Mohammad Alshahrani, Chief Information Security Officer

Mohammad Alshahrani

Chief Information Security Officer

saudi Arabian Cooperative Insurance Co

Lieu
Arabie Saoudite - Riyad
Éducation
Master, MBA
Expérience
15 years, 4 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :15 years, 4 Mois

Chief Information Security Officer à saudi Arabian Cooperative Insurance Co
  • Arabie Saoudite - Riyad
  • Je travaille ici depuis août 2021

• Developed and evolved information / cyber security strategy and roadmap.
• Governed all SAICO security policies, procedures, designs, standards, network, applications deployments.
• Decreased threats 55% in 1 year by performing risk analysis, identifying counter security measures.
• Grew audit compliance from 0% to 70% while lowering risk 60% in first year by creating 5 new information security processes: Security Governance, Risk Management, Security Incident Response, Vulnerability Management Strategy and Third Party Cyber Security.
• Delivered 38% decrease in response time by automating cybersecurity incident response.
• Introduced 450+ controls during roll out of information Security Program centered on compliance against regulatory requirements.
• Achieved 50% reduction in phishing attacks - from 70% to 20% by creating and deploying Security Awareness Program.
• Established Data Privacy program with collaboration with all teams.
• Improved safeguarding of Customer data by building Computer Incident Response Team "CIRT" and working with IT department and Risk department on Disaster Recovery/ business Continuity Plans.

Acting CIO à Saudi Arabian Cooperative Insurance Company (SAICO)
  • Arabie Saoudite - Riyad
  • octobre 2021 à avril 2022

• Leader of 25 employees that serves over 80, 000 + beneficiaries.
• Reduced IT operating expenses by 1, 000, 000 SAR by negotiated current and future mutual interests with company vendors.
• Virtualized 60% of company Data Center reducing life cycle expenses.
• Managed IT budget of over 16 Million SAR.
• Team won local awards for Nphies integration with CHI.
• Led and speed up implementation and development of new core system application.
• Increased achievements of 110 major tasks and projects within 4 months timeline by promoting coordinations and collaborations between infrastructure team, Application Team, database team and IT security team.

Director of Risk Management and Information Security à Bayan Credit Bureau
  • Arabie Saoudite - Riyad
  • juin 2019 à août 2021

• Establish and maintain department strategy, Information Security program, data classification Program, and awareness program to ensure that business operations, information assets, and technologies are adequately protected due to hosting critical data for more than 10 Saudi banks.
• Oversaw security operations, governance, compliance, internal/external risks.
• Eliminated all audit findings regarding in less than 1 year and half, by establishing company automation methodology frameworks, and tools.
• Drafted security operating procedures and training materials for human resource department.
• Achieved immediate 50% decrease in internal and external risk by holding workshop for company employees.
• Partnered with business and IT leaders to develop security policies, standards, guidelines, and procedures to ensure confidentiality, integrity, and availability of internal systems and data.
• Completed both progressive and regressive testing scenarios by applying testing frameworks.

Head of IT infrastructure à Bayan Credit Bureau
  • Arabie Saoudite - Riyad
  • octobre 2018 à juin 2019

• Grew IT process efficiency 25% by initiating several initiatives to improve communication.
• Guided implementation of Company-wide security strategy for network and hardware, disaster recovery, data protection and endpoint protection.
• Responsible for planning, designing, budgeting, operating. The infrastructure includes enterprise servers, storage & SAN and host ERP, other financial, batch processing applications. My team is responsible for physical facility management, OS and all business applications management.
• Worked with other IT leaders to refine incident & problem management of 24x7 service operation and established change management of the service strategy as part of the IT service management.
• Led disaster recovery and business continuity setups of tier -3 applications/infrastructure. Established RTO and RPO of applications.

