محمد الشهراني, Chief Information Security Officer

محمد الشهراني

Chief Information Security Officer

saudi Arabian Cooperative Insurance Co

البلد
المملكة العربية السعودية - الرياض
التعليم
ماجستير, MBA
الخبرات
15 years, 4 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :15 years, 4 أشهر

Chief Information Security Officer في saudi Arabian Cooperative Insurance Co
  • المملكة العربية السعودية - الرياض
  • أشغل هذه الوظيفة منذ أغسطس 2021

• Developed and evolved information / cyber security strategy and roadmap.
• Governed all SAICO security policies, procedures, designs, standards, network, applications deployments.
• Decreased threats 55% in 1 year by performing risk analysis, identifying counter security measures.
• Grew audit compliance from 0% to 70% while lowering risk 60% in first year by creating 5 new information security processes: Security Governance, Risk Management, Security Incident Response, Vulnerability Management Strategy and Third Party Cyber Security.
• Delivered 38% decrease in response time by automating cybersecurity incident response.
• Introduced 450+ controls during roll out of information Security Program centered on compliance against regulatory requirements.
• Achieved 50% reduction in phishing attacks - from 70% to 20% by creating and deploying Security Awareness Program.
• Established Data Privacy program with collaboration with all teams.
• Improved safeguarding of Customer data by building Computer Incident Response Team "CIRT" and working with IT department and Risk department on Disaster Recovery/ business Continuity Plans.

Acting CIO في Saudi Arabian Cooperative Insurance Company (SAICO)
  • المملكة العربية السعودية - الرياض
  • أكتوبر 2021 إلى أبريل 2022

• Leader of 25 employees that serves over 80, 000 + beneficiaries.
• Reduced IT operating expenses by 1, 000, 000 SAR by negotiated current and future mutual interests with company vendors.
• Virtualized 60% of company Data Center reducing life cycle expenses.
• Managed IT budget of over 16 Million SAR.
• Team won local awards for Nphies integration with CHI.
• Led and speed up implementation and development of new core system application.
• Increased achievements of 110 major tasks and projects within 4 months timeline by promoting coordinations and collaborations between infrastructure team, Application Team, database team and IT security team.

Director of Risk Management and Information Security في Bayan Credit Bureau
  • المملكة العربية السعودية - الرياض
  • يونيو 2019 إلى أغسطس 2021

• Establish and maintain department strategy, Information Security program, data classification Program, and awareness program to ensure that business operations, information assets, and technologies are adequately protected due to hosting critical data for more than 10 Saudi banks.
• Oversaw security operations, governance, compliance, internal/external risks.
• Eliminated all audit findings regarding in less than 1 year and half, by establishing company automation methodology frameworks, and tools.
• Drafted security operating procedures and training materials for human resource department.
• Achieved immediate 50% decrease in internal and external risk by holding workshop for company employees.
• Partnered with business and IT leaders to develop security policies, standards, guidelines, and procedures to ensure confidentiality, integrity, and availability of internal systems and data.
• Completed both progressive and regressive testing scenarios by applying testing frameworks.

Head of IT infrastructure في Bayan Credit Bureau
  • المملكة العربية السعودية - الرياض
  • أكتوبر 2018 إلى يونيو 2019

• Grew IT process efficiency 25% by initiating several initiatives to improve communication.
• Guided implementation of Company-wide security strategy for network and hardware, disaster recovery, data protection and endpoint protection.
• Responsible for planning, designing, budgeting, operating. The infrastructure includes enterprise servers, storage & SAN and host ERP, other financial, batch processing applications. My team is responsible for physical facility management, OS and all business applications management.
• Worked with other IT leaders to refine incident & problem management of 24x7 service operation and established change management of the service strategy as part of the IT service management.
• Led disaster recovery and business continuity setups of tier -3 applications/infrastructure. Established RTO and RPO of applications.

