Mohammed Ahmed, Cybersecurity Risk Consultant

Mohammed Ahmed

Cybersecurity Risk Consultant

Risk Management Group

Lieu
Canada - Ontario
Éducation
Baccalauréat, Management Information Systems
Expérience
19 years, 3 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :19 years, 3 Mois

Cybersecurity Risk Consultant à Risk Management Group
  • Canada - Ontario
  • Je travaille ici depuis janvier 2017

January 2017 - Present
Cybersecurity Risk Consultant, Risk Management Group, Toronto, Canada

 Identified IT risk and contributed to the execution of the IT risk management strategy supporting business objectives and aligning with the enterprise risk management (ERM) strategy
 Analyzed and evaluated enterprise risk to determine the likelihood and impact on business objectives and enabled risk-based decision making
 Determined risk response options and evaluated their efficiency and effectiveness to manage risk in alignment with the business objectives
 Continuously monitored and reported on IT risk and controls to stakeholders and ensured continued efficiency and effectiveness and reporting on KRIs and KPIs

Successfully delivered on the following requirements for our clients as Managing Consultant

Threat & Risk Assessment - TRA
Responsibilities:
 TRA Identifying the Scoping Criteria
 Planning the Objectives and TRA Approach
 Identifying Assets & Business Value
 Threat, External & Internal Factors
 Threat/Risk Modeling using CVSS, STRIDE, ISO 31000
 Risk Evaluation & Prioritization based on Likelihood and Impact
 Risk Evaluation of Controls in place to calculate Residual Risk
 Prioritized Recommendations & Solutions to Address Risk
 Executive & Technical Reports
 Delivered most TRAs using ISO 27000, ISO 31000, SANS Top 20, NIST 800-53

Information Security Assessments
Responsibilities:
 Enterprise Security Assessments
 Applications Security Program Management
 Security Architecture Reviews
 Controls Assessments - ISO 27001/27002 Frameworks SANS Top 20 Critical Controls
 Technical Assessments - Vulnerability Assessment, Penetration Testing
 Technical Reviews - Firewalls Reviews, IPS Review, SIEM Review DLP Review
 Endpoint and Mobile Reviews
 Post Assessment - Hardening & Remediation activities
 Benchmark Reviews CIS and NIST Framework
 Professional Services Deployment - File Integrity Monitoring (Tripwire), SIEM

Awareness & Training
Delivered Corporate trainings for vendor certifications - AlienVault, Securonix, and Council Course (CEH)

Senior Program Manager - Risk, Governance & Compliance à Cybersecurity Umbrella Corp
  • Canada - Ontario
  • décembre 2016 à septembre 2018

Established and maintained an information security governance framework along with its supporting processes and ensured that the information security strategy is aligned with the organizational goals and objectives, information risk is managed appropriately, and program resources are managed.
•Managed information risk to acceptable levels while meeting the business, legal and compliance requirements of the organization by establishing processes, identifying legal and regulatory requirements, evaluating information security controls, identifying gaps, monitoring existing risks and reporting on noncompliance to assist in the risk management decision making process.
•Established and managed the information security program in alignment with the information security strategy by ensuring alignment between IS program and other business functions, establishing awareness and training programs, and periodically reporting program management and operational metrics
•Planned, established and managed the capabilities to detect, investigate, respond and recover from information security incidents to minimize business impact by establishing incident response plans, implementing processes for timely reporting on incidents, maintaining escalation and notification processes, communicating incident response plans, conducting post-incident reviews and post mortems to determine root cause, and maintaining integration among IR, DRP and BCP

Cybersecurity Consultant à Cybersecurity Umbrella Corp
  • Canada - Ontario
  • juin 2016 à décembre 2016

Coordinated the development, implementation, assessment and monitoring of cybersecurity controls.
•Created, optimized and managed enterprise vulnerability and patch management program with monthly metrics to measure improvement.
•Identified gaps, conducted risk assessments, provided remediation solutions and oversight of implementation of controls for internal CF assets, to comply with corporate internal information security policies and standards and SANS 20 controls.
•Developed solutions and strategies for facilitating effective and continuous asset management.
•Developed cybersecurity processes and procedures, technical vendor compliance policies, roles and responsibilities (RACI) matrices to meet cybersecurity controls.
•Created and documented standard operating procedures for IT operations and security teams.
•Liaised and interviewed multiple personnel across teams and departments in order to facilitate corporate security posture.

