Muhammad Jawwad Alam Siddiqi, Head of Information Security

Muhammad Jawwad Alam Siddiqi

Head of Information Security

Almajdouie Holding

Location
Saudi Arabia
Education
Master's degree, MBA (Digital Tranformation)
Experience
19 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 4 Months

Head of Information Security at Almajdouie Holding
  • Saudi Arabia - Dammam
  • My current job since November 2015

Heading the Information Security function at group level

Deputy Director at NADRA
  • Pakistan - Islamabad
  • December 2012 to November 2015

Heading the Information Security Governance, Risk, Compliance and Trainings & Awareness Teams of NADRA Pakistan.

Information Security Executive at Telenor Pakistan
  • Pakistan - Islamabad
  • January 2010 to December 2012

Responsibilities include:
􀂃 Conducting ISO27001 Internal Audit for Financial Services - Mobile Banking (EasyPaisa)
􀂃 Conducted TL9000 Internal Audit for Business Services, NOC
􀂃 Conducted ISO14001 Internal Audit of Telenor Pakistan
􀂃 Performing Business Impact Analysis for Business Services
􀂃 Conducting Policy Compliance Reviews
􀂃 Performing Incident Response activities
􀂃 Conducting Application Security Reviews
􀂃 Conducting Process Reviews
􀂃 Coordinating with External Auditors
􀂃 Coordinating with Tameer Bank
􀂃 Ensruing regulatory compliance in Financial Services - Mobile Banking

Assistant Manager - IT Advisory Services at KPMG
  • Pakistan - Islamabad
  • July 2009 to December 2009

Responsibilities included:
􀂃 Managing the IT Advisory Service line & IT Audits of KPMG TH Islamabad Office

Major Projects include:
􀂃 Integrated Banking System Selection Consultancy to Khushali Bank
􀂃 Royal Bank of Scotland global KPMG assignment of conducting ISO27001 based security reviews of RBS vendors.
􀂃 Conducted ISO27001 based security review of Ufone for RBS-Ufone co-branding project
􀂃 Conducted ISO27001 based security review of Chanda Law Associates

Senior Associate II - IT Advisory Services at KPMG
  • Pakistan - Islamabad
  • July 2008 to June 2009

Responsibilities include:
􀂃 Leading the IT Advisory Section of KPMG TH Islamabad Office
􀂃 Leading the Information Risk Management (IRM) Audit team of KPMG TH Islamabad Office

IRM clients audited belong to following sectors:
􀂃 Hospitality
->Marriott Hotel Islamabad, Marriott Hotel Karachi, Serena Hotel Islamabad, Pearl Continental Hotel Rawalpindi, Hashwani Hotels Limited, Pakistan Services Limited
􀂃 Manufacturing
-> AkzoNobel (formerly ICI Pakistan), Murree Brewery, Biafo Industries Limited, Bestway Cement Limited, Mustehkam Cement Limited, Fauji Cement Company Limited, Fauji Fertilizer Company Limited, Fauji Fertilizer Bin Qasim Limited
􀂃 Telecom
-> Mobilink (PMCL), Diallog CDMA
􀂃 Insurance (nonlife)
-> Askari General Insurance Company Limited
􀂃 NGO
-> National Rural Support Program (NRSP), Sarhad Rural Support Program
􀂃 Pharmaceutical
-> Ferozsons Laboratories Limited
􀂃 Government
-> Pakistan Telecom Authority (PTA)
􀂃 Oil & Gas
-> Halliburton, Oil & Gas Development Corporation Limited, Dewan Petroleum Limited
􀂃 Stock Exchange
-> Islamabad Stock Exchange
􀂃 Electricity Generation & Distribution
-> Islamabad Electric Supply Company Limited, Southern Electric Power Company, Uch Power, Saif Power Limited, Fauji Power Company (Dharki) Limited
􀂃 Airline
-> Air Blue
􀂃 Banking & Microfinance Institution
-> NRSP Bank, Khushali Bank Limited, First Microfinance Bank
􀂃 Software House & IT Consulting
-> Landmark Resources (LMKR)
􀂃 Construction
-> PakGulf Construction

Information Security Analyst at Digital Processing Systems
  • Pakistan - Islamabad
  • July 2007 to June 2008

􀂃 Leading one of ISO/IEC 27001:2005 implementation team.
􀂃 Maintaining Disaster Recovery Plan
􀂃 Managing Information Security Group (ISG) in the absence of Manager
􀂃 Member Incidence Response Team
􀂃 Coordinating with Consultants, External Auditors & Pakistan Software Export Board (PSEB) Representatives
􀂃 Creating and implementing information security policies and practices in DPS Inc.
􀂃 Monitoring and Controlling the Information Security Management System (ISMS).
􀂃 Implementing ISO/IEC 27001:2005 controls
􀂃 Implementing Information Security related CMMI process areas.
􀂃 Conducting internal audits of applications, processes and physical sites.
􀂃 Conducting risk analysis
􀂃 Providing Information Security Consultancy to the clients of DPS Inc.
􀂃 Coordinating with other branches of DPS Inc. for acquisition and deployment of security hardware.
􀂃 Conducting Information Security Awareness campaigns for all DPS Inc. employees
􀂃 Administering Information Security Induction to newly hired employees in DPS Inc.
􀂃 Preparing EOI and RFP documents for the projects DPS Inc. is interested in.

