Asharaf Haddad, Sr. Inforation Security Officer

Asharaf Haddad

Sr. Inforation Security Officer

Societe Generale Bank Jordan SGBJ

البلد
الأردن
التعليم
ماجستير, MBA
الخبرات
13 years, 1 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :13 years, 1 أشهر

Sr. Inforation Security Officer في Societe Generale Bank Jordan SGBJ
  • الأردن - عمان
  • أشغل هذه الوظيفة منذ يونيو 2019
Sr.Information Security Officer في Microfund for women
  • الأردن - عمان
  • أشغل هذه الوظيفة منذ أبريل 2018

Manage and Implement Cyber security & ISO 27k regulatory requirements in the Company environment

Manage and Implement IT Governance program ( COBIT 5)regulatory requirements in the Company environment

Manage and Develop Business continuity and disaster recovery plan


Develop information security programs, policies and procedures, and successfully executing these programs that meet the bank objectives

Accountable for the development and management of the IS budget.

Ensure management information reports from the IS meetings highlight key risks and action

Senior Risk Management Officer \ Information security في Ahli Micro-finance Company
  • الأردن - البلقاء‎
  • أكتوبر 2014 إلى مارس 2018

Create, Implement and enforce Information Security Policies, Procedures, and controls.

Perform planning, implementation and tracking of assigned security projects.

Perform risk assessment for each functional area in Ahli-microfinance company.

Translating the information security requirements into specific security controls for network, application, database, operating systems, etc.

Maintain & Develop ISO 27001 Certification.

Maintain & Develop disaster recovery and Business continuity plan

Participate in Create and develop access privileges manual.

Real Time Monitoring, Detection, Analysis & Response for security events using SEIM & IDS solutions.

Conduct monthly Vulnerability Assessment (VA) against Ahli-microfinance company servers, user PCs and databases.

IT auditor في Ahli microfinance company
  • الأردن - عمان
  • مايو 2011 إلى سبتمبر 2014

Identification and reporting of audit issues and recommendations.

Perform auditing on the IT department, including other departments that work along with Information Systems.

Evaluate controls and compliance with internal policies and procedures

Lead and perform a variety of IT audit reviews, including, Applications, Infrastructure, and Systems Development


Partnering with the Financial Audit Team to assist with the approach of testing other IT dependent controls

IT Projects - Security Involvement

الخلفية التعليمية

ماجستير, MBA
  • في The Hashemite University
  • سبتمبر 2012
بكالوريوس, Management Information System
  • في Al-Balqa' Applied University
  • يناير 2011

Specialties & Skills

ISO 27001
Risk Management
IT Audit
Information Security Management
Information Security
IT Auditing & Compliance
IT Risk management
IT Strategic Planning
Service Management
internal control

اللغات

العربية
متمرّس
الانجليزية
متوسط

التدريب و الشهادات

Certified Information Systems Auditor (CISA) (تدريب)
معهد التدريب:
Newhorizons
تاريخ الدورة:
October 2012
المدة:
40 ساعة
Certified Ethical Hacking V8 (CEH) (تدريب)
معهد التدريب:
Newhorizons
تاريخ الدورة:
August 2014
المدة:
40 ساعة