Mohammed Ahmed, Cybersecurity Risk Consultant

Mohammed Ahmed

Cybersecurity Risk Consultant

Risk Management Group

Location
Canada - Ontario
Education
Bachelor's degree, Management Information Systems
Experience
19 years, 3 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 3 Months

Cybersecurity Risk Consultant at Risk Management Group
  • Canada - Ontario
  • My current job since January 2017

January 2017 - Present
Cybersecurity Risk Consultant, Risk Management Group, Toronto, Canada

 Identified IT risk and contributed to the execution of the IT risk management strategy supporting business objectives and aligning with the enterprise risk management (ERM) strategy
 Analyzed and evaluated enterprise risk to determine the likelihood and impact on business objectives and enabled risk-based decision making
 Determined risk response options and evaluated their efficiency and effectiveness to manage risk in alignment with the business objectives
 Continuously monitored and reported on IT risk and controls to stakeholders and ensured continued efficiency and effectiveness and reporting on KRIs and KPIs

Successfully delivered on the following requirements for our clients as Managing Consultant

Threat & Risk Assessment - TRA
Responsibilities:
 TRA Identifying the Scoping Criteria
 Planning the Objectives and TRA Approach
 Identifying Assets & Business Value
 Threat, External & Internal Factors
 Threat/Risk Modeling using CVSS, STRIDE, ISO 31000
 Risk Evaluation & Prioritization based on Likelihood and Impact
 Risk Evaluation of Controls in place to calculate Residual Risk
 Prioritized Recommendations & Solutions to Address Risk
 Executive & Technical Reports
 Delivered most TRAs using ISO 27000, ISO 31000, SANS Top 20, NIST 800-53

Information Security Assessments
Responsibilities:
 Enterprise Security Assessments
 Applications Security Program Management
 Security Architecture Reviews
 Controls Assessments - ISO 27001/27002 Frameworks SANS Top 20 Critical Controls
 Technical Assessments - Vulnerability Assessment, Penetration Testing
 Technical Reviews - Firewalls Reviews, IPS Review, SIEM Review DLP Review
 Endpoint and Mobile Reviews
 Post Assessment - Hardening & Remediation activities
 Benchmark Reviews CIS and NIST Framework
 Professional Services Deployment - File Integrity Monitoring (Tripwire), SIEM

Awareness & Training
Delivered Corporate trainings for vendor certifications - AlienVault, Securonix, and Council Course (CEH)

Senior Program Manager - Risk, Governance & Compliance at Cybersecurity Umbrella Corp
  • Canada - Ontario
  • December 2016 to September 2018

Established and maintained an information security governance framework along with its supporting processes and ensured that the information security strategy is aligned with the organizational goals and objectives, information risk is managed appropriately, and program resources are managed.
•Managed information risk to acceptable levels while meeting the business, legal and compliance requirements of the organization by establishing processes, identifying legal and regulatory requirements, evaluating information security controls, identifying gaps, monitoring existing risks and reporting on noncompliance to assist in the risk management decision making process.
•Established and managed the information security program in alignment with the information security strategy by ensuring alignment between IS program and other business functions, establishing awareness and training programs, and periodically reporting program management and operational metrics
•Planned, established and managed the capabilities to detect, investigate, respond and recover from information security incidents to minimize business impact by establishing incident response plans, implementing processes for timely reporting on incidents, maintaining escalation and notification processes, communicating incident response plans, conducting post-incident reviews and post mortems to determine root cause, and maintaining integration among IR, DRP and BCP

Cybersecurity Consultant at Cybersecurity Umbrella Corp
  • Canada - Ontario
  • June 2016 to December 2016

Coordinated the development, implementation, assessment and monitoring of cybersecurity controls.
•Created, optimized and managed enterprise vulnerability and patch management program with monthly metrics to measure improvement.
•Identified gaps, conducted risk assessments, provided remediation solutions and oversight of implementation of controls for internal CF assets, to comply with corporate internal information security policies and standards and SANS 20 controls.
•Developed solutions and strategies for facilitating effective and continuous asset management.
•Developed cybersecurity processes and procedures, technical vendor compliance policies, roles and responsibilities (RACI) matrices to meet cybersecurity controls.
•Created and documented standard operating procedures for IT operations and security teams.
•Liaised and interviewed multiple personnel across teams and departments in order to facilitate corporate security posture.

