Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Thank you. Your report has been submitted and will be reviewed shortly.
Anees Shaikh, Manager Governance, Risk & Compliance

Anees Shaikh

Manager Governance, Risk & Compliance·E& Enterprise IoT & AI LLC

United Arab Emirates

Higher diploma, computer Technology

Work experience

Total years of experience: 25 years, 7 months

Manager Governance, Risk & Compliance

April 2015 - Present

E& Enterprise IoT & AI LLC

Dubai, United Arab Emirates

April 2015 - Present

Role: Manager Quality Assurance & Compliance
Project: UAE FEDERAL Government Project

 Experience in information security strategy and planning (strategies, roadmaps, maturity assessments, governance organization design, roles and responsibilities), defining KPIs/KRIs and measurement.
 Developing IS policies, standards, guidelines, processes and procedures
 Managed and delivered large-scale information security projects like implementation of ITIL Process, ISO 27001 ISMS, ISO 20000 Service Management, ISO 22301 BCMS and ISO 27017 Cloud security standard implementation to achieve certification
 Conducting assessments for NIST SP 800-53, COBIT, CIS, National Electronic Security Authority (NESA), National Security National Emergency Crisis and Disasters Management Authority (NCEMA), ISR (Dubai Government Information Security Resolution), Abu Dhabi Government Data Management Standards.
 Served as the designated Management Representative and liaison to 3rd party auditors.
 Performed Internal Audit and maintained all controlled documents and forms and was responsible for continuous maintenance of standards.
 Ensured efficient and effective completion of all audit requirements.
 Managed all related internal audit programs and issued corrective actions.
 Provided recommendations for business process and internal control improvements.
 Risk Management-Identifying opportunities to improve risk posture, developing solutions for remediating or mitigating risks and assessing the residual risk. Escalated potentially significant risks and exposures. Review and update the Risk register for the department.
 Developed management reports to communicate progress.
 Conduct review of security audit reports and agree with management team on actions to be taken.
 Accountable for developing effective information security and ensure continuous quality improvement for organizational operational excellence by developing, implementing and conducting comprehensive organizational quality assessments

Company industry:
Telecommunications
Job role:
Management

Manager Quality Assurance & Compliance

January 2015 - Present

E& Enterprise IoT & AI LLC-

Dubai, United Arab Emirates

January 2015 - Present

• Implemented and governed compliance across business units for ISO 20000 (ITSM), ISO 27001/27017
(Information & Cloud Security), ISO 22301 (BCM), and ITIL frameworks, ensuring alignment with
global best practices and regulatory requirements.
• Oversaw compliance with UAE regulatory mandates, including NESA, NCEMA as well as internal TDRA
cybersecurity policies and standards.
• Served as the Single Point of Contact (SPOC) for external auditors -BSI audits, internal TDRA audits,
and regulatory engagements—managing end-to-end audit coordination, evidence collection,
stakeholder communication, and timely closure of compliance findings.
• Designed and implemented an Enterprise Risk Management (ERM) framework; maintained a
comprehensive risk register across stakeholders, conducted monthly risk reviews, and ensured
alignment with ISO standard requirements (ISO 27001, ISO 22301, ISO 20000).
• Led weekly operational meetings with cross-functional stakeholders, including aeCERT, Cloud, and
NOC teams, and facilitated Change Control Board (CCB) sessions to assess major changes, conduct
risk and impact analysis, and ensure seamless implementation.
• Managed multiple IT security projects, including DDoS deployment, SIEM integration (LogRhythm),
Forcepoint DLP implementation, and infrastructure hardening using CIS benchmarks coordinating
closely with vendors and suppliers to ensure timely delivery and adherence to security standards
• Delivered weekly and monthly reports on security posture and SLA performance to TDRA
management, supporting proactive governance and compliance monitoring.
• Drive Continuous Improvement Plans (CIP) to maintain compliance posture and adapt to evolving
standards and regulatory requirements
• Acted as Internal Auditor, conducting audits to ensure compliance with applicable standards such as
ISO 27001/27017, ISO 22301, and ISO 20000, and driving continual improvement across business
processes.

Company industry:
Telecommunications

Manager Governance, Risk and Compliance

January 2011 - March 2015

Wipro

Dubai, United Arab Emirates

January 2011 - March 2015

Role: Consulting Manager - Governance, Risk & Compliance
Projects:

Projects: Audit Assignments

 Carry out major audit projects assignments for ISO 27001 Information security, ISO 20000, BS 25999, PCI DSS, GDPR and ISO 22301 standards.
 Perform all phases of an audit, including risk assessment, planning, identification of internal controls, audit - programs, fieldwork, and reporting in accordance with standards.
 Evaluate the significance of audit findings, and review findings, recommendations, and corrective action with Internal Audit management and audit client.
 Monitor corrective actions for adequacy and effectiveness.
 Analyze a complete risk assessment for business function / unit issues and ways on how to reduce the risks through preventive and corrective actions.
 Has recommended the industry best practices in order to further strengthen the existing information security.

