Muhammad Razzaq Chishty, Senior Information Systems Security Auditor

Muhammad Razzaq Chishty

Senior Information Systems Security Auditor

Arab National Bank

البلد
المملكة العربية السعودية - الرياض
التعليم
بكالوريوس, Computer Systems Engineering
الخبرات
13 years, 11 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :13 years, 11 أشهر

Senior Information Systems Security Auditor في Arab National Bank
  • المملكة العربية السعودية - الرياض
  • أشغل هذه الوظيفة منذ ديسمبر 2016

Assess the implementation of Bank's Information Technology (IT) and Information Security (Info Sec) Policies & Procedures, Standards, established practices​ and related regulations.

Senior Information Security Engineer في comspots
  • المملكة العربية السعودية - الرياض
  • يناير 2013 إلى نوفمبر 2016

• Perform Network and Application Penetration Testing using both Automated and Manual techniques.
• Design and perform audits of computer systems to ensure they are operating securely and that data is protected from both internal and external threats
• Assess system-wide security statuses
• Design and recommend Implementation of IT security policies, procedures and standards
• Ensure compliance to policies and procedures
• Evaluate highly complex security systems according to industry best practices to safeguard internal information systems and databases
• Lead investigations of security violations and breaches and recommend solutions, prepare reports on intrusions as necessary, and provide an analysis summary for management
• Respond to complex requests for information security information from both internal and external customers
• Implementing Private and Public Key Authentication, Encryption and Decryption in different security products
• Proven ability to troubleshoot and quickly resolve complex hardware, software and network issues
• Technical evaluation and selection of security management tools
• Advising management on information security related issues

Information Security Engineer في Horizon Tech Services
  • باكستان - إسلام أباد
  • يونيو 2010 إلى يناير 2013

• Developed a Client/Server based multi-threaded Wi-Fi auditing tool using some open source APIs, frontend GUI was developed in JAVA and at backend Perl, Python, bash scripting, and MySQL database was used.
• Worked on a stateful packet inspection firewall project to build a complete, secure and stable firewall exclusively from Open Source software
• Implemented Private and Public Key Authentication, Encryption and Decryption in different security products.
• Penetration testing of different Information Security products e.g. firewalls, IPS, and IDS. wired and wireless networks auditing and penetration testing
• Also have done some projects in C, VB, PHP, Perl, Python and Adobe Flex
• Implementation of IT security policies, procedures and standards.
• Advising management on information security related issues.

الخلفية التعليمية

بكالوريوس, Computer Systems Engineering
  • في Ghulam Ishaq Khan Institute (GIKI) of Engineering Science and Technology, Topi, Swabi, Pakistan
  • يونيو 2010

Computer Systems Engineering

Specialties & Skills

Vulnerability Management
Cyber Security
IT Audit
Penetration Testing
Ethical Hacking
Ethical Hacking/ Penetration Testing
Project Management
Information Security Architecture
Development and implementation of Information Security Policies, Standards, Procedures, and Guidelin
Information Security Risk Assessment
Improve organizations IT continuity capabilities
Excellent communication and team management skills
Information Security Program development and implementation
Secure Software Development
IT and regulatory compliance and audit
Information Security Management System Development

اللغات

الانجليزية
متمرّس
الأوردو
متمرّس
العربية
متوسط

التدريب و الشهادات

CDPSE - Certified Data Privacy Solutions Engineer by ISACA USA (الشهادة)
تاريخ الدورة:
June 2020
CEH v10 - Certified Ethical Hacker by EC-Council USA (الشهادة)
تاريخ الدورة:
February 2019
CISSP - Certified Information Systems Security Professional by ISC² USA (الشهادة)
تاريخ الدورة:
April 2018
CEH v.6 - Certified Ethical Hacker by EC-Council USA (الشهادة)
تاريخ الدورة:
May 2011
صالحة لغاية:
May 2016
ECSA - Certified Security Analyst by EC-Council USA (الشهادة)
تاريخ الدورة:
November 2012
صالحة لغاية:
November 2012
CISA - Certified Information Systems Auditor | by ISACA USA (الشهادة)
تاريخ الدورة:
November 2017

الهوايات

  • Reading Books and Technical Blogs