IT Security Analyst at Cybersecurity Umbrella Corp
  • Canada - Ontario
  • October 2014 to June 2016

Conducted risk analysis, prepared risk registers, created reports for key risk matrices, alignment of risk appetite with business objectives.
•Prepared Security Assessment Plans (SAP) for analyzing vulnerability of networks and devices, providing cost benefit analysis of a secure versus insecure framework, revisiting significance of government compliance; thereby convincing clients to implement effective security architecture in their organizations and acquiring potential contracts for cybersecurity Umbrella.
•Developed Plan of Action and Milestone (POA&M) to execute a structured vulnerability assessment plan, thereby increasing efficiency of their business by 30%.
•Assisted in conducting system security assessments hence minimizing security gaps between current program design and corporate security policies.
•Preformed network discovery: host/device, using NMAP and other tools, reducing irrelevant set of in scope IP addresses into a list of active targets, therefore decreasing assessment time and production impact by 30%.
•Monitored and analyzing network traffic (using Wireshark), established baselines, documented anomalies, implemented appropriate measures to minimize security breaches and network downtime by 40%.
•Assisted in developing, coordinating and implementing security standards, procedures and policies to facilitate organization’s success strategy.
•Provided detailed status updates on existing cyber security incidents prioritized with severity regularly, including follow up with client/customer, ensuring satisfactory resolution of issues.

Web Applications Project Manager at Wazzam Web Solutions
  • Canada
  • January 2014 to October 2014
Digital Account Executive at Rogers Broadcasting – Citytv and OMNI TV
  • Canada
  • May 2008 to December 2009
Data Network Analyst at TELUS
  • Canada
  • October 2007 to May 2008
Technical Consultant at IBM Canad
  • Canada
  • February 2007 to September 2007
Information Systems Analyst at Centennial College
  • Canada
  • January 2001 to December 2006

Education

Bachelor's degree, Management Information Systems
  • at Centennial College
  • January 2001

Information Systems Software Development Network Administration Systems Administration Technical Analysis

Specialties & Skills

APPROACH
CONSULTING
COUNCIL
CUSTOMER RELATIONS
DECISION MAKING
FIREWALLS
INFORMATION SECURITY
MANAGEMENT
MODELING

Social Profiles

Personal Website
Personal Website
RiskManagementGroup.ca

Languages

English
Native Speaker
Arabic
Intermediate
French
Intermediate
Hindi
Intermediate
Urdu
Intermediate
Spanish
Beginner

Memberships

ISACA
  • member
  • May 2017
OWASP
  • Member
  • April 2017
EC Council
  • Trainer and Contributor
  • August 2016
ISO 27001 Auditors Group
  • Regular Member
  • May 2018

Training and Certifications

Certified Chief Information Security Officer - CCISO (Training)
Training Institute:
EC-Council
Securonix Security Analyst/Administrator (Certificate)
Date Attended:
January 2017
Alien Vault - SIEM Implementor (Training)
Training Institute:
Alien Vault - AT&T
Secure Coding - ASP.NET (Training)
Training Institute:
EC Council
Network Defense (Training)
Training Institute:
EC Council
Computer Hacking & Forensic Investigator (Training)
Training Institute:
EC Council
Date Attended:
January 2017
Certified EC Council Instructor (Certificate)
Date Attended:
January 2018
Certified Ethical Hacker - CEH (Certificate)
Date Attended:
May 2017
ISO 27001 ISMS Lead Auditor (Certificate)
Date Attended:
March 2018