Project Management & Implementation of GRC Solution
Management for Archer implementation for all the solutions for Oil Company in Abu Dhabi Implementation of solutions for a leading bank in Bahrain and India

Key responsibilities
 Implementing ARCHER in various SLDC stages including Analysis, Design, Development, Enhancement, Testing, Migration, Documentation and implementation of applications.
 Designing Workflow, High Level and Low Level diagram for all the GRC Solutions like Enterprise, Policy, Risk, Compliance, Audit and Threat Management.
 Data Feed / Import from the existing process of client within Archer Solutions
 Configured access control, record permissions, events and notifications in Archer.
 Involved in content mapping from industry best practices like ISO, NIST... etc. to Archer standards to upgrade authoritative sources for RSA Archer.
 Designing iView’s, Dashboard and Reports in Archer
 Creation of Archer User Manual as per the Business requirement.

Quality Assurance Manager for a Cyber Security Operation center

Clients: SABIC -Saudi Arabia
Key Accomplishments:
 Develop, rollout & maintain Cyber Security operation policies and processes.
 Perform audit for the in scope applications and infra to check if the defined ISMS controls are implemented and highlight the gaps (if any) to the management and follow up for the closure of the identified gaps.
 Maintain the IT security Dashboard covering all Information Security Processes to ensure that the progress are being reported to all stakeholders.
 Accountable for developing effective Security Management process
 Established KPI’s and SLA related to information security.

Risk Management and Business Continuity Management as accordance with ISO 22301 Standard

Clients: Mobily - Saudi Arabia
Key Accomplishments:
 Conducted Gap Analysis (existing readiness versus ISO 22301 requirements)
 Conducted Risk Assessment as per best practice 31000 guideline
 Developed BCM Manual, Procedures and various relevant documents as per the ISO 22301 standard requirements
 Involved in preparing Crisis Management Plan and the Fire Drills
 Collaborated with External Stakeholders and third parties for ensuring their BC Readiness
 Conducted the BC-Awareness campaigns across the organization

Conducted Audit assignment ISMS under ISO/IEC 27001:2005 and ISO 20000 and best practice like NIST, ANISA, ITIL for various industry verticals like banking, Oil, finance, education, government and aviation

Clients: State Data Centre- MIAL, SABIC, PNU, BOI, Etisalat, FGB, ADCO, NBAD- UAE, Third party service provider audit for BPO’s.

Company industry:
Business Consultancy Services
Job role:
Information Technology

Consulting Manager – Governance, Risk & Compliance

January 2011 - January 2015

Wipro Infotech –

Abu Dhabi, United Arab Emirates

January 2011 - January 2015

• Performed a strategic assessment and designed a security governance framework aligned with COBIT
principles for an Oil & Gas organization- SABIC, driving improvements in risk management, control
effectiveness, and alignment between IT and business goals.
• Led implementation and audit programs for ISO 27001, ISO 20000, ISO 22301, BS 25999, and ITIL,
ensuring end-to-end compliance.
• Led RSA Archer GRC platform deployments, implementing modules including Policy Management,
Enterprise Risk, Incident Management, Business Continuity, Audit, and Threat Management to
automate and streamline compliance and risk governance processes.
• Conducted detailed gap assessments for PCI DSS and GDPR, including data flow analysis, control
validation, and stakeholder interviews; delivered comprehensive compliance reports with prioritized
remediation actions to close identified gaps and support audit readiness.
• Implemented Business Continuity Management (BCM) frameworks in alignment with BS 25999 and
ISO 22301 for enterprise clients across India and the Gulf region.
• Conducted in-depth gap assessments and compliance readiness evaluations for PCI DSS, GDPR, and
SOC 2, enabling organizations to identify control deficiencies, mitigate risks, and achieve audit
preparedness.

Company industry:
IT Services

Senior Security Consultant

July 2008 - January 2011

ITS2

Riyadh, Saudi Arabia

July 2008 - January 2011

Client: Communication & Information Technology regulator (CERT-SA) - Saudi Arabia
Build and implement SIEM reporting for Security Operation center and involved with incident response teams and vulnerability management. Ensuring that procedures and controls are implemented that are capable of promptly detecting and responding to incidents, as well as the review and oversight of information security incidents.

