Farrukh Riaz مالك, Manager, Information Security & Compliance

Farrukh Riaz مالك

Manager, Information Security & Compliance

Banawi Industrial Group

البلد
الإمارات العربية المتحدة - دبي
التعليم
دبلوم, CISSP (Certified Information Systems Security Professional)
الخبرات
17 years, 11 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :17 years, 11 أشهر

Manager, Information Security & Compliance في Banawi Industrial Group
  • المملكة العربية السعودية - جدة
  • أشغل هذه الوظيفة منذ يناير 2012

• Manage information risk to an acceptable level to meet the business and compliance requirements of the organization.
• Establish and manage the information security program in alignment with the information security leading practices.
• Plan, establish and manage the capability to detect, investigate, respond to and recover from information security incidents to minimize business impact.

Senior Consultant في PwC
  • غير ذلك
  • نوفمبر 2009 إلى ديسمبر 2011

• Managing and delivering Information Management & Security related advisory projects.
• Responsible for managing complete lifecycle of IT Governance and Information Security related projects from analyzing RFP, developing proposals, project delivery and post project activities.
• Conducting internal and external IT Governance related trainings for staff and clients.
• Conducting Information Systems Process Re-engineering projects.

MAJOR PROJECTS

DEVELOPMENT OF DISASTER RECOVERY PLAN FOR MHD OMAN AS TEAM LEADER

DEVELOPMENT OF DATA CLASSIFICATION FRAMEWORK FOR OETC AS TEAM LEADER

IMPLEMENTATION OF (ISO 27001) INFORMATION SECURITY MANAGEMENT SYSTEM FOR MUSCAT SECURITIES MARKET & MOHSIN HAIDER DARWISH OMAN AS TEAM LEADER

INFORMATION SYSTEMS AUDIT TRAINING AS INSTRUCTOR

DEVELOPING PROJECT MANAGEMENT OFFICE FOR OETC AS TEAM LEADER

Senior Consultant في Ernst & Young (EY)
  • غير ذلك
  • مايو 2008 إلى أكتوبر 2009

• Information Technology Process Control Assessment and Consultancy Services.
• Revenue Management Chain & Revenue Assurance Advisory.
• Appraisal of Information Security Management System.
• IT Audits and Information System Evaluation.

MAJOR PROJECTS

IT PROCESS AUDIT & EVALUATION FOR NATIONAL BANK OF OMAN

CORE BANKING SYSTEM DATA MIGRATION ASSURANCE PROJECT FOR BANK MUSCAT

CORPORATE SECURITY AFFAIRS ADVISORY PROJECT FOR OMAN LNG

IT PROCESS AUDIT & EVALUATION FOR OMAN QATARI TELECOM (NAWRAS) AS TEAM LEADER

IT ORGANIZATION RESTRUCTURING USING ITIL FOR OMAN GAS COMPANY (OGC) AS TEAM LEADER

DEVELOPMENT OF IT STRATEGIC PLAN USING COBIT FOR OETC AS SECTION TEAM LEADER

INFORMATION SECURITY MANAGEMENT PROJECT FOR OMAN AIR SERVICES AS TEAM LEADER

ORACLE ERP INTEGRITY REVIEW FOR GDI QATAR USING EY ANALYZER

DEVELOPED SELF ASSESSMENT WORKSHEETS FOR BANK MUSCAT BASED ON E&Y IT EFFECTIVENESS METHODOLOGY

Senior Associate في KPMG, Pakistan
  • غير ذلك
  • نوفمبر 2007 إلى أبريل 2008

• Information Risk Management Advisory for systems in use by the clients.
• Assessment of Security Controls in place for the safeguard of information assets.
• Business Process controls review.

MAJOR PROJECTS

Entity level controls assessment

Financial reporting process review

Logical and Physical security assessment

Change Management Procedure Implementation

Data Backup system and Disaster Recovery Plan review.

MAJOR CLIENTS

United Bank Limited

DHL Express Pakistan

NJI Life Insurance Company

Engro Chemicals Pakistan ltd.