A/ Network & Internet Support Manager في King Saud bin Abdulaziz University for Health Sciences
  • المملكة العربية السعودية - الرياض
  • أبريل 2012 إلى أكتوبر 2018

• Architect, manage and maintain primary services located in university's data center to serve 10 Colleges and more than 5000 users.
• Assess university's security measures, such as firewalls, IDS, anti-virus software, and passwords.
• Assess university's IT infrastructure performance optimization, such as internet bandwidth, routers, switches, servers, and storage.
• Manage and supervise IT controls prevention systems, including authentication, authorization, physical security, and encryption.
• Manage and supervise IT controls restoration systems, including backups, replication, fail-over, and disaster recovery.
• Manage and supervise IT controls detection systems, including monitoring and auditing. Manage data center expansion project successfully.

Network Engineer في ALRAJHI Bank
  • المملكة العربية السعودية - الرياض
  • مارس 2009 إلى مارس 2012

• Monitored network capacity and performance to diagnose and resolve complex network problems• Provided network support services for devices such as hubs, bridges, routers, and other hardware for more than 700 branches and 3000 ATM.
• Troubleshot complex multi-vendor network service provider issues Within short time.
• Provided complete end-to-end engineering and installation of route-based IP network solutions for 800 ATMs with minimum downtime.
• Managed, tracked, and coordinated problem resolution and escalation processes.
• Performed troubleshooting for Juniper, Cisco, and packet analysis.
• Created VPN infrastructure and allowed for secure remote connections.

Network Engineer (On-job Trainee), في King Fahd University of Petroleum and Minerals
  • المملكة العربية السعودية - الدمام
  • يونيو 2007 إلى يوليو 2007

- Deploy wireless Access Point on university campus.
- Checking network connectivity

الخلفية التعليمية

ماجستير, MBA
  • في Saudi Electronic University
  • مايو 2021
بكالوريوس, Computer Engineering
  • في King Fahd University of Petroleum and Minerals
  • يوليو 2008

Specialties & Skills

Routing
Routers
Petroleum
MS office
Analysis
Network Troubleshooting
Cisco Devices
Access Management
Asset Security
Communication Security
Identity Management
Network Security
Risk Management
Security Assessment
Security Engineering
Security Management
Security Operations
Security Testing
Software Development Security

اللغات

العربية
متمرّس
الانجليزية
متمرّس

التدريب و الشهادات

Operations Management Foundations (تدريب)
معهد التدريب:
LinkedIn
تاريخ الدورة:
January 2017
Change Management (تدريب)
معهد التدريب:
ACTrain
تاريخ الدورة:
August 2017
Project Management Professional (تدريب)
معهد التدريب:
Alkhaleej
Troubleshooting and Maintaining Cisco IP Networks (تدريب)
معهد التدريب:
Sigma IT
تاريخ الدورة:
November 2011
Certified Information Systems Security Professional (CISSP) (الشهادة)
تاريخ الدورة:
February 2017
صالحة لغاية:
April 2020
Key Managerial and Administrative Skills (تدريب)
معهد التدريب:
Human Resources Development Ltd.
تاريخ الدورة:
October 2014
Cisco Certified Network Professional (الشهادة)
تاريخ الدورة:
December 2011
صالحة لغاية:
December 2014
Implementing CiscoWorks (تدريب)
معهد التدريب:
Sigma IT
تاريخ الدورة:
August 2011
Implementing Cisco MPLS (تدريب)
معهد التدريب:
Sigma IT
تاريخ الدورة:
December 2011
Group Dynamic and Interpersonal Relation Skills (تدريب)
معهد التدريب:
EUROMA Tech
تاريخ الدورة:
March 2009
High Performance Teams (تدريب)
معهد التدريب:
Human Resources Development Ltd.
تاريخ الدورة:
October 2014
Implementing Cisco IP Routing (تدريب)
معهد التدريب:
Sigma IT
تاريخ الدورة:
April 2011
Cisco Certified Network Associate (الشهادة)
تاريخ الدورة:
April 2011
صالحة لغاية:
April 2014
Implementing Cisco IP Switched Networks (تدريب)
معهد التدريب:
Sigma IT
تاريخ الدورة:
July 2011
Leading People and Team (تدريب)
معهد التدريب:
Human Resources Development Ltd.
تاريخ الدورة:
October 2014