Moeen Qaemi Mahmoodzadeh, Information Security Manager

Moeen Qaemi Mahmoodzadeh

Information Security Manager

Almarai Company

Location
Saudi Arabia - Riyadh
Education
Master's degree, Information Security
Experience
17 years, 2 Months

Share My Profile

Block User


Work Experience

Total years of experience :17 years, 2 Months

Information Security Manager at Almarai Company
  • Saudi Arabia - Riyadh
  • My current job since February 2014

Info Sec Strategic & Tactical Planning
Information Security Project Management
Risk Management
Compliance Management
ISO/IEC 27001:2005 Transitioning to ISO/IEC 27001:2013
ISMS Development and Management
ISMS Review
Policy and Procedure development
Information System Audit
Internal IT Audit
SIEM Management and Incident Management
Information Control Management and Review
Business Continuity and Disaster Recovery Planning and Testing
Awareness and Training
Team Building and Development t
Digital Forensic
Proxy, Email Gateway, End Point Security, Anti Virus Management

Senior Analyst Information Security & Quality at Almarai Company
  • Saudi Arabia - Riyadh
  • December 2012 to February 2014

ISMS Development and Management
ISMS Review
Policy and Procedure development
Information System Audit
Internal IT Audit
SIEM Management and Incident Management
Information Control Management and Review
Business Continuity and Disaster Recovery Planning and Testing
Awareness and Training
Team Building and Development
Risk Management
Digital Forensic
Proxy, Email Gateway, End Point Security, Anti Virus Management

Information Security Officer at TERADATA GCC
  • Pakistan - Islamabad
  • February 2010 to December 2012

Successfully Implemented the ISO27001 with in the organization and completed a Successful Certification.

Development and Management of Information Security Policy

Information Security Policy and Guidelines Development

Developed the Information Security Awareness and Training Program for the organization

Developed the Information Security Measurement Program Development

Information Security Analyst & Consultant at Trilium Information Security Systems
  • Other
  • October 2009 to February 2010

Performed as an Information Security Analyst and Consultant. Assisted in Risk Assessment, Information Security Control development and deployment, Information Security Training and Proposal development

Information Security & IT Consultant at NSA Pakistan
  • Pakistan - Islamabad
  • September 2008 to October 2009

Performed as a security and IT consultant for a private non profit organization.

AV deployment
Information security controls implementations
IT Consultancy
Network Management

MIS System Analyst, MIS Designer, Data Management Officer, VB/Macro Programmer at International Rescue Committee
  • Other
  • August 2008 to September 2008

Developed the Information Decision System for the NGO's scholarship project. Managed a team of 10 data entry officers

MIS System Analyst, MIS Designer, (PHP/MySql) Web Programmer at People Primary Health Care Initiative - District Support Unit, Peshawar, Pakistan
  • Other
  • June 2007 to August 2007

Developed the Management Information System for the People Primary Health Care Initiative - DSU Peshawar.

IT Support Officer at Japan Emergency NGO
  • Other
  • January 2002 to January 2003

Managed and Supported the IT Infrastructure for the Office of the NGO

Education

Master's degree, Information Security
  • at National University of Science & Technology, Pakistan
  • March 2012

3.90 CGPA Received Endowment Scholarship for the entire MS/MPhil leading to Phd. Program in Information Security, covering all tuition fee and stipend.

Bachelor's degree, Computer Sciences
  • at Institute of Management Sciences
  • December 2007

CGPA of 4.0, Gold medalist Full time scholarship holder Class Topper in 6 consecutive semesters.

Specialties & Skills

Risk Management
Business Continuity
IT Audit
Information Security Management
Information Security Management System Audit against ISO27001 requirements
Compliance with international standard for information security, information technology governance
DIgital Forensics, Knowledge of tools, techniques for Crime scene processing & evidence collection
Information Security Risk Assessment / Risk Management
Information Security Management System Establishment and implementation against ISO27001 requireme
Network & Wireless Network Security: Firewall, IPS, VPN, IPSEC, SSLetc.
Information Security Control Implementation against ISO27001 requirements and ISO27002 guidelines
Capacity Management and Capacity requirement analysis
Enterprise Risk Assessment / Management Methodology and Frameworks (Octave, COSO ERM)
Network Forensics, Mobile Forensics, Instant Messaging Forensics
Information System Administration & Server Configuration (Windows, Linux, Unix, Mail, DHCP, DNS, AD)
IT Services Delivery Security Requirements Management
IT Security Vulnerability Assessment
Knowledge of tools and techniques for Multi OS file system forensics (Windows, Unix, Mac)
Expertise in Compliance local and international information security laws and regulations
SIEM - Qradar
Team Management
Information Security Policy/Procedure and Guideline Development and Establishment
IT Governance thorough CobiT
Physical & Environmental Security Management
Data Center Security Requirements Management
IT Service Management with ITIL best practices
Information System Audit
Networking Technologies and Network Design
Change Control and Change Management.
Web Browser Forensics (IExplorer, Mozilla, Chrome, Opera)
Databases (Mysql, MSSQL, TERADATA)
Information Security Measurement Program development and deployment based on ISO27004 Guidelines
Information Security Awareness and Training Program development
Information Security Incident Management and Review
Business Continuity and Disaster Recovery Strategy & Plan Development
(ISO27001, ISO20000, PCI-DSS, BS25999, NIST)
Programming (C, C++, C#, VB.NET, VB6, ASP, ASP.NET, PHP)

Languages

English
Expert
Urdu
Expert
Persian
Expert

Memberships

ISACA
  • Member
  • April 2010

Training and Certifications

(Certificate)
Date Attended:
February 2015
Certified Information System Security Professional (CISSP) (Certificate)
ITIL V3 (Certificate)
ISO20000 LA (Certificate)
Valid Until:
September 2011
Certified Information System Auditor (CISA) (Certificate)
Date Attended:
May 2011
Valid Until:
May 2011
ISO27001 Lead Auditor (Certificate)
Date Attended:
May 2011
Valid Until:
May 2011