for a Cyber Security Operation center

Clients: SABIC -Saudi Arabia
Key Accomplishments:
 Develop, rollout & maintain Cyber Security operation policies and processes.
 Perform audit for the in scope applications and infra to check if the defined ISMS controls are implemented and highlight the gaps (if any) to the management and follow up for the closure of the identified gaps.
 Maintain the IT security Dashboard covering all Information Security Processes to ensure that the progress are being reported to all stakeholders.
 Accountable for developing effective Security Management process
 Established KPI’s and SLA related to information security.

Risk Management and Business Continuity Management as accordance with ISO 22301 Standard

Clients: Mobily - Saudi Arabia
Key Accomplishments:
 Conducted Gap Analysis (existing readiness versus ISO 22301 requirements)
 Conducted Risk Assessment as per best practice 31000 guideline
 Developed BCM Manual, Procedures and various relevant documents as per the ISO 22301 standard requirements
 Involved in preparing Crisis Management Plan and the Fire Drills
 Collaborated with External Stakeholders and third parties for ensuring their BC Readiness
 Conducted the BC-Awareness campaigns across the organization

Conducted Audit assignment ISMS under ISO/IEC 27001:2005 and ISO 20000 and best practice like NIST, ANISA, ITIL for various industry verticals like banking, Oil, finance, education, government and aviation

Clients: State Data Centre- MIAL, SABIC, PNU, BOI, Etisalat, FGB, ADCO, NBAD- UAE, Third party service provider audit for BPO’s.

مجال الشركة:
خدمات الاستشارات التجارية
الدور الوظيفي:
تكنولوجيا المعلومات

Consulting Manager – Governance, Risk & Compliance

يناير 2011 - يناير 2015

Wipro Infotech –

أبو ظبي، الإمارات العربية المتحدة

يناير 2011 - يناير 2015

• Performed a strategic assessment and designed a security governance framework aligned with COBIT
principles for an Oil & Gas organization- SABIC, driving improvements in risk management, control
effectiveness, and alignment between IT and business goals.
• Led implementation and audit programs for ISO 27001, ISO 20000, ISO 22301, BS 25999, and ITIL,
ensuring end-to-end compliance.
• Led RSA Archer GRC platform deployments, implementing modules including Policy Management,
Enterprise Risk, Incident Management, Business Continuity, Audit, and Threat Management to
automate and streamline compliance and risk governance processes.
• Conducted detailed gap assessments for PCI DSS and GDPR, including data flow analysis, control
validation, and stakeholder interviews; delivered comprehensive compliance reports with prioritized
remediation actions to close identified gaps and support audit readiness.
• Implemented Business Continuity Management (BCM) frameworks in alignment with BS 25999 and
ISO 22301 for enterprise clients across India and the Gulf region.
• Conducted in-depth gap assessments and compliance readiness evaluations for PCI DSS, GDPR, and
SOC 2, enabling organizations to identify control deficiencies, mitigate risks, and achieve audit
preparedness.

مجال الشركة:
خدمات تكنولوجيا المعلومات

Senior Security Consultant

يوليو 2008 - يناير 2011

ITS2

الرياض، المملكة العربية السعودية

يوليو 2008 - يناير 2011

Client: Communication & Information Technology regulator (CERT-SA) - Saudi Arabia
Build and implement SIEM reporting for Security Operation center and involved with incident response teams and vulnerability management. Ensuring that procedures and controls are implemented that are capable of promptly detecting and responding to incidents, as well as the review and oversight of information security incidents.

 Review of existing System security procedures, Logical access controls, Systems parameter and configuration controls and IT change control procedures for SOC datacenter.
 Ensuring documentation regarding processes and procedures are complete and available to stakeholders.
 Accountable for developing effective Security Management process
 Conduct security audits on the systems and infrastructure
 Review security implications of proposals for changes to infrastructure managed by the SOC
 Conducting review of security audit reports and monitor preventive actions taken to improve security posture
 Ensuring any system update/modifications are going through proper change management process with necessary security representation during impact analysis
 Establishing appropriate measures to assess operational capabilities and determine compliance and effectiveness levels with the Service Management & Security Standards

مجال الشركة:
خدمات الاستشارات التجارية
الدور الوظيفي:
تكنولوجيا المعلومات

Senior Security Consultant

يوليو 2008 - ديسمبر 2010

IT Security Training & Solutions I(TS)2-

الرياض، المملكة العربية السعودية

يوليو 2008 - ديسمبر 2010

Arabia
• Supported CERT-Saudi Arabia with SIEM deployment- ArcSight, Incident Management.
• Led end-to-end SIEM implementation including log source integration, rule fine-tuning, and
customized dashboard/report development to provide actionable security insights and meet
compliance requirements.
• Implemented ISO 27001 and ISO 20000 standard-aligned information security and IT service
management policies and processes, ensuring organizational compliance and audit readiness
• Developed and implemented internal security audit and reporting systems.
• Conducted compliance checks against ISO 27001 standards

