Naveed ahmed, Cyber Security & Governance Consultant

Naveed ahmed

Cyber Security & Governance Consultant

National Information Center - SDAIA

Location
Saudi Arabia - Riyadh
Education
Bachelor's degree, Electrical and Electronics
Experience
33 years, 0 Months

Share My Profile

Block User


Work Experience

Total years of experience :33 years, 0 Months

Cyber Security & Governance Consultant at National Information Center - SDAIA
  • Saudi Arabia - Riyadh
  • My current job since April 2013

Transformed the Information Security (now Cyber Security) function from an ad hoc, unstructured entity to a strategized, organized and resourced one.
Setup the Risk Management Function, Policies, Procedures and Automated GRC processes
Expert in the Functional Design & Implementation of all Modules of RSA Archer
Efficiently adopted global benchmarks for enhancing Risk Management (Cobit for Risk, ISO 31000, NIST RMF and ISF Risk framework) 
Effectively Accomplished all Risk Management projects on-time
Consulted and Advised Cross Functional Technical Teams on Cybersecurity best practices and controls (NCA ECC & CCC)
Assessed Organizational Maturity against NIST, & CIS Top20.
Modelled Cybersecurity program using NIST CS framework
Defined Information Security Strategy with Initiatives designed to achieve Enterprise goals.
SME (Subject Matter Expert) for the Design, Implementation, Certification and Sustenance of the ISMS benchmarked to ISO 27001:2013
Mentored Colleagues in the fields of Strategy, Risk Management, GRC, VAPT, Cyber security incident management and forensics.
Championed Initiatives for Enterprise wide IT Governance using Cobit 5.

Head - IT Security at Dubai Customs
  • United Arab Emirates - Dubai
  • November 2007 to April 2013

Change Enablement, adoption and implementation of Cobit integrated with existing ISO standards
Strategized, defined and setup Information Security Office function (Vision, Mission, Goals, KPI’s, Business decomposition)
Managed Implementation and sustenance of ISO 27001 
Certification for all locations and all divisions
Addressed Identified gaps in Technology through best of breed tool Implementation management
Mentoring of teams' Security Cyber forensics capability enhancement. (