ممدوح الزهراني, Information Security Monitoring and incident Response Manager

ممدوح الزهراني

Information Security Monitoring and incident Response Manager

National Commercial Bank - NCB

البلد
المملكة العربية السعودية - جدة
التعليم
ماجستير, Computer System Security
الخبرات
16 years, 0 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :16 years, 0 أشهر

Information Security Monitoring and incident Response Manager في National Commercial Bank - NCB
  • المملكة العربية السعودية - جدة
  • أشغل هذه الوظيفة منذ أغسطس 2013

Build a SoC and maintain Incidents management

Head Cyber Security Inte. في National Commercial Bank - Alahli Ncb
  • المملكة العربية السعودية - جدة
  • أشغل هذه الوظيفة منذ فبراير 2017
Risk Assessment Specialist في Alinma Bank
  • المملكة العربية السعودية
  • يناير 2011 إلى يناير 2012

Risk Assessment Specialist 2011-2012
Alinma Bank, Riyadh, KSA

-Security &Risk management: • Main objectives vary from assessing raising daily external and internal risks to producing quality work that helps in the process of maintaining the
enterprise's security requirements.
• Monitoring systems and applications logs: Security logs.

-Security Awareness: • Increase the security and continuity awareness levels for all the bank's
employees by using emails and training sessions.
• Managing and Operating An awareness program "e-learning" system.

-Internal IT Audit: • Were able to coordinate, manage and assess internal and external
audits requirements towards IT systems and standard.

-Policies&procedures: • To ensure compliance with external requirements from regulators, industry
organisations, and security standards.
• Annual updates of organisational and technical policies and procudres.
• Developing new security document (policy, procedure, standard and guideline) based on needed.
• Maintaining/developing the enterprise's security documents (policies,
standards, guidelines and procedures) based on need.

-Co-operator of PCI DSS Card Scan: • Main task were to managing the process of PCI card scanning and update the scope of PCI DSS on the enterprise assets.

Administrator في Internet WebHosting
  • المملكة العربية السعودية - جدة
  • يناير 2005 إلى يناير 2009

Used to design and implement AQL, HTML, PHP, Java and other coding to websites while administrating more than 10 major websites. Also, Supporting clients in troubleshooting and managing Application.

الخلفية التعليمية

ماجستير, Computer System Security
  • في Sauth Wales University -Glamorgan
  • يناير 2010

University of Glamorgan, Cardiff, UK 2009-2010 MSc in Computer System Security

بكالوريوس, Computer Science
  • في King AbdulAziz Uni
  • ديسمبر 2006

King Abdul AzizUniversity, Jeddah, KSA 2003-2006 BSc in Computer Science

Specialties & Skills

Science
Risk Assessment
Management
Awareness
SECURITY
Security Risk Assessment
Security Project Management
Security Incident Handling
Security monitoring
Risk Management
Security Governance
Security Audit
Security Threat Analysis

اللغات

العربية
مبتدئ
الانجليزية
متمرّس

التدريب و الشهادات

GCTI (الشهادة)
GMON (الشهادة)
GCIH (الشهادة)
CISM (الشهادة)
Certified Ethical Hacker (تدريب)
معهد التدريب:
EC-Council - CEH
تاريخ الدورة:
March 2013