System & Application Engineer (Secure Payments) في Infotel Pakistan
  • باكستان - كراتشي
  • فبراير 2007 إلى نوفمبر 2007

• Installation, Commissioning and Technical Support for THALES’ Communication & Transaction Security Equipments for ATM Networks & Secure Card Payment Systems:
HSM (Host Security Modules), DC2K (DataCryptor 2000), P3 (Personalization Preparation Process)
• Technical support to the Master Card & VISA International regarding DTUs, Routers, Firewalls.

IT Administrator في HnF Communications
  • باكستان - كراتشي
  • يونيو 2006 إلى يناير 2007

• To setup Network Infrastructure for Voice communication over Internet for Tele Marketing.
• To design and implement CMS (Call Management System).
• Technical support for Asterisk System.

الخلفية التعليمية

دبلوم, CISSP (Certified Information Systems Security Professional)
  • في ISC2
  • فبراير 2009

Certified Information Systems Security Professional (CISSP) is an independent information security certification governed by International Information Systems Security Certification Consortium also known as (ISC)². A CISSP is an information assurance professional who defines the architecture, design, management and/or controls that assure the security of business environments. The vast breadth of knowledge and the experience it takes to pass the exam is what sets the CISSP apart. The credential demonstrates a globally recognized standard of competence provided by the (ISC)²® CBK which covers critical topics in security today, including cloud computing, mobile security, application development security, risk management and more.

دبلوم, ISO27001 Lead Auditor
  • في IRCA
  • يوليو 2008

The ISO 27001 Lead Auditor certification consists of a professional certification for auditors specializing in information security management systems (ISMS) based on the ISO/IEC 27001 standard and ISO/IEC 19011. ISO 27001 Lead Auditor certification is the recognition that the individual can be engaged by certification bodies to perform information management system audits under their direction and management system.

دبلوم, CISA (Certified Information Systems Auditor)
  • في ISACA
  • يونيو 2007

Certified Information Systems Auditor (CISA) is a professional certification for Information Technology Audit professionals sponsored by ISACA, formerly the Information Systems Audit and Control Association. CISAs are recognized internationally as professionals with the knowledge, skills, experience and credibility to leverage standards, manage vulnerabilities, ensure compliance, offer solutions, institute controls and deliver value to the enterprise.

بكالوريوس, Computer Engineering
  • في SSUET
  • أبريل 2006

Computer Engineering is applied reasoning which requires the ability to implement ideas through Software and Hardware technology. The Course is concerned with software and hardware aspects of Microprocessors, Mini-computers and Main-frame computers. The course is designed in such a way so as to facilitate young Computer Engineers to be able to work in the field confidently or take advanced studies and research work in the related field. The course is also supplemented through laboratory work and seminars. Ample computing facilities with modern computers are available.

Specialties & Skills

Governance
Disaster Recovery
Information Security Management
Information Security Management
Cobit , ITIL , ISO 27001 , ISO 20000 , HIPAA and PCIDSS Compliance Review
IT Strategic Management
Data Center Design Services
Network Architecture Review
Information Security Risk Assessment
Vulnerability Assessment
ISO 27001 Implementation
Information Security Policies Development and Implementation
Computer Forensics
Information Systems Audit or IS Audit or IT Audit
Information Security & Governance Advisory and Consultancy Projects
IT Governance, IT Policies & Procedures and IT Strategy (ITIL, Cobit, ISO 20000, TOGAF)
Business Continuity & Disaster Recovery Plan (BS 25999)
Computer Assisted Audit Tools - CAAT (ACL)
IS or IT Audit Planning, Execution, Reporting and Follow-up
Creating Prposals, RFP (Request for Proposal) Writing, Proposal/Vendor Evaluation, Project Mgmt
ERP Integrity Reviews for SAP, Oracle E-Business Suite

اللغات

الانجليزية
متمرّس

التدريب و الشهادات

KPMG Audit Methodology (تدريب)
معهد التدريب:
KPMG
تاريخ الدورة:
January 2008
ISO 27001 Lead Audit (تدريب)
معهد التدريب:
IRCA
تاريخ الدورة:
June 2009
Transform Methodology "Change & Project Management" (تدريب)
معهد التدريب:
PwC
تاريخ الدورة:
March 2011
ERP Integrity Review (تدريب)
معهد التدريب:
Ernst & Young
تاريخ الدورة:
February 2009