Khalid AlJemy, Information Security Auditor

Khalid AlJemy

Information Security Auditor

Riyad Bank

Location
Saudi Arabia - Riyadh
Education
Bachelor's degree, Networks Engineering and Security
Experience
5 years, 7 Months

Share My Profile

Block User


Work Experience

Total years of experience :5 years, 7 Months

Information Security Auditor at Riyad Bank
  • Saudi Arabia - Riyadh
  • My current job since February 2023

Information Security / Information Technology Auditor at the Internal Audit Division
Khalid’s responsibilities are:
• Be fully aware of the Bank’s Internal Audit’s Methodology and Audit Universe
•Part of several integrated audits toward some of the Bank's application reviews; by being involved at:
o Defining the engagement scope and participating at the audit opening
o Preparing the engagement program memorandum (EPM)
o Conducting the audit fieldwork by testing the auditable object controls and validates the
adequacy of the governance documentation
o Participating in the audit internal closing meeting which assesses the identified associated risks,
classifying reportable audit findings, work papers, and audit ratings
o Participating in the audit external closing meeting
o Follow-up and validate closure of reported audit findings with the auditee
• Conduct the NCA (National Cybersecurity Agency) regulatory controls’ assessment “ CSCC (Critical Systems Cybersecurity Controls)” thoroughly as an independent and objective party towards the Bank’s identified critical assets and their stakeholders; by identifying the governance documentation, identifying technology and business stakeholders, request evidences, generate assessment reports, and follow-up with the gaps and non-compliances
• Conduct the NCA regulatory controls’ assessment “ECC (Essential Cybersecurity Controls)” thoroughly as an independent and objective party; as per the above CSCC approach
• Part of SAMA (Saudi Arabian Monetary Agency) ITGF (Information Technology Governance Framework) assessment

Cybersecurity Compliance Expert at NCGR (National Center for Government Resources Sys.)
  • Saudi Arabia - Riyadh
  • April 2022 to February 2023

Worked as organizational compliance expert.
Khalid’s responsibilities are:
• Continues compliance assessments towards official government regulatory agencies and directives that includes consistent follow-ups with stakeholders, policy makers, and organizational operators and practitioners
• Semi-annual compliance inspections and reporting
• Quarterly systems’ users access review
• Annual systems roles and privileges reviews
• Part of all SailPoint project milestones
• Conduct RBAC & SOD exercise on several systems.
• Part of NCGR’s one-of-kind National UGRP system (Unified Government Resources Payroll) which is meant to serve the government sector in Saudi Arabia.
• Continues organizational policies implementation compliance reviews
• Organizational policies feedback review with policy makers
• Examine internal IT controls, evaluate the design and operational effectiveness, determine exposure to risk, and develop remediation strategies
• Handling organizational complaints, disputes and grievances
• focal point of communication with official regulatory agencies
• Build up a cyber threat intelligence function

Cyber Threat Analyst/Consultant at Saudi Information Technology Company
  • Saudi Arabia - Riyadh
  • September 2019 to February 2022

Cyber Threat Intelligence (CTI) analyst and consultant internally for SITE and externally for its clients as a subscription based business model. Khalid’s responsibilities at SITE were:
• Hunting feasible cyber threats to the Saudi threat landscape and immediately provide actionable intelligence, analysis, and professional assessments and reports
• Intel Collection (Internal - Commercial - OSINT - Surface-web - Deep Web - Counter Intel - Dark web)
• Advanced Persistent Threat groups profiling & Malware Analysis & Enriching SITE’s CTI platform (TIP)
• Part of building-up the CTI service catalogue model and subscription based business model initiativeCyber Threat Intelligence (CTI) analyst and consultant internally for SITE and externally for its clients as a subscription based business model. Khalid’s responsibilities at SITE were: • Hunting feasible cyber threats to the Saudi threat landscape and immediately provide actionable intelligence, analysis, and professional assessments and reports • Intel Collection (Internal - Commercial - OSINT - Surface-web - Deep Web - Counter Intel - Dark web) • Advanced Persistent Threat groups profiling & Malware Analysis & Enriching SITE’s CTI platform (TIP) • Part of building-up the CTI service catalogue model and subscription based business model initiative
Skills: Quality Assurance · Quality Management · Quality Control · Threat Analysis · Threat Assessment · Threat Modeling · Incident Response · Incident Handling · Computer Forensics · Consulting · Report Writing · Malware Analysis · Cyber Threat Intelligence (CTI) · Cybersecurity

Researcher at AlYamamah University
  • Saudi Arabia - Riyadh
  • September 2018 to October 2019

Khalid and his colleagues published a conference paper named "Improving IoT Security Using Blockchain" in the 10th IEEE-GCC Conference and Exhibition at Kuwait. The conference theme was "Powering the 4th Industrial Revolution" and we published it under the track of "Smart City Technologies". https://ieeexplore.ieee.org/document/9087619
In addition, Khalid and his colleagues participated in Dell EMC Graduation Project Fair among Africa and middle-east and Turkey, and the project fell short of the highest top 10 out of 329 projects.

