Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
MUSTAPHA BENGALI, Head of Corporate Information Security

MUSTAPHA BENGALI

Head of Corporate Information Security·Ooredoo Qatar

Qatar

Master's degree, Business Administration

Work experience

Total years of experience: 28 years, 0 months

Head of Corporate Information Security

June 2013 - Present

Ooredoo Qatar

Doha, Qatar

June 2013 - Present

Reporting to CEO, directs Corporate Information and Cyber Security for 10 separate global telecom operations (OPCO) across the GCC, Southeast Asia, and North Africa. Defines strategic information security framework and blueprints and ensures regulatory compliance with strict adherence to relevant laws, regulations, and local/regional policies. Trusted advisor to Executive Management and the Board on InfoSec program health and the industry threat landscape.

Represents Company at Mission-Critical National Security Forums, Working Groups, and Committees
➔ Qatar National Cyber Security Strategy Committee
➔ Qatar National Business Continuity Forum (QBCF)
➔ Ooredoo Strategic Security and Resilience Working Group
➔ Project Stadia and Fifa 2020 SCDL Cyber Security Working Group
Security Functions Ranked as one of the Most Mature and Prominent across Qatar within a 2 Year-Period
➔ Transformed the Information Security function from a cost to a profit center. Successfully developed and deployed the Security Information Center while establishing group OPCO security organization and annual strategy.
➔ Developed and implemented Managed Security services for customers. Ensured clean Telecom network while reducing information security risk and maximizing ROSI.
➔ Parlayed expertise to identify, assess, and prioritize risks, developing strategic security plans to close gaps and strengthen company capability to combat threats in support of corporate business objectives.
➔ Led the convergence of technical and physical security controls to better coordinate security resources in emergencies and enable identity-based reporting system.
➔ Architected robust function encompassing governance, risk, and compliance, telecom security architecture, operations, monitoring. Effectively mitigates cyber risk while advising other telcos in the group.
➔ Improved security incident detection through the establishment of Security Information Center, allowing constant monitoring and analysis of networks, servers, and databases.
➔ Collaborated with ERM/Resilience teams to evaluate and manage corporate risk Directs risk identification, assessment, and prioritization.
➔ Worked with the B2B function, in establishing the Managed Securi5ty Services offering from RFP and establishment.
➔ Planned and implemented the national clean pipe (Carrier DDoS) service.

Accelerated Advancement of Governance Framework & Structure through Skilled Deployment across all OPCO’s
➔ Developed and implemented Managed Security services for customers that ensured clean Telecom network.
➔ Established a group-wide Cyber Security strategy with set goals, objectives, policies, and standards frameworks; all OPCOs adopted functions and advisories.
▪ Formulated and executed SOPs to protect information and information systems, ensuring the organization maintains security best practices to comply with ISO 27001 standards and series.

Company industry:
Telecommunications
Job role:
Information Technology

Sr. Manager/Business Continuity & Crisis Management

February 2011 - June 2013

etisalat

Dubai, United Arab Emirates

February 2011 - June 2013

I am a founding member of the Etisalat Information Security team & now the Business Continuity & Crisis management section. I am currently involved in establishing the Business Continuity Management framework for etisalat based on the NEP-T, TRA Directive No. 5 and the BS25999-2:2007 standards.

Prior to this role and as part of the Information Security section, I was involved in Security Governance, Awareness, Policies and Certifications based on ISO 27001; Risk Assessment based on ANZ 4360 & FMEA methods & BS25999 based BCMS and Mobile security projects.


Major Projects.

• Leading the Business Continuity Management System initiative for Etisalat, to enhance resilience of all Critical service and ensure continuity. The BCMS will be based on the new BS25999:2 standards. As part of the project, I have been involved in every service that Etisalat delivers broadly classified within Mobile & Fixed (Voice & Data), Internet, Television, Satellite and Carrier services. The project looks at Technological, Regulatory, Legal, Supplies and other aspects, providing immense exposure to all areas of risk and governance for a Telecom.

• I am leading the BCMS Organization to ensure various Telecom service groups in Etisalat are compliant to the UAE TRA & BS25999:2007 standard for Business Continuity Management.