 Review of existing System security procedures, Logical access controls, Systems parameter and configuration controls and IT change control procedures for SOC datacenter.
 Ensuring documentation regarding processes and procedures are complete and available to stakeholders.
 Accountable for developing effective Security Management process
 Conduct security audits on the systems and infrastructure
 Review security implications of proposals for changes to infrastructure managed by the SOC
 Conducting review of security audit reports and monitor preventive actions taken to improve security posture
 Ensuring any system update/modifications are going through proper change management process with necessary security representation during impact analysis
 Establishing appropriate measures to assess operational capabilities and determine compliance and effectiveness levels with the Service Management & Security Standards

Company industry:
Business Consultancy Services
Job role:
Information Technology

Senior Security Consultant

July 2008 - December 2010

IT Security Training & Solutions I(TS)2-

Riyadh, Saudi Arabia

July 2008 - December 2010

Arabia
• Supported CERT-Saudi Arabia with SIEM deployment- ArcSight, Incident Management.
• Led end-to-end SIEM implementation including log source integration, rule fine-tuning, and
customized dashboard/report development to provide actionable security insights and meet
compliance requirements.
• Implemented ISO 27001 and ISO 20000 standard-aligned information security and IT service
management policies and processes, ensuring organizational compliance and audit readiness
• Developed and implemented internal security audit and reporting systems.
• Conducted compliance checks against ISO 27001 standards

Company industry:
IT Services
Job role:
Information Technology

Security Senior Consultant

April 2005 - July 2008

HCL Comnet - Mumbai, India

Mumbai, India

April 2005 - July 2008

 Study various systems and applications used by the different vendors.
 Understand the various business processes used by the vendors and perform a Risk Assessment.
 Review policy, procedures and existing controls.
 Assess the gaps with respect to PCI DSS and ISO27001 controls
 Classify gaps w.r.t Make recommendations for remediation.
 This engagement involved regular monitoring and reporting of various security related events through SIEM tool, preparation of KPI metrics and sharing the same with the top management for further action at their end.
 Evaluate security incident, Incident handling and Response as per security management procedures with coordination with organization Computer Security Incident Response Team.

Company industry:
Business Consultancy Services
Job role:
Information Technology

Senior Security Consultant

April 2005 - July 2008

HCL Comnet

Mumbai, India

April 2005 - July 2008

• ArcSight SIEM configuration for monitoring & reporting compliance against ISO 27001.
• Participated in Security Incident Management for enterprise environments.

Company industry:
IT Services
Job role:
Information Technology

Network Security Engineer

December 2003 - April 2005

Microland

Mumbai, India

December 2003 - April 2005

• Managed enterprise networks Security devices - IPS, firewalls, VPN, DNS, and endpoint security.

Company industry:
Business Consultancy Services
Job role:
Information Technology

Network Security Engineer

December 2003 - January 2005

Microland Limited,

Mumbai, India

December 2003 - January 2005

• Designed and implemented ISO 27001-aligned IT security controls.
• Lead ITIL process rollouts for service improvement.

Company industry:
IT Services

Network Consultant

December 2000 - November 2003

Radical Solution

Mumbai, India

December 2000 - November 2003

• Managed enterprise networks Security devices - IPS, firewalls, VPN, DNS, and endpoint security.
• Conducted system hardening and vulnerability management.

Company industry:
IT Services
Job role:
Information Technology

Education

Terna Engineering College

June 1999

June 1999

Higher diploma, computer Technology

India

GPA (percentage): 60%

GPA (percentage): 60%

Completed Diploma in Computer Technology from Mumbai Technical Board

Skills

Information Security Policy

Expert

ISO 27001

Expert

ITIL

Expert

CISSP

Expert

CISA

Expert

CERTIFIED INFORMATION SECURITY MANAGER

Intermediate

CERTIFIED INFORMATION SYSTEM AUDITOR CISA

Intermediate

CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONAL

Intermediate

PROJECT MANAGEMENT

Intermediate

INFORMATION TECHNOLOGY INFRASTRUCTURE LIBRARY

Intermediate

PRINCE2 PROJECTS IN CONTROLLED ENVIRONMENTS 2

Intermediate

CLOUD SECURITY CCSK

Intermediate

CERTIFICATE OF CLOUD SECURITY KNOWLEDGE

Intermediate

GOVERNANCE

Intermediate

ISO 22301

Expert

IS0 27017

Expert

Audit

Expert

PMP

Intermediate

ISO 20000 LA

Expert

GRC Tool - Archer

Intermediate

DLP - Forcepoint

Intermediate

SIEM- Arcsight

Intermediate

Information Security Policy

Expert

ISO 27001

Expert

ITIL

Expert

CISSP

Expert

CISA

Expert

Languages

English

Expert

Trainings and Certifications

Certifications

ISO 22301 Implementation

ISO 19011:2011 Guidelines for auditing management systems

Certified Ethical Hacking training

BSI ISO/IEC 27001:2005 Lead Implementer Course

Certified Information Systems Security Professional CISSP

Certified Information Systems Auditor CISA

ISO/IEC 27001:2005 Lead Auditor

Risk Management 31000 guidelines

Practitioner Certificate in Project Management

ISO/IEC 20000-1:2018 Lead Auditor

Certified Information Security Manager CISM

Cloud Security Alliance CCSK

ISO 22301:2019 Business Continuity Management Lead Auditor

Project Management Professional PMP

CISSP

May 2008

Hobbies and interests

Travelling