Internship at SITE/PSU
  • Saudi Arabia - Riyadh
  • February 2019 to September 2019

Fulltime program was provided by the Saudi Information Technology Company and hosted at Prince Sultan University.
This program aims to provide professional courses in softskills and the cybersecurity field as well.

COOP at Bahri
  • Saudi Arabia - Riyadh
  • September 2018 to January 2019

Fulltime Cooperative Assignment at Bahri Co. in the IT Infrastructure Department focused on NOC and SOC.

Education

Bachelor's degree, Networks Engineering and Security
  • at AlYamamah University
  • December 2018

Worked on a graduation project on my undergraduate studies. This project involves improving IoT Security using Ethereum Blockchain and developing a Smart-Contract for “Access Controlled Blockchain”. We published the paper in the 10th IEEE Conference and Exhibition on April 2019. The paper entitled "Improving IoT Security Using Blockchain". The conference theme was "Powering the 4th Industrial Revolution", and we published it under the track of "Smart City Technologies" discussing cybersecurity and IoT.

Diploma, English Proficiency
  • at Saudi Interlink
  • December 2014

A pre-university English proficiency program consists of advanced English skills in communication and reading.

Specialties & Skills

Computer Forensics
Network Forensics
Intelligence Analysis
Malware Analysis
Security Intelligence
Threat Intelligence Reporting
Threat hunting
Advanced cyber threat groups profiling
Malware Analysis
Intelligence gathering
Digital Ferensics
Incedint Response

Languages

Arabic
Native Speaker
English
Expert

Memberships

IEEE
  • IEEE Member
  • October 2018
ACM
  • ACM Member
  • April 2019

Training and Certifications

Advanced proficiency in the English language (Training)
Training Institute:
Saudi Interlink
Date Attended:
January 2014
CNSS & NSA Recognition (Certificate)
Date Attended:
May 2019
COOP Completion from Bahri (Certificate)
Date Attended:
January 2019
IEEE conference attendance as a lecturer (Certificate)
Date Attended:
April 2019
IELTS Score (Certificate)
Date Attended:
June 2019
Microsoft Powershell (Training)
Training Institute:
Globel Knowledge
Date Attended:
April 2019
Project Management Professional (Training)
Training Institute:
PSU
Date Attended:
July 2019
Duration:
40 hours
Java Prpgrammer 1 (Training)
Training Institute:
Oracle Academy Java Prpgrammer 1
Date Attended:
May 2016
CompTIA Certified Security Analytics Professional "CASP" (Certificate)
Date Attended:
July 2019
CompTIA Cybersecurity Analyst "CySA+" (Certificate)
Date Attended:
July 2019
CompTIA Security+ (Certificate)
Date Attended:
June 2019
Certified Virtialization Forensics Examiner (Certificate)
Date Attended:
August 2019
Certified Digital Forensics Examiner (Certificate)
Date Attended:
August 2019
Mile2 Certified Networks Forensics Examiner (Certificate)
Date Attended:
September 2019
Mile2 Certified Incident Handling Engineer (Certificate)
Date Attended:
August 2019
VMware Certified DataCenter Virtualization Professional (Certificate)
Date Attended:
June 2019
CCNA Security (Certificate)
Date Attended:
May 2019
CCNA Cyber Ops (Certificate)
Date Attended:
July 2019
CCNA R&S (Certificate)
Date Attended:
May 2019
Microsoft Technology Associate in Windows Server Fundamentls (Certificate)
Date Attended:
March 2019
Microsoft Technology Associate in Security Fundamentls (Certificate)
Date Attended:
April 2019
Microsoft Technology Associate in Network Fundamentals (Certificate)
Date Attended:
March 2019
RedHat Certified System Administrator (Certificate)
Date Attended:
April 2019
IBM Security Intelligence Explorer Badge (Certificate)
Date Attended:
May 2018

Hobbies

  • Research paper's review
    I try to assist one of my former faculty members in the research paper publication review process. Usually, I review papers in computer science and engineering field. The most important reason for doing this; is that I find it quite a pleasure doing it! Also, updating myself in the field, improve my reading and writing skills, and to prepare myself for the upcoming MSc and Ph.D
  • Bycle riding
    to maintain good health and shape, as well as it's quite amusing
  • Reading novels
  • Reading psycology books
    It provides me with amusement, emotional intelligence, and the optimum mentality that I'm seeking