Mohamad Ballan, Manager IT Audit, Risk and Governance Professional

Mohamad Ballan

Manager IT Audit, Risk and Governance Professional

Ooredoo

Location
Qatar - Doha
Education
Bachelor's degree, Bachelor of Science Degree majoring in Accounting
Experience
27 years, 7 Months

Share My Profile

Block User


Work Experience

Total years of experience :27 years, 7 Months

Manager IT Audit, Risk and Governance Professional at Ooredoo
  • Qatar - Doha
  • My current job since November 2015

As an experienced Audit, Risk and Control professional and in addition to my professional involvements, I am responsible for engagement planning, budgeting, organizing, executing work plans, managing daily aspects of engagements, scheduling and conducting interviews, executing engagements and communicating the results of work in technical, as well as non-technical, terms. His role also includes managing and mentoring staff during engagements in addition to communicating opportunities to improve the system of internal controls.

Head Department at Doha Bank
  • Qatar - Doha
  • My current job since January 2020

Department Head - IT Audit

Information Security Manager, CISO at Doha Bank
  • Qatar - Doha
  • September 2012 to November 2015

a. Participate actively during internal audits and follow-up on remediation actions of findings;
b. Work with outside consultants as appropriate for independent security audits;
c. Develop and conduct security training and awareness programs; including ISMS awareness training and workshop for all the staff of the bank to communicate bank information security policy, standards and procedures;
d. Promote and develop security mission, mandate and IS Governance;
e. Develop, and implement security controls, policies and standards; in accordance with the bank’s corporate governance, regulatory requirements and industry best practice;
f. Assist the head of Operational Risk in coordinating and driving compliance in all information security streams;
g. Presenting the information security program and related framework to the Bank’s management; conduct periodic information security forum in Operational Risk Management Committee, or an appropriate committee, meeting to frequently report the effectiveness of the control and security environment;
h. Develop policies framework for IS risk assessment, acceptance and deviation methodology, manage Information Security reviews and submit assessment reports on adequacy of control in accordance with policies, standards, procedures to safeguard Bank’s assets;
i. Oversee incident response planning as well as the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary;
j. Co-ordinate with all departments for continuous assessment, mitigation and control of information security related risks;
k. Help in recruiting the skilled resources to achieve the Bank’s ISMS objectives;
l. Managing other levels of personnel who implement the information security program and perform information security duties that are required under the policy and practices of IS framework implementation; including ISMS coordination and resource allocation

Technology Control Manager (AVP Corp.) at Mashreq
  • United Arab Emirates - Dubai
  • August 2011 to September 2012

a. Help in recruiting the skilled resources to achieve the Bank’s ISMS objectives;
b. Managing other levels of personnel who implement the information security program and perform information security duties that are required under the policy and practices of IS framework implementation; including ISMS coordination and resource allocation;
c. Plan and select resources based on skills required to conduct IT reviews of various information assets as per the plan in order to achieve the desired ISMS objectives;
d. Act as in-house consultant and recommend best practices for consistently raising the standards;
e. Develop a IS risk assessment methodology to identify risky areas exposing the bank’s assets;
f. Act as the source of reference within IS to facilitate and promote understanding of IS risk and compliance requirements;
g. Act as subject matter expert for all IS policies and procedures and as a single point of contact for process improvement;
h. Evaluate and recommend new security solutions to be implemented in the Bank;
i. Represent the bank on FS-IREC membership and participate actively;
j. Interface and interact with internal and external entities (such as Department Heads, Branch Managers, Internal and External Auditions, ITD units, BCM, user departments, external businesses, suppliers, vendors, security solution providers, etc.) with respect to information security governance and compliance requirements, policies, standards and procedures and other areas as required;
k. Maintain relationships with law enforcement and other related government agencies.

Senior Audit Manager (IS&T Group) at SCOTIABANK
  • Canada - Ontario
  • July 2006 to August 2011

As an experienced Audit, Risk and Control professional and in addition to my professional involvements, I am responsible for engagement planning, budgeting, organizing, executing work plans, managing daily aspects of engagements, scheduling and conducting interviews, executing engagements and communicating the results of work in technical, as well as non-technical, terms. His role also includes managing and mentoring staff during engagements in addition to communicating opportunities to improve the system of internal controls.

Tecnhnology and Security Risk (TSRS) Manager at ERNST & YOUNG - USA
  • United States - Washington
  • November 2004 to May 2006

As an experienced Audit, Risk and Control professional and in addition to my professional involvements, I am responsible for engagement planning, budgeting, organizing, executing work plans, managing daily aspects of engagements, scheduling and conducting interviews, executing engagements and communicating the results of work in technical, as well as non-technical, terms. His role also includes managing and mentoring staff during engagements in addition to communicating opportunities to improve the system of internal controls.

Enterprise Risk Services (ERS) Supervisor Senior at DELOITTE - USA
  • United States - Washington
  • November 2002 to October 2004

As an experienced Audit, Risk and Control professional and in addition to my professional involvements, I am responsible for engagement planning, budgeting, organizing, executing work plans, managing daily aspects of engagements, scheduling and conducting interviews, executing engagements and communicating the results of work in technical, as well as non-technical, terms. His role also includes managing and mentoring staff during engagements in addition to communicating opportunities to improve the system of internal controls.

Senior Auditor and ERS Senior at Deloitte - Qatar
  • Qatar - Doha
  • August 1996 to November 2002

As an experienced Audit, Risk and Control professional and in addition to my professional involvements, I am responsible for engagement planning, budgeting, organizing, executing work plans, managing daily aspects of engagements, scheduling and conducting interviews, executing engagements and communicating the results of work in technical, as well as non-technical, terms. His role also includes managing and mentoring staff during engagements in addition to communicating opportunities to improve the system of internal controls.

Education

Bachelor's degree, Bachelor of Science Degree majoring in Accounting
  • at Beirut Arab University (BAU)
  • July 1996

In addition to Over 2000 CPE hours training and teaching courses which including managing engagements, consultative skills, internal controls COSO, Risk and Control, COBIT, and RISKIT, Sarbanes-Oxley, Internal Audit, CISA review courses, ITIL V3 and other work related technical and non-technical training courses such as the ACL, DTT/AS/2, EY/AWS, Microsoft Technology, SAP, AS/400, PWC TeamMate and more.

Specialties & Skills

Auditing
Security
Internal Controls
Management
Team Work
Risk Management
Audit Methodology Development

Languages

Arabic
Expert
English
Expert
French
Beginner

Memberships

Information System Audit and Control Association (ISACA)
  • Certified in Risk and Information Systems Control
  • January 2011
Association of Certified Fraud Examiners
  • Certified Fraud Examiner
  • January 2004
Banking Administration Institute
  • Certified Risk Professional
  • January 2003
British Standards Institute
  • Certified ITIL Version 3 Foundation
  • January 2009
Institute of Internal Controls Auditors
  • Certified Internal Controls Auditor
  • July 2010
British Standards Institute
  • Certified ISO 27001: 2005 Lead Implementer
  • February 2012
International Council of Electronic Commerce Consultants), USA
  • Certified C|CISO EC-Council
  • March 2012
CISA
  • ISACA
  • January 2015
ISACA
  • CISM
  • January 2021