Lojain Nahhas, Cybersecurity Specialist

Lojain Nahhas

Cybersecurity Specialist

Pioneers Systems

Location
Saudi Arabia
Education
Master's degree, Cybersecurity
Experience
3 years, 8 Months

Share My Profile

Block User


Work Experience

Total years of experience :3 years, 8 Months

Cybersecurity Specialist at Pioneers Systems
  • Saudi Arabia - Jeddah
  • March 2023 to February 2024

Implement and collect evidence for NIST 800-171, CMMC, SACS-002: Third Party Cybersecurity Standard (Saudi Aramco), and the Cybersecurity Regulatory Framework (CRF) for service providers in the information and communications technology sector.
Mapping between NIST 800-171 and CMMC.
Creating self-evaluation files for NIST 800-171 and CMMC.
Mapping policies between NCA and ISO 27001.
Tack an action for indicators of compromise (IOCs).
Participating in the Communication, Space, & Technology Commission (Alerting for Cybersecurity).
Conducting a vulnerability assessment for several servers and the website and writing a report.
Scanning vulnerabilities in systems and assets.
Developing a working and scheduled plan for vulnerability assessment.
Creating a new file for assets to collect the asset value for all assets in one file.
Responding to and acting on email incidents.
Creating and sending an awareness email.
Working on an external audit related to the project.
Handling several requests for the VPN.
Creating a training plan and supervising help desk trainees.
Being responsible for everything related to cybersecurity (internal and external).

Cybersecurity Specialist at Pioneers Systems
  • Saudi Arabia
  • March 2023 to February 2024
Penetration Tester at Holy Makkah Municipality
  • Saudi Arabia - Mecca
  • February 2022 to February 2023

Scanning vulnerabilities in systems and assets.
Developing a working plan for vulnerability assessment.
Working on HASEEN.
Monitoring security updates and verifying their compatibility with NCA systems and applications.
Implementing NCA cybersecurity controls specific to vulnerability management.
Clarifying the impact of vulnerabilities on the organization and how to address them.
Identifying the methodologies that attackers may use to exploit vulnerabilities in systems and networks.
Conducting internal audits to ensure compliance with cybersecurity controls and policies.
Preparing reports on the results of penetration testing and vulnerability assessments, including risk levels, remediation suggestions, and all necessary technical details.
Acting on any cybersecurity alerts from NCA.
Subscribing to cybersecurity alerts from the Communications, Space, and Technology Commission.
Collaborating with the awareness team to provide ideas for cyber security awareness.
Modifying the assets to meet the corresponding NCA requirements.
Creating a training plan and supervising cybersecurity trainees.
Working on the KPIs for the cybersecurity department.
Creating and documenting job descriptions for the cybersecurity department, based on the Saudi Cybersecurity Workforce Framework (SCyWF).

Administrative Assistant at Umm Al-qura University
  • Saudi Arabia - Mecca
  • August 2020 to December 2020

Find payment problems for paid graduate students and make a report on that.
Respond to the email from the graduate studies unit.
List the names of students wishing to withdraw and make a report on that. Communicate with students.
List the names of students in closed programs.
Communicate with students regarding closed programs and clarify the procedures followed (whether refunding the amount or transferring to another department (if possible) by filling out the transfer form).
Make a comprehensive report listing the names of students in the inactive programs and withdraw.
Make fee refund forms and communicate with students.
Make an inventory of the various payment problems (such as technical problems, etc.).
Make a report regarding the problem of the invoice not appearing for the first semester and send the solution to students in the event of a question.
List the names of students who faced problems withdrawing and refunding the amount.
Respond to the WhatsApp of the Graduate Studies Unit.
List the names of the employees of the Deanship of Graduate Studies.

Secrétariat at Diamond Matrix Company
  • Saudi Arabia - Mecca
  • February 2019 to August 2019

Register the names of trainees and their personal information in the company’s program.
Search and list the names of the trainees in canceled courses and write their information and the registration amount to be transferred.
Scan files and upload them to the Dropbox admin file.
Modify file names in file management and rename all files.
Prepare reports on ways to improve sales.
Search for problems related to marketing. propose the proper solution and write a report on that to discuss it with the marketing team.
Prepare the minutes of the sales team meeting.
Write, format, and review the whiteboard draft on Word.
Print invoices and put them in a file according to the date of the session.
Make a table for invoices in Excel, scan them, and link them with files.
Write an initial employment contract.
Make a template for the visiting schedule.
Scan files and add invoices related to construction.
Write an hourly work contract, coordinate, amend, and send it.

Reservations Agent at Makkah Clock Royal Tower, A Fairmont Hotel
  • Saudi Arabia - Mecca
  • February 2016 to August 2016

Follow up and implement all check-in and check-out tasks.
Manage and track reservations online and by phone.
Inform customers about payment methods, and verify their credit card information.
Record the necessary data and information for visitors.
Collaborate with visitors and provide information on the hotel, available rooms, rates, and facilities.
Respond to customers' complaints in a timely and professional manner.
Communicate with the various departments within the hotel according to the needs of the guests.
Confirm reservations and arrange customer service.
Periodically updating and maintaining records of reservations and payments.

Education

Master's degree, Cybersecurity
  • at Umm Al-qura University
  • February 2022
Bachelor's degree, Computer Science
  • at Umm Al-qura University
  • June 2014

Specialties & Skills

ISO 27001
Vulnerability Assessment
Risk Assessment
Data Analysis
Responsibility
Leadership
Creativity
Critical Thinking
Teamwork
Self-learning and skill development
Organization
Problem-Solving
Project Management
Attention to Detail
Flexibility

Languages

English
Intermediate
Arabic
Native Speaker

Memberships

Saudi Council of Engineers
  • 824276
  • January 2022

Training and Certifications

CRISC (Certified in Risk and Information Systems Control Course) (Training)
Training Institute:
ISACA
Date Attended:
November 2022
Cyber Security Bootcamp- Level 1 (Training)
Training Institute:
TechCampus
Date Attended:
December 2022
ISO 27005 Risk Manager (Training)
Training Institute:
Trusted Vision
Date Attended:
February 2023
ISO 27001 Lead Implementer (Training)
Training Institute:
Trusted Vision
Date Attended:
June 2023
Systems Security Certified Practitioner (Training)
Training Institute:
Ministry of Communications and Information Technology
Date Attended:
June 2023
SOC Analyst (Training)
Training Institute:
Tuwaiq Academy
Date Attended:
July 2023
Operational Excellence in Digitalization (Training)
Training Institute:
Leading National Academy
Date Attended:
August 2023
CompTIA A+ (Training)
Training Institute:
TechCampus
Date Attended:
October 2023
AWS Cloud Practitioner (Training)
Training Institute:
Saudi Digital Academy (SDA)
Date Attended:
February 2024