A/ Network & Internet Support Manager à King Saud bin Abdulaziz University for Health Sciences
  • Arabie Saoudite - Riyad
  • avril 2012 à octobre 2018

• Architect, manage and maintain primary services located in university's data center to serve 10 Colleges and more than 5000 users.
• Assess university's security measures, such as firewalls, IDS, anti-virus software, and passwords.
• Assess university's IT infrastructure performance optimization, such as internet bandwidth, routers, switches, servers, and storage.
• Manage and supervise IT controls prevention systems, including authentication, authorization, physical security, and encryption.
• Manage and supervise IT controls restoration systems, including backups, replication, fail-over, and disaster recovery.
• Manage and supervise IT controls detection systems, including monitoring and auditing. Manage data center expansion project successfully.

Network Engineer à ALRAJHI Bank
  • Arabie Saoudite - Riyad
  • mars 2009 à mars 2012

• Monitored network capacity and performance to diagnose and resolve complex network problems• Provided network support services for devices such as hubs, bridges, routers, and other hardware for more than 700 branches and 3000 ATM.
• Troubleshot complex multi-vendor network service provider issues Within short time.
• Provided complete end-to-end engineering and installation of route-based IP network solutions for 800 ATMs with minimum downtime.
• Managed, tracked, and coordinated problem resolution and escalation processes.
• Performed troubleshooting for Juniper, Cisco, and packet analysis.
• Created VPN infrastructure and allowed for secure remote connections.

Network Engineer (On-job Trainee), à King Fahd University of Petroleum and Minerals
  • Arabie Saoudite - Dammam
  • juin 2007 à juillet 2007

- Deploy wireless Access Point on university campus.
- Checking network connectivity

Éducation

Master, MBA
  • à Saudi Electronic University
  • mai 2021
Baccalauréat, Computer Engineering
  • à King Fahd University of Petroleum and Minerals
  • juillet 2008

Specialties & Skills

Routing
Routers
Petroleum
MS office
Analysis
Network Troubleshooting
Cisco Devices
Access Management
Asset Security
Communication Security
Identity Management
Network Security
Risk Management
Security Assessment
Security Engineering
Security Management
Security Operations
Security Testing
Software Development Security

Langues

Arabe
Expert
Anglais
Expert

Formation et Diplômes

Operations Management Foundations (Formation)
Institut de formation:
LinkedIn
Date de la formation:
January 2017
Change Management (Formation)
Institut de formation:
ACTrain
Date de la formation:
August 2017
Project Management Professional (Formation)
Institut de formation:
Alkhaleej
Troubleshooting and Maintaining Cisco IP Networks (Formation)
Institut de formation:
Sigma IT
Date de la formation:
November 2011
Certified Information Systems Security Professional (CISSP) (Certificat)
Date de la formation:
February 2017
Valide jusqu'à:
April 2020
Key Managerial and Administrative Skills (Formation)
Institut de formation:
Human Resources Development Ltd.
Date de la formation:
October 2014
Cisco Certified Network Professional (Certificat)
Date de la formation:
December 2011
Valide jusqu'à:
December 2014
Implementing CiscoWorks (Formation)
Institut de formation:
Sigma IT
Date de la formation:
August 2011
Implementing Cisco MPLS (Formation)
Institut de formation:
Sigma IT
Date de la formation:
December 2011
Group Dynamic and Interpersonal Relation Skills (Formation)
Institut de formation:
EUROMA Tech
Date de la formation:
March 2009
High Performance Teams (Formation)
Institut de formation:
Human Resources Development Ltd.
Date de la formation:
October 2014
Implementing Cisco IP Routing (Formation)
Institut de formation:
Sigma IT
Date de la formation:
April 2011
Cisco Certified Network Associate (Certificat)
Date de la formation:
April 2011
Valide jusqu'à:
April 2014
Implementing Cisco IP Switched Networks (Formation)
Institut de formation:
Sigma IT
Date de la formation:
July 2011
Leading People and Team (Formation)
Institut de formation:
Human Resources Development Ltd.
Date de la formation:
October 2014