Muhammad Razzaq Chishty, Senior Information Systems Security Auditor

Muhammad Razzaq Chishty

Senior Information Systems Security Auditor

Arab National Bank

Lieu
Arabie Saoudite - Riyad
Éducation
Baccalauréat, Computer Systems Engineering
Expérience
13 years, 11 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :13 years, 11 Mois

Senior Information Systems Security Auditor à Arab National Bank
  • Arabie Saoudite - Riyad
  • Je travaille ici depuis décembre 2016

Assess the implementation of Bank's Information Technology (IT) and Information Security (Info Sec) Policies & Procedures, Standards, established practices​ and related regulations.

Senior Information Security Engineer à comspots
  • Arabie Saoudite - Riyad
  • janvier 2013 à novembre 2016

• Perform Network and Application Penetration Testing using both Automated and Manual techniques.
• Design and perform audits of computer systems to ensure they are operating securely and that data is protected from both internal and external threats
• Assess system-wide security statuses
• Design and recommend Implementation of IT security policies, procedures and standards
• Ensure compliance to policies and procedures
• Evaluate highly complex security systems according to industry best practices to safeguard internal information systems and databases
• Lead investigations of security violations and breaches and recommend solutions, prepare reports on intrusions as necessary, and provide an analysis summary for management
• Respond to complex requests for information security information from both internal and external customers
• Implementing Private and Public Key Authentication, Encryption and Decryption in different security products
• Proven ability to troubleshoot and quickly resolve complex hardware, software and network issues
• Technical evaluation and selection of security management tools
• Advising management on information security related issues

Information Security Engineer à Horizon Tech Services
  • Pakistan - Islamabad
  • juin 2010 à janvier 2013

• Developed a Client/Server based multi-threaded Wi-Fi auditing tool using some open source APIs, frontend GUI was developed in JAVA and at backend Perl, Python, bash scripting, and MySQL database was used.
• Worked on a stateful packet inspection firewall project to build a complete, secure and stable firewall exclusively from Open Source software
• Implemented Private and Public Key Authentication, Encryption and Decryption in different security products.
• Penetration testing of different Information Security products e.g. firewalls, IPS, and IDS. wired and wireless networks auditing and penetration testing
• Also have done some projects in C, VB, PHP, Perl, Python and Adobe Flex
• Implementation of IT security policies, procedures and standards.
• Advising management on information security related issues.

Éducation

Baccalauréat, Computer Systems Engineering
  • à Ghulam Ishaq Khan Institute (GIKI) of Engineering Science and Technology, Topi, Swabi, Pakistan
  • juin 2010

Computer Systems Engineering

Specialties & Skills

Vulnerability Management
Cyber Security
IT Audit
Penetration Testing
Ethical Hacking
Ethical Hacking/ Penetration Testing
Project Management
Information Security Architecture
Development and implementation of Information Security Policies, Standards, Procedures, and Guidelin
Information Security Risk Assessment
Improve organizations IT continuity capabilities
Excellent communication and team management skills
Information Security Program development and implementation
Secure Software Development
IT and regulatory compliance and audit
Information Security Management System Development

Langues

Anglais
Expert
Urdu
Expert
Arabe
Moyen

Formation et Diplômes

CDPSE - Certified Data Privacy Solutions Engineer by ISACA USA (Certificat)
Date de la formation:
June 2020
CEH v10 - Certified Ethical Hacker by EC-Council USA (Certificat)
Date de la formation:
February 2019
CISSP - Certified Information Systems Security Professional by ISC² USA (Certificat)
Date de la formation:
April 2018
CEH v.6 - Certified Ethical Hacker by EC-Council USA (Certificat)
Date de la formation:
May 2011
Valide jusqu'à:
May 2016
ECSA - Certified Security Analyst by EC-Council USA (Certificat)
Date de la formation:
November 2012
Valide jusqu'à:
November 2012
CISA - Certified Information Systems Auditor | by ISACA USA (Certificat)
Date de la formation:
November 2017

Loisirs

  • Reading Books and Technical Blogs