كلما زادت طلبات التقديم التي ترسلينها، زادت فرصك في الحصول على وظيفة!

إليك لمحة عن معدل نشاط الباحثات عن عمل خلال الشهر الماضي:

عدد الفرص التي تم تصفحها

عدد الطلبات التي تم تقديمها

استمري في التصفح والتقديم لزيادة فرصك في الحصول على وظيفة!

هل تبحثين عن جهات توظيف لها سجل مثبت في دعم وتمكين النساء؟

اضغطي هنا لاكتشاف الفرص المتاحة الآن!
نُقدّر رأيكِ

ندعوكِ للمشاركة في استطلاع مصمّم لمساعدة الباحثين على فهم أفضل الطرق لربط الباحثات عن عمل بالوظائف التي يبحثن عنها.

هل ترغبين في المشاركة؟

في حال تم اختياركِ، سنتواصل معكِ عبر البريد الإلكتروني لتزويدكِ بالتفاصيل والتعليمات الخاصة بالمشاركة.

ستحصلين على مبلغ 7 دولارات مقابل إجابتك على الاستطلاع.


تم إلغاء حظر المستخدم بنجاح
الهام السعد, Information Security Compliance & Offensive Security

الهام السعد

Information Security Compliance & Offensive Security ·Saudi National Bank

المملكة العربية السعودية

بكالوريوس, Information Technology

الخبرة العملية

مجموع سنوات الخبرة: 5 سنوات, 11 أشهر

Information Security Compliance & Offensive Security

أبريل 2026 - حتى الآن

Saudi National Bank

جدة، المملكة العربية السعودية هجين

أبريل 2026 - حتى الآن

During my time with SNB, I was given the opportunity to develop my technical skills in the field using the Immersive Labs Platform:

• Enumeration Scanning Tools
◦ Nikto and DIRB, WordPress Scan, Port Knocking, DNS Enumeration, Banner Grabbing, Nmap
• Windows Hardening
Reconnaissance - Hardening with Microsoft Defender Firewall
◦ Analyzed a penetration testing report findings and translated remediation recommendations into
Windows host-based firewall controls, as listed below.
◦ Implemented Windows hardening measures (least privilege and network segmentation) using
Microsoft Defender Firewall with Advanced Security, including the creation, and modification of
inbound service-specific rules and profile-based firewall rules, such as:
◦ Creating and enabling an inbound firewall rule to allow FTP traffic on TCP port 21 for
Domain profiles only
◦ Blocking unnecessary remote management services such as MSRPC on TCP port 135
for Public Profile
◦ Restricted Remote Desktop Protocol (RDP) access by defining authorized remote IP address
ranges and limiting connectivity to approved corporate subnets.
◦ Applied network segmentation and least privilege principles through firewall scope configuration,
profile-based rule enforcement (Domain, Private, and Public), and IP-based access restrictions.
◦ Gained hands-on experience interpreting vulnerability remediation recommendations and imple
menting compensating security controls at the host level.

مجال الشركة:
أمن المعلومات و الشبكات
الدور الوظيفي:
البنوك

Information Security Compliance

أبريل 2026 - حتى الآن

Saudi National Bank

جدة، المملكة العربية السعودية

أبريل 2026 - حتى الآن

• Facilitated and coordinated SNBC information security audit requirements
• Performed a compliance assessment against the NCA-TCC, developed detailed report, maintained
evidence, tracker, and reported findings to management for remediation action
• Led an audit engagement for the Cortex Credit Card Management System between the Internal Audit
and the Information Security Department.
• Familiarity of SAMA electronic banking requirements and related compliance check reviews
• Assisted in preparing the RFIs, and validating the received evidence related to SAMA electronic
banking requirements, and updating the compliance tracker and associated reports accordingly
• Responsible for validating KPI/KRI values and evidence on quarterly basis
• Effectively communicated the KPI/KRI gaps to senior management and cross-functional stakeholders
• Performed compliance assessments against +6 of SNB information security internal policies, covering
15% of each policy in three months
• Collaborated with the team to perform a compliance assessment against the ISM Main Policy and
reported findings to senior colleagues
• Conducted a gap assessment against the NCA-DCC framework, identifying over 10 new gaps from
previous year
• Assisted in following up with the SNB asset inventories and in ensuring asset inventories compliance
with SAMA requirements and observations
• Provided support to the line manager on various tasks as assigned
• Responsible for consolidating team updates and preparing summary presentations for the line
manager to track progress on a weekly basis.
• Experience in utilizing the automation tool Archer for KPI and KRI activities
• Led the automation of the SAMA thematic inspection observations in Archer tool by designing the
workflow process, creating supporting documentation and diagrams, and successfully coordinating
and communicating the implementation details to the Archer administrator, in addition to responding
to the follow-up inquiries, leading to successfully implementing the project
• Participated in reviewing an information security policy to ensure its compliance with NCA and SAMA
regulations
• Performed a comprehensive review on SNBs information security CMMI to enhance its maturity
level, covering 200 controls under the strategy domain, and resulting in a 12% improvement in overall
maturity.
• Basic familiarity of the various systems and security tools in use, such as Centrify, Blackberry MDM,
SCCM, SOAR, Citrix, AnyConnect VPN, Active Directory, DLP, GetVisibility, Informatica