IT Security Analyst à Cybersecurity Umbrella Corp
  • Canada - Ontario
  • octobre 2014 à juin 2016

Conducted risk analysis, prepared risk registers, created reports for key risk matrices, alignment of risk appetite with business objectives.
•Prepared Security Assessment Plans (SAP) for analyzing vulnerability of networks and devices, providing cost benefit analysis of a secure versus insecure framework, revisiting significance of government compliance; thereby convincing clients to implement effective security architecture in their organizations and acquiring potential contracts for cybersecurity Umbrella.
•Developed Plan of Action and Milestone (POA&M) to execute a structured vulnerability assessment plan, thereby increasing efficiency of their business by 30%.
•Assisted in conducting system security assessments hence minimizing security gaps between current program design and corporate security policies.
•Preformed network discovery: host/device, using NMAP and other tools, reducing irrelevant set of in scope IP addresses into a list of active targets, therefore decreasing assessment time and production impact by 30%.
•Monitored and analyzing network traffic (using Wireshark), established baselines, documented anomalies, implemented appropriate measures to minimize security breaches and network downtime by 40%.
•Assisted in developing, coordinating and implementing security standards, procedures and policies to facilitate organization’s success strategy.
•Provided detailed status updates on existing cyber security incidents prioritized with severity regularly, including follow up with client/customer, ensuring satisfactory resolution of issues.

Web Applications Project Manager à Wazzam Web Solutions
  • Canada
  • janvier 2014 à octobre 2014
Digital Account Executive à Rogers Broadcasting – Citytv and OMNI TV
  • Canada
  • mai 2008 à décembre 2009
Data Network Analyst à TELUS
  • Canada
  • octobre 2007 à mai 2008
Technical Consultant à IBM Canad
  • Canada
  • février 2007 à septembre 2007
Information Systems Analyst à Centennial College
  • Canada
  • janvier 2001 à décembre 2006

Éducation

Baccalauréat, Management Information Systems
  • à Centennial College
  • janvier 2001

Information Systems Software Development Network Administration Systems Administration Technical Analysis

Specialties & Skills

APPROACH
CONSULTING
COUNCIL
CUSTOMER RELATIONS
DECISION MAKING
FIREWALLS
INFORMATION SECURITY
MANAGEMENT
MODELING

Profils Sociaux

Site Web Personnel
Site Web Personnel
RiskManagementGroup.ca

Langues

Anglais
Langue Maternelle
Arabe
Moyen
Français
Moyen
Hindi
Moyen
Urdu
Moyen
Espagnol
Débutant

Adhésions

ISACA
  • member
  • May 2017
OWASP
  • Member
  • April 2017
EC Council
  • Trainer and Contributor
  • August 2016
ISO 27001 Auditors Group
  • Regular Member
  • May 2018

Formation et Diplômes

Certified Chief Information Security Officer - CCISO (Formation)
Institut de formation:
EC-Council
Securonix Security Analyst/Administrator (Certificat)
Date de la formation:
January 2017
Alien Vault - SIEM Implementor (Formation)
Institut de formation:
Alien Vault - AT&T
Secure Coding - ASP.NET (Formation)
Institut de formation:
EC Council
Network Defense (Formation)
Institut de formation:
EC Council
Computer Hacking & Forensic Investigator (Formation)
Institut de formation:
EC Council
Date de la formation:
January 2017
Certified EC Council Instructor (Certificat)
Date de la formation:
January 2018
Certified Ethical Hacker - CEH (Certificat)
Date de la formation:
May 2017
ISO 27001 ISMS Lead Auditor (Certificat)
Date de la formation:
March 2018