Muhammad Razzaq Chishty, Senior Information Systems Security Auditor

Muhammad Razzaq Chishty

Senior Information Systems Security Auditor

Arab National Bank

Location
Saudi Arabia - Riyadh
Education
Bachelor's degree, Computer Systems Engineering
Experience
13 years, 11 Months

Share My Profile

Block User


Work Experience

Total years of experience :13 years, 11 Months

Senior Information Systems Security Auditor at Arab National Bank
  • Saudi Arabia - Riyadh
  • My current job since December 2016

Assess the implementation of Bank's Information Technology (IT) and Information Security (Info Sec) Policies & Procedures, Standards, established practices​ and related regulations.

Senior Information Security Engineer at comspots
  • Saudi Arabia - Riyadh
  • January 2013 to November 2016

• Perform Network and Application Penetration Testing using both Automated and Manual techniques.
• Design and perform audits of computer systems to ensure they are operating securely and that data is protected from both internal and external threats
• Assess system-wide security statuses
• Design and recommend Implementation of IT security policies, procedures and standards
• Ensure compliance to policies and procedures
• Evaluate highly complex security systems according to industry best practices to safeguard internal information systems and databases
• Lead investigations of security violations and breaches and recommend solutions, prepare reports on intrusions as necessary, and provide an analysis summary for management
• Respond to complex requests for information security information from both internal and external customers
• Implementing Private and Public Key Authentication, Encryption and Decryption in different security products
• Proven ability to troubleshoot and quickly resolve complex hardware, software and network issues
• Technical evaluation and selection of security management tools
• Advising management on information security related issues

Information Security Engineer at Horizon Tech Services
  • Pakistan - Islamabad
  • June 2010 to January 2013

• Developed a Client/Server based multi-threaded Wi-Fi auditing tool using some open source APIs, frontend GUI was developed in JAVA and at backend Perl, Python, bash scripting, and MySQL database was used.
• Worked on a stateful packet inspection firewall project to build a complete, secure and stable firewall exclusively from Open Source software
• Implemented Private and Public Key Authentication, Encryption and Decryption in different security products.
• Penetration testing of different Information Security products e.g. firewalls, IPS, and IDS. wired and wireless networks auditing and penetration testing
• Also have done some projects in C, VB, PHP, Perl, Python and Adobe Flex
• Implementation of IT security policies, procedures and standards.
• Advising management on information security related issues.

Education

Bachelor's degree, Computer Systems Engineering
  • at Ghulam Ishaq Khan Institute (GIKI) of Engineering Science and Technology, Topi, Swabi, Pakistan
  • June 2010

Computer Systems Engineering

Specialties & Skills

Vulnerability Management
Cyber Security
IT Audit
Penetration Testing
Ethical Hacking
Ethical Hacking/ Penetration Testing
Project Management
Information Security Architecture
Development and implementation of Information Security Policies, Standards, Procedures, and Guidelin
Information Security Risk Assessment
Improve organizations IT continuity capabilities
Excellent communication and team management skills
Information Security Program development and implementation
Secure Software Development
IT and regulatory compliance and audit
Information Security Management System Development

Languages

English
Expert
Urdu
Expert
Arabic
Intermediate

Training and Certifications

CDPSE - Certified Data Privacy Solutions Engineer by ISACA USA (Certificate)
Date Attended:
June 2020
CEH v10 - Certified Ethical Hacker by EC-Council USA (Certificate)
Date Attended:
February 2019
CISSP - Certified Information Systems Security Professional by ISC² USA (Certificate)
Date Attended:
April 2018
CEH v.6 - Certified Ethical Hacker by EC-Council USA (Certificate)
Date Attended:
May 2011
Valid Until:
May 2016
ECSA - Certified Security Analyst by EC-Council USA (Certificate)
Date Attended:
November 2012
Valid Until:
November 2012
CISA - Certified Information Systems Auditor | by ISACA USA (Certificate)
Date Attended:
November 2017

Hobbies

  • Reading Books and Technical Blogs