مجال الشركة:
البنوك
الدور الوظيفي:
البنوك

Cybersecurity and IT support Intern

ديسمبر 2023 - فبراير 2026

Saudi Geological Survey (CyberPro+)

جدة، المملكة العربية السعودية

ديسمبر 2023 - فبراير 2026

• Participated in updating policies and drafting change requests to update policies
• Evaluated the cybersecurity service providers services against the Saudi Geological Survey
Cybersecurity Tender prior to outsourcing their services
• Assisted in formatting laptops, installing windows operating system, configuring user/admin accounts,
installing desktops applications (Microsoft Office, EDR, Antivirus, TeamWork), connecting devices
into the organizations network, updating softwares license and hardwares drivers

مجال الشركة:
السلامة والبيئة

Cybersecurity GRC Specialist

يونيو 2023 - ديسمبر 2025

Bupa Arabia for Cooperative Insurance

جدة، المملكة العربية السعودية

يونيو 2023 - ديسمبر 2025

• Following up with the cybersecurity KPIs
• Familiarity with NCA-ECC, DCC, and SAMA CSFs
• Reviewing +5 cloud service providers contracts to address all SAMA required outsourcing clauses
before outsourcing any service into the cloud
• Filling SAMA outsourcing forms and answering SAMA questions regarding the cybersecurity posture
of cloud service providers
• Participated in facilitating requirements during the gap assessment phase of the NDMO project
between Bupa and its third party
• Risk Key Tasks:
• Familiarity with the Third-Party Risk Management Framework
• Participated in classifying the level of access of service providers to Bupas data and in assessing
service providers cybersecurity posture through preparing a list of tailored questions (RFIs) for each
service provider to collect evidence of identified risks prior to onboarding them
• Governance Key Tasks:
• Participated in the development of a draft policy to comply with SAMA minimum verification controls
according to their applicability to Bupas applications in alignment with the Information Technology
team input
• Mapping policiess controls to their references and updating policies revision dates
• Facilitating the publication of newly approved policies

مجال الشركة:
التأمين
الدور الوظيفي:
تكنولوجيا المعلومات

Cybersecurity Intern

سبتمبر 2022 - نوفمبر 2025

Jeddah Municipality (CyberPro+)

جدة، المملكة العربية السعودية

سبتمبر 2022 - نوفمبر 2025

• Participated in the GRC function
• Familiarity with IT security tools (e.g., EDR, NDR, VA, Email Security, WAF, McAfee ePolicy
Orchestrator Administration, Arbor)

مجال الشركة:
الهندسة المعمارية
الدور الوظيفي:
تكنولوجيا المعلومات

COOP Intern

يونيو 2020 - أغسطس 2025

Ministry of Communications and Information Technology

جدة، المملكة العربية السعودية

يونيو 2020 - أغسطس 2025

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
المحاسبة والتدقيق

التعليم

King Abdul-Aziz University

سبتمبر 2021

سبتمبر 2021

بكالوريوس، Information Technology

المملكة العربية السعودية

المعدل التراكمي (نقاط): 4.34 من 5

المعدل التراكمي (نقاط): 4.34 من 5

Graduated with second class honors

Skills

MICROSOFT POWERPOINT
Beginner
MICROSOFT POWERPOINT
Beginner
MICROSOFT WORD
Beginner
MICROSOFT WORD
Beginner
TIME MANAGEMENT
Beginner
TIME MANAGEMENT
Beginner
Coordination
Expert
Coordination
Expert
Fast Learning
Expert
Fast Learning
Expert
Communications
Expert
Communications
Expert
Microsoft Excel
Intermediate
Microsoft Excel
Intermediate
Analytical Mindset
Expert
Analytical Mindset
Expert
Compliance
Expert
Compliance
Expert
English
Expert
English
Expert
Audit coordination
Expert
Audit coordination
Expert
MANAGEMENT
Expert
MANAGEMENT
Expert
CYBER SECURITY
Expert
CYBER SECURITY
Expert
DETAIL ORIENTED
Expert
DETAIL ORIENTED
Expert
STRONG WORK ETHIC
Expert
STRONG WORK ETHIC
Expert
REGULATORY COMPLIANCE
Expert
REGULATORY COMPLIANCE
Expert
QUICK LEARNING
Expert
QUICK LEARNING
Expert
PROFESSIONALISM
Expert
PROFESSIONALISM
Expert
TEAMWORK
Expert
TEAMWORK
Expert
BANKING
Intermediate
BANKING
Intermediate
COMPUTER SECURITY
Intermediate
COMPUTER SECURITY
Intermediate
NIKTO WEB SCANNER
Intermediate
NIKTO WEB SCANNER
Intermediate
NMAP
Intermediate
NMAP
Intermediate
TECHNICAL SUPPORT
Intermediate
TECHNICAL SUPPORT
Intermediate

اللغات

العربية

متمرّس

الانجليزية

متمرّس

التدريب و الشهادات

الشهادات
CompTIA – Security+ Certified
CompTIA – CySA+ Certified
GIAC GCIA Certified
CyberPro+ Program
CompTIA – Security+ Certified
CompTIA – CySA+ Certified
GIAC GCIA Certified
CyberPro+ Program
GCIA
SANS

الهوايات والاهتمامات

Learning

GCIA - SANS CySA+ - CompTIA Security+ - CompTIA Just finished recently my internship with Jeddah Municipality in the department of Cybersecurity.