• Leading the design of the Implementation of for all Information Security projects for Etisalat enterprise. This included securing Etisalat services (Mobile Systems etc.), Etisalat Web services, Etisalat Content provider infrastructure and Etisalat Gateways for staff services (Web, Email, Remote access).

Team member part of the Etisalat E4ME portal BS7799 certification. I was involved in creating Security policies and procedures related to the ISMS scope, creation of the ISMS Manual, performing Risk Assessment using ANZ 4630:2000 and Hybrid methods. I was also involved in the migration for the scope to the ISO 27001 certification.

Company industry:
Telecommunications
Job role:
Information Technology

Sr Manager, Information Security Management

August 2008 - February 2011

etisalat

Abu Dhabi, United Arab Emirates

August 2008 - February 2011

• Establishing Security Governance and policy framework;
• Setup a framework to monitor measure and report security posture to management.
• Worked closely with business leaders to ensure Etisalat services & products were secured from internal & external threats.
• Developed technology strategies with IT leadership.
• Established a risk Management process to manage organizational Information Security risks.
• Setting up and conducting the security awareness program.
• Leading ISO 27001 ISMS Certifications for various Etisalat internal scopes;
• Internal Auditor for all ISO 27001 scopes in Etisalat.
• Conducting risk assessments based on ISO 27003, ANZ 4360 & FMEA methods.

Company industry:
Telecommunications
Job role:
Information Technology

Manager, Information Security Management

October 2000 - August 2008

etisalat

Abu Dhabi, United Arab Emirates

October 2000 - August 2008

2000-2002 - Assistant Engineer - Network Security
2002-2003 - Engineer - Network Security
Profile - Risk based network security design, implementation & maintenance. (Firewalls & IDS, Antimalware gateways) for Telecom infrastructure.
2003 - 2007 - Senior Engineer - NISD (Network & Information Security department)
2007-2008 - Manager, Information Security

Company industry:
Telecommunications
Job role:
Information Technology

Senior Executive, Security and Services

June 1999 - August 2000

Softcell Technologies Ltd

Mumbai, India

June 1999 - August 2000

Softcell Technologies is a leading Information technology services and solution provider based in Mumbai, India. My roles were as follows:-

• Founding member of the IT Services & Security team and responsible for IT & Security Planning, Design and Implementation for Softcell customers. It involved understanding the network/infrastructure, risk and ensure that adequate controls were implemented.

Company industry:
IT Services
Job role:
Information Technology

Intranet/Web Administrator

March 1998 - March 1999

Ministry of Information

Riyadh, Saudi Arabia

March 1998 - March 1999

I worked for the Network Team at the Ministry of Information, Riyadh Saudi Arabia.

My role was to manage and administer an IP network running for systems and application servers and planning for new MOI systems.

Company industry:
Public Administration
Job role:
Information Technology

Education

S P Jain Glocabl School of Management

March 2013

March 2013

Master's degree, Business Administration

United Arab Emirates

GPA (point): 3.72 out of 5

GPA (point): 3.72 out of 5

Skills

ISO 27001
Expert
ISO 27001
Expert
Information Security Management
Expert
Information Security Management
Expert
Security Awareness
Expert
Security Awareness
Expert
Business Continuity
Expert
Business Continuity
Expert
Security Management
Expert
Security Management
Expert
Network Security
Expert
Network Security
Expert
Business Continuity Management
Expert
Business Continuity Management
Expert
Information Security Management
Expert
Information Security Management
Expert
Program & Project Management
Expert
Program & Project Management
Expert
Budgeting & Planning
Expert
Budgeting & Planning
Expert
Cybersecurity
Expert
Cybersecurity
Expert
GDPR
Expert
GDPR
Expert
Security Strategy
Expert
Security Strategy
Expert
ISO 27001
Expert
ISO 27001
Expert
Security Awareness
Expert
Security Awareness
Expert
Business Continuity
Expert
Business Continuity
Expert
Security Management
Expert
Security Management
Expert

Languages

English
Expert
Hindi
Intermediate
Gujarati
Native Speaker

Memberships

ISACA UAE Chapter

Program Director, Board Member

January 2009

ISC2

CISSP

February 2002

Training and Certifications

Certifications
CISSP
Feb 2002

Training
Business Continuity Lead Auditor
BS25999 Lead Auditor
Nov 2010