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

Security Senior Consultant

أبريل 2005 - يوليو 2008

HCL Comnet - Mumbai, India

مومباي، الهند

أبريل 2005 - يوليو 2008

 Study various systems and applications used by the different vendors.
 Understand the various business processes used by the vendors and perform a Risk Assessment.
 Review policy, procedures and existing controls.
 Assess the gaps with respect to PCI DSS and ISO27001 controls
 Classify gaps w.r.t Make recommendations for remediation.
 This engagement involved regular monitoring and reporting of various security related events through SIEM tool, preparation of KPI metrics and sharing the same with the top management for further action at their end.
 Evaluate security incident, Incident handling and Response as per security management procedures with coordination with organization Computer Security Incident Response Team.

مجال الشركة:
خدمات الاستشارات التجارية
الدور الوظيفي:
تكنولوجيا المعلومات

Senior Security Consultant

أبريل 2005 - يوليو 2008

HCL Comnet

مومباي، الهند

أبريل 2005 - يوليو 2008

• ArcSight SIEM configuration for monitoring & reporting compliance against ISO 27001.
• Participated in Security Incident Management for enterprise environments.

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

Network Security Engineer

ديسمبر 2003 - أبريل 2005

Microland

مومباي، الهند

ديسمبر 2003 - أبريل 2005

• Managed enterprise networks Security devices - IPS, firewalls, VPN, DNS, and endpoint security.

مجال الشركة:
خدمات الاستشارات التجارية
الدور الوظيفي:
تكنولوجيا المعلومات

Network Security Engineer

ديسمبر 2003 - يناير 2005

Microland Limited,

مومباي، الهند

ديسمبر 2003 - يناير 2005

• Designed and implemented ISO 27001-aligned IT security controls.
• Lead ITIL process rollouts for service improvement.

مجال الشركة:
خدمات تكنولوجيا المعلومات

Network Consultant

ديسمبر 2000 - نوفمبر 2003

Radical Solution

مومباي، الهند

ديسمبر 2000 - نوفمبر 2003

• Managed enterprise networks Security devices - IPS, firewalls, VPN, DNS, and endpoint security.
• Conducted system hardening and vulnerability management.

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

التعليم

Terna Engineering College

يونيو 1999

يونيو 1999

دبلوم عالي، computer Technology

الهند

المعدل التراكمي (نسبة مئوية): 60%

المعدل التراكمي (نسبة مئوية): 60%

Completed Diploma in Computer Technology from Mumbai Technical Board

Skills

Information Security Policy

Expert

ISO 27001

Expert

ITIL

Expert

CISSP

Expert

CISA

Expert

CERTIFIED INFORMATION SECURITY MANAGER

Intermediate

CERTIFIED INFORMATION SYSTEM AUDITOR CISA

Intermediate

CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONAL

Intermediate

PROJECT MANAGEMENT

Intermediate

INFORMATION TECHNOLOGY INFRASTRUCTURE LIBRARY

Intermediate

PRINCE2 PROJECTS IN CONTROLLED ENVIRONMENTS 2

Intermediate

CLOUD SECURITY CCSK

Intermediate

CERTIFICATE OF CLOUD SECURITY KNOWLEDGE

Intermediate

GOVERNANCE

Intermediate

ISO 22301

Expert

IS0 27017

Expert

Audit

Expert

PMP

Intermediate

ISO 20000 LA

Expert

GRC Tool - Archer

Intermediate

DLP - Forcepoint

Intermediate

SIEM- Arcsight

Intermediate

Information Security Policy

Expert

ISO 27001

Expert

ITIL

Expert

CISSP

Expert

CISA

Expert

اللغات

الانجليزية

متمرّس

التدريب و الشهادات

الشهادات

ISO 22301 Implementation

ISO 19011:2011 Guidelines for auditing management systems

Certified Ethical Hacking training

BSI ISO/IEC 27001:2005 Lead Implementer Course

Certified Information Systems Security Professional CISSP

Certified Information Systems Auditor CISA

ISO/IEC 27001:2005 Lead Auditor

Risk Management 31000 guidelines

Practitioner Certificate in Project Management

ISO/IEC 20000-1:2018 Lead Auditor

Certified Information Security Manager CISM

Cloud Security Alliance CCSK

ISO 22301:2019 Business Continuity Management Lead Auditor

Project Management Professional PMP

CISSP

May 2008

الهوايات والاهتمامات

Travelling