Fahad Aalem, Cyber Security Manager

Fahad Aalem

Cyber Security Manager

haboob

Location
Saudi Arabia - Riyadh
Education
Master's degree, E-MBA
Experience
13 years, 8 Months

Share My Profile

Block User


Work Experience

Total years of experience :13 years, 8 Months

Cyber Security Manager at haboob
  • Saudi Arabia - Riyadh
  • My current job since March 2020
Governance Risk and compliance Supervisor at General Authority and Zakat and Tax
  • Saudi Arabia - Riyadh
  • May 2018 to May 2020

o Negotiated 4 contracts, overall worth $4.5M (16M SAR) over 2 years, by understanding stakeholders key needs. Key wins, added Escrow agreements and project closed under-budget.
o Conformed governance with high degree of fidelity in strategic projects through value realization process with key stakeholders.
o Guided GAP assessment(Current Vs ISO27001) and maturity assessment(CPA) projects.
o Key stakeholder in building an enterprise security strategy aligned with business and IT strategies.
o Managed IAM project for Infrastructure services and business services (CRM).
o Guided an integrated IT framework of ITIL, TOGAF, COBIT and PMP as a starting point for IT and IS strategy leaning towards ISO27001.
o lead ISO 27001, starting with Identity Access Management, DB encryption, Document Security and the physical security projects.
o Customized Information Security’s framework, policy and procedures constituting both compliance with NCA and ISO 27001 requirements, as well as achieving business monetary goals.
o Played a key role in contributing to IS initiatives by efficient monitoring of performance, optimizing workflow and creating enhanced processes.
o Identified service catalogue for Information Security department.
o Interviewed business and IT managements to ensure a complete understanding of the value realized from building and maintain User Access Matrices through across core functions.
o Adopted Single Sign On(SSO) approaches into critical functions.
o Part of the team to build the Asset Management Life Cycle.
o Developed and communicated Acceptable Use Policy(AUP), Mobile Management Policy(MDM), Bring Your Own Device(BYOD).
o Auditing IT Assets for MBSS and communicating Security Coding Standards with its relevant testing scenarios to ensure efficient implementation of controls.
o Evaluated (Security Operation Center) power of authority and level of access based on the outsourcing identified risks.

Information Security Governance Specialist at Trusted Securities
  • Saudi Arabia - Riyadh
  • August 2017 to May 2018

o Played a role in implementing Enterprise Project Management Office throughout the organization.
o Co-lead 1 year Security Awareness program for a government agency.

Quality Management Specialist at Bank Al Bilad
  • Saudi Arabia - Riyadh
  • November 2014 to August 2017

Implementing projects relating to IT operations business change, customer service improvement, quality, policy and
procedures management as strategic imperatives across the organization
 Conceptualizing and developing compelling business cases for IT organizational change and driving change initiatives across
stakeholder groups
 Aligning the organization to IT business excellence frameworks
 Implementing best practice and standardization of policies and processes framework in IT operations to drive consistency,
efficiency and client centricity
 Supporting innovation and creativity to improve products, services and customer experience
 Accurately mapping critical moments for designing future IT process & process changes to enhance productivity
 Partnering cross functionally Sr Executives to build an effective strategy and route map for positive change and success

Technical Project Manager at bankalbilad
  • Saudi Arabia - Riyadh
  • November 2012 to November 2014

Key Accountabilities
 Mainline responsibility for devising/establishing quality policies and driving various quality management initiatives
 Be responsible for
o Controlling 3Ps (Policy, Procedures and Process) Project for Information Technology Governance (ITG)
establishment program
o Developing procedures for ITG Process Management Unit and Data Governance departments and composing
Change Management document
o Supporting testing teams and production teams
o Streamlining operations by conducting operational administration of TFS 2010 and TFS-EPM integration, and
analyzing resources historical estimations to conclude accurate buffering
o Enhancing operational efficiency through coordinating change requests, monitoring performance, optimizing
workflow, and creating, reviewing and updating ITSD documentations
o Ensuring service efficiency by developing Release Management and Quality Management documents, and
creating KPI’s for Process Management Unit
o Created and Implemented Quality Management system on an organizational, departmental and operational
levels.
 Generate various MIS reports for review by Senior Management
Significant Attainments
 Successfully
o Achieved 20% increase in ITSDs effectiveness and efficiency and increased stakeholders’ satisfaction by monitoring
all projects and applying Enterprise Project Management (EPM)
o Directed, controlled and managed predicted conflicts with stakeholders
o Played a key role in contributing to IT Solution & Development

Executive Assistant at Credit Suisse Saudi Arabia
  • Saudi Arabia - Riyadh
  • July 2011 to July 2012

Providing Assistant to CEO and COO in arranging meeting with potential clients, supporting to OGM/EGM meetings and board members meetings.

Call Center Agent at Saudi Airlines
  • Saudi Arabia - Riyadh
  • January 2007 to January 2008

Making Travel Reservations

Education

Master's degree, E-MBA
  • at Al Yamamah University
  • December 2016

Executive MBA

Bachelor's degree, Information Systems
  • at King Saudn University
  • March 2012

Specialties & Skills

IT Strategy
Risk Management
IT Governance
Information Security
Project Management
Risk Management
ISO27001
Security Framework
Managing New Managers
NCA ECC
Enterprise Architecture
Change Management
ISO31000
Identity Access Management
Resource Management
Enterprise Risk Management
ISO9001
Information Technology
Information Security Management
Strategic Planning
Mentoring
Organizational Leadership
Process Enhancement
Business Transformation
Public Relation
IT Security Assessment
IT Security Best Practises
Information Security Management System
Conflict Management
Training Development
Communication
Coaching
Leadership Foundation
Stakeholder Management
Leading without Formal Authority
strategy Governance
strategy development
budgeting

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Expert

Training and Certifications

Security + (Certificate)
Date Attended:
August 2021
CISSP (Certificate)
Date Attended:
December 2019
CISSP (Certificate)
Date Attended:
December 2019
ISO31000 (Training)
Training Institute:
BSI Group
Date Attended:
July 2019
Duration:
20 hours
ISO27001 LI (Certificate)
Date Attended:
July 2019
COBIT5 Foundation (Certificate)
Date Attended:
December 2018
MGT414 SANA Training Program for CISSP Certification (Certificate)
Date Attended:
October 2019
Valid Until:
October 2019
Design-Driven Leadership (Certificate)
Date Attended:
March 2019
الاحتيال وغسيل الاموال (Training)
Training Institute:
بنك البلاد
Date Attended:
July 2014
Duration:
18 hours
Ethical Hacking (Training)
Training Institute:
Center of Excellence in Information Assurance
Date Attended:
June 2011
Secure Coding using ASP.NET (Training)
Training Institute:
Center of Excellence in Information Assurance
Date Attended:
August 2011

Hobbies

  • Top of the Line Home Cinema
    (12.2 speakers), for, Atmos, or Aura3d etc... and on top of that read about a lot of speakers(Boss) and speakers properties, like crossover sounds, delay time, or response time. the challenge was finding an adequate audio receiver in my setup was (Dennon). now to tunning up my workstation at home to push for 4k and DTS:X,
  • Hosting Game Servers
    Hosting a dedicated server for Call of Duty 4, configuring the network to accept a specific port on my STC ADSL modem, and forwarding another port for another private server for extra resources. configured 4 modems 'my gateway is a fiperobtic modem, the second modem had to be configured as a static ip - as I needed to act as an access point instead of a modem' then I connected the rest