Bandar Alharbi, SENIOR INFORMATION SECURITY AND RISK CONSULTANT

Bandar Alharbi

SENIOR INFORMATION SECURITY AND RISK CONSULTANT

SAMA

Location
Saudi Arabia
Education
Master's degree, Network Security
Experience
12 years, 6 Months

Share My Profile

Block User


Work Experience

Total years of experience :12 years, 6 Months

SENIOR INFORMATION SECURITY AND RISK CONSULTANT at SAMA
  • Saudi Arabia - Riyadh
  • My current job since March 2017
SENIOR INFORMATION SECURITY SPECIALIST at Saudi Aramco
  • Saudi Arabia - Eastern Province
  • January 2012 to August 2015

Best Learning Experience: in August 2012, I engaged with the IR team in the forensic investigation and services restoration of the biggest cyber attack in cyber history that hit Aramco.
Evaluating and enhancing the security of perimeter network devices such as BGP and VSAT gateways
Evaluating existing IT security solutions for identifying gaps and proposing new security technologies
Performing vulnerability assessment and configuration compliance assurance for network devices
Performing technical security reviews for network protocols and services: RADIUS, EAP variants, 802.1x, CCMP, DNS, DHCP, OSPF, BGP
Advising and assisting various IT departments in projects related to information security (e.g. SCADA)
Revising and improving existing security standards, polices, procedures, guidelines and baselines
Defining and testing technical security requirements for Wi-Fi and VoIP infrastructure
Participating in security awareness programs and educational efforts
Investigating security incidents as a tier-three analyst
Updating and upgrading security systems as needed

INFORMATION SECURITY EXPERT at Ministry of Foreign Affairs
  • Saudi Arabia - Riyadh
  • October 2011 to January 2012

Conducting IT risk assessment for the ministry headquarter and branches
Revising existing policies, procedures, standards, baselines and guidelines
Designing and building an Information Security Awareness Program based on the ministry's policies and requirements

INFORMATION SECURITY OFFICER at Ministry of Higher Education
  • Saudi Arabia - Riyadh
  • January 2010 to January 2011

Overseeing policies and procedures regarding the security of information assets
Overseeing identity and access management
Briefing executives on status and risks
Identifying goals and objectives for the ministry's IT security
Creating IT security units with specific responsibilities to implement the SoD model
Leading the design of a new DMZ for hosting servers that provide Internet-facing services
Making sure that vulnerabilities and compliance issues are addressed in accordance with its risk rates
Leading the implementation of disaster recovery, business continuity and ISO 27001 projects
Leading the implementation of security best practices
Activating and configuring non-utilized, existent security features and technologies to increase the security level and reduce the annual spending

NETWORK ADMIN AND DEVELOPER at Medina Chamber of Commerce & Industry
  • Saudi Arabia - Medina
  • January 2006 to March 2006

Installing network appliances such as switches, routers, PIX firewalls and Novell devices
Configuring, maintaining and troubleshooting server farms and network platforms
Working as a system analyst and a programmer
Assisting in technical writings and revisions

Education

Master's degree, Network Security
  • at DePaul University
  • July 2009

Master of Science in Computer, Information and Network Security, GPA: 3.923 out 4 DePaul University, Chicago, IL, Graduation with Distinction: July 2009 Graduation: Securing all OSI layers of a virtual IT data center by applying IT security standards Intensive English Program

Diploma, Intensive English Program
  • at DePaul University, English Language Academy
  • December 2007

DePaul University, English Language Academy, Chicago, IL, June 2006 - December 2007

Bachelor's degree, Computer Science
  • at Taibah University
  • August 2005

Taibah University, Medina, Graduation: August 2005 Graduation: In-depth Studying of cryptographic algorithms and coding an AES program. Bachelor of Science in Computer Science, GPA: 3.87 out 5

Specialties & Skills

System Security
Network Security
Information Security Policy
Vulnerability Assessment
Information Security Management
INFORMATION SECURITY
IT INFRASTRUCTURE
SECURITY
VULNERABILITY ASSESSMENT
Network Security
Cryptography
network design and management, incidents response and forensics
BlueCoat, IronPort, F5, Foundry, FortiGate, McAfee IPS, Snort IPS, NetWare, Aruba ClearPass,
Cisco, Juniper and HP networking and security platforms
Hands-on experience on most of the well-known hacking, networking, password cracking, forensics
TECHNICAL SKILLS C/C++/Python Deep understanding of OSI and TCP/IP models GRC, PT, VA,
IBM Netcool, Great Bay, InfoBlox, FireEye, Juniper STRM, BIND, LAMP, ActiveDirectory, Citrix, Linux
malware dissecting, VoIP, and encryption tools as well as Linux and Windows system utilities

Languages

Arabic
Expert
English
Expert

Memberships

Golden Key International Honour Society
  • Honour Memeber
  • May 2009
Upsilon Pi Epsilon
  • Honour Memeber
  • May 2009
Saudi Aramco
  • Aramco Recognition Ward of 2013
  • May 2014
Saudi Aramco
  • Aramco Recognition Award of 2014
  • May 2015

Training and Certifications

Offensive Security Certified Expert (OSCE) (Certificate)
Date Attended:
December 2016
Offensive Security Certified Professional (OSCP) (Certificate)
Date Attended:
May 2016
EC-Council Computer Hacking Forensics Investigator (CHFI) (Certificate)
GIAC Certified Enterprise Defender (GCED) (Certificate)
EC-Council Certified Ethical Hacker (CEH) (Certificate)
GIAC Certified Incident Handler (GCIH) (Certificate)
Penetration Testing with Kali Course (PWK) (Certificate)
Aruba Certified ClearPass Professional (ACCP) (Certificate)
SANS NetWars Continuous: an online hands-on hacking-and-defending course (Certificate)
Certified Information Systems Security Professional (CISSP) (Certificate)
SecurityTube Wi-Fi Security Expert (SWSE) (Certificate)
Juniper Networks Certified Associate Junos (JNCIA) (Certificate)
SANS NetWars Tournaments: Digital Forensics and Incident Response (DFIR) and Core (Certificate)
Network Security device and Proxy (Training)
Training Institute:
McAfee Web Gateway System Administration
Date Attended:
October 2012
Network Security Appliance (Training)
Training Institute:
JUNOS Security (JSEC) and Advanced JUNOS for Security Platforms (AJSEC)
Date Attended:
December 2012
Network Security Appliance (Training)
Training Institute:
Implementing Cisco Intrusion Prevention System (IPS)
Date Attended:
January 2010
Network Security Appliance (Training)
Training Institute:
Introduction to the JUNOS Operating System (IJOS) and JUNOS Routing Essentials (JRE)
Date Attended:
December 2012
Network Security Appliance (Training)
Training Institute:
Configuring Juniper Secure Access (CJSA) and Advanced Juniper Secure Access (AJSA)
Date Attended:
June 2010
Network Switches (Training)
Training Institute:
HP E-Series Networking Technologies
Date Attended:
June 2012