Jr. Information Security Analyst at Digital Processing Systems
  • Pakistan - Islamabad
  • August 2005 to June 2007

Responsibilities included:
􀂃 Creating and implementing information security policies and practices in DPS Inc.
􀂃 Monitoring and Controlling the Information Security Management System (ISMS).
􀂃 Implementing ISO/IEC 27001:2005 controls
􀂃 Implementing Information Security related CMMI process areas.
􀂃 Conducting internal audits of applications, processes and physical sites.
􀂃 Conducting risk analysis
􀂃 Providing Information Security Consultancy to the clients of DPS Inc.
􀂃 Coordinating with other branches of DPS Inc. for acquisition and deployment of security hardware.
􀂃 Conducting Information Security Awareness campaigns for all DPS Inc. employees
􀂃 Administering Information Security Induction to newly hired employees in DPS Inc.
􀂃 Preparing EOI and RFP documents for the projects DPS Inc. is interested in.
􀂃 Created Training Guides for TABS (Telecommunications, Administration, & Billing System) of ITS
Kuwait. Sites included Warid Telecom (Pakistan) & BanglaLink (Bangladesh).

Jr. Network Engineer at Rawalpindi College for Girls
  • Pakistan - Rawalpindi
  • June 2005 to August 2005

Work responsibility included maintaining college website and computer laboratories.

Internee-Volunteer at Union Bank Limited
  • Pakistan - Islamabad
  • January 2005 to May 2005

Worked in the clearing section of the bank therefore I am familiar with the entire inward and outward
clearing procedures being followed in most of the well reputed banks. Also during my stay there I
prepared an interns manual for those doing internship in the clearing section of Union Bank.

Education

Master's degree, MBA (Digital Tranformation)
  • at University of Southern Queensland, Australia
  • November 2015
Master's degree, Project Management
  • at Shaheed Zulfikar Ali Bhutto Institute of Science and Technology
  • July 2010
Master's degree, Software Engineering
  • at Shaheed Zulfikar Ali Bhutto Institute of Science and Technology
  • April 2008
Bachelor's degree, Business Information Technology
  • at Curtin University of Technology
  • March 2005
Diploma, Major in Information Systems
  • at Informatics Academy
  • August 2004
Diploma, Major in Computer Science
  • at University of Cambridge
  • December 2003
High school or equivalent, Double Majors in Business Computing & Programming
  • at University of Cambridge
  • December 2002

Specialties & Skills

ISO 27001
IT Audit
Information Security Management
Information Security Policy
Risk Management
Compliance
Information Risk Management
ISO 27001
ISO 9001
TL 9000
Inofmration Security Review
Project Management
Disaster Recovery
Business Continuity
Risk Management
Primavera P6
MS Project
SAP Project Systems
MS Office Suite
PhotoExpress
BS25999
Application Security Review
Oracle Financials
Information Security Management
Application Security
Security Awareness
IT Audit
IT Service Management
Security Audits
Vulnerability Assessment
Risk Assessment
Incident Management
ISO14001

Languages

English
Expert
Urdu
Expert

Memberships

ISACA
  • Member
  • November 2007
(ISC)2
  • Member
  • May 2008
Business Continuity Institute
  • Member
  • August 2008
IRCA
  • Provisional Auditor ISMS
  • August 2009

Training and Certifications

CISSP (Certificate)
CISA (Certificate)
PMO Maturity (Training)
Training Institute:
SysComp International
Date Attended:
May 2008
HSSE - People First (Training)
Training Institute:
Edvantage Group
Date Attended:
October 2011
BS25999 Implementer Course (Training)
Training Institute:
Business Beam
Date Attended:
November 2008
SEI Authorized - Introduction to CMMI version 1.2 (Training)
Training Institute:
GRAFP Technologies
Date Attended:
November 2008
IRCA Certified - ISMS Lead Auditor Course (Training)
Training Institute:
Moody International
Date Attended:
May 2009
COBIT 4.1 Foundation (Training)
Training Institute:
Business Beam
Date Attended:
October 2009
PMP Prep Course (Training)
Training Institute:
Rita Mulcahy International
Date Attended:
November 2007