Hesham Youssef, Information Security Governance Unit Head

Hesham Youssef

Information Security Governance Unit Head

Confidential

Location
Kuwait
Education
Bachelor's degree, Computer Science
Experience
21 years, 5 Months

Share My Profile

Block User


Work Experience

Total years of experience :21 years, 5 Months

Information Security Governance Unit Head at Confidential
  • Kuwait - Al Ahmadi
  • My current job since November 2014

Supporting the Chief Information Security Officer in Establishing the information security function, defining security organization structure include team structure, roles and responsibilities, scope of responsibilities, formulating relevant information security committees, facilitating strategic decision making process using a systematic risk assessment and management methodologies.

Establishing and maintaining the IT Group Information Security Management System (ISMS) as per compliance requirements of the ISO 27001:2013 and other leading international standards and practices including ISO 22301, ISO3100, SCADA Security GP, and NERC CIP (Critical Infrastructure Protection) in addition to the applicable national statutory and regulatory compliance requirements

Information Security Manager at ITS Group
  • Kuwait - Al Kuwait
  • April 2010 to October 2014

Establish, maintain and improve the organization Information Security Management System (ISMS) in order to protect the confidentiality, integrity and availability of information, give direction on the advancing technologies, tools, standards, and strategies that ensure Information Security Governance is continuously improved and is aligned with business objectives, and applicable laws and regulations.

Key Work:
1. Monitoring the information security related activities of departments / suppliers responsible for safeguarding the company's information assets to ensure compliance with company policies and procedures.
2. Defining an approach for organization-wide risk assessment of assets and risk management
3. Approving methodologies and processes for information security e.g. risk assessment, asset classification
4. Identify protection goals, objectives and metrics consistent with corporate strategic plan.
5. Manage the development and implementation of global security policy, standards, guidelines and procedures to ensure ongoing maintenance of security.
6. Assessing the adequacy of information security controls and coordinating their implementation
7. Oversee incident response planning as well as the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary.
8. Maintain relationships with local law enforcement and other related government agencies.
9. Review the business continuity plan periodically
10. Monitor the business continuity and disaster recovery procedures in case of any disaster
11. Institutionalize information archiving through primary, secondary & tertiary information backup and recovery processes
12. Plan for additional investment in security after consultation with other members of the Security committee
13. Ensure that appropriate awareness and training sessions are conducted for the concerned to understand the Organization’s security policies....

Information Security Officer at ITS - Egypt Office- Promoted to group level management position
  • Egypt - Cairo
  • July 2007 to March 2010

To establish and maintain the organization Information Security Management System (ISMS) in order to protect the confidentiality, integrity and availability of information according to ISO27001 compliance requirements

Key Work:
1. Identify and manage information security risks associated with the business objectives.
2. Documenting the information security policies and procedures instituted by the organization's Information Security Committee.
3. Coordinating the activities of the Information Security Committee
4. Facilitate the development, testing and implementation of organization security plans, products and controls techniques
5. Facilitate the preparation of the organization's disaster recovery and business continuity plans for information systems.
6. Providing direct information security training to all employees, contractors, alliances, and other third parties.
7. Monitoring compliance with the organization's information security policies and procedures and referring problems to appropriate department managers or administrators
8. Reviewing information system related information security plans throughout the organization's network, and acting as liaison to the Information Systems users

General Manager at Olitech Egypt
  • Egypt - Cairo
  • November 2005 to July 2007

Managing the full operations of a company specialized in Physical Security Systems, Time Management Solutions, Banking specialized systems and other related products.

IT Projects Manager, (Information Security) at International Cyber Service (ICS)
  • Saudi Arabia - Riyadh
  • August 2004 to October 2005

Consulting and Education using Role-based Training and Modular Enterprises "CERTME™."
E-Learning, Information Assurance and Security Consulting.
http://www.ics-emea.com/
Between KSA & Egypt.

Technical Manager at Olitech Egypt
  • Egypt - Cairo
  • May 2004 to August 2004

Managing the Support and Implementation team for Physical Security Systems, Time Management Solutions, Banking specialized systems and other related solutions

Senior IT Support at Olitech Egypt
  • Egypt - Cairo
  • December 2002 to May 2004

Support Physical Security Systems, Time Management Solutions, Banking specialized systems and other related solutions

Education

Bachelor's degree, Computer Science
  • at Modern Academy Maadi
  • May 2002

Overall Grade: Good. Graduation project: Autonomous Handling Robotic Vision System, Project Grade: Excellent.

Specialties & Skills

Information Security Management
ISO 27001
Business Continuity
Risk Management
Information Security Management
IT Project Management
Compliance Management
IT Service Management
Business Continuity Planning and Consulting
COBIT, HIPPA, PCI DSS Standards
ISO 27001 Implementer
ISO 27001 Lead Auditor

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

Arabic
Expert
English
Expert

Memberships

ISACA.org
  • Member
  • August 2012

Training and Certifications

Certified Information Security Officer (10 Certificates Track) (Certificate)
Date Attended:
January 2003
Deltar Level 4 Award in the Foundations of Corporate Security and Risk Management (Training)
Training Institute:
ISRM
Date Attended:
April 2020
Level 5 Award in Corporate Risk and Crisis Management (Training)
Training Institute:
ISRM
Date Attended:
April 2020
ISO 22301 Lead Implementer (Certificate)
Date Attended:
March 2016
Certified ISO 9001 Lead Auditor by IRCA (Certificate)
Date Attended:
December 2013
Valid Until:
December 2016
ISA/IEC 62443 Cybersecurity Fundamental Specialist (Certificate)
Date Attended:
July 2018
Certified ISO 27001 Lead Auditor by IRCA (Certificate)
Date Attended:
March 2009
Valid Until:
March 2012
Certified ISA/IEC 62443 Cybersecurity Risk Assessment Specialist (Certificate)
Date Attended:
July 2018
Certified Information Security Manager® (CISM) (Certificate)
Date Attended:
September 2012
Valid Until:
September 2018
Crisis Management, Evacuation Drills, Evacuation Planning, Emergency Handling, Fire Fighting (Training)
Training Institute:
Crisis Management and Fire Fighting from Egyptian Fire Authority
Date Attended:
September 2007
CISSP Review Workshop from ISC2 (Training)
Training Institute:
ISC2
Date Attended:
November 2007
IT Service Management Foundation based on ITIL v3 (Training)
Training Institute:
ITIL v3 Foundation
Date Attended:
March 2010
Physical Security Solutions Design and Implementation (Training)
Training Institute:
IDTECK Korea
Date Attended:
May 2004
CCTV Solutions Design and Implementation (Training)
Training Institute:
Samsung CCTV in Korea
Date Attended:
January 2005
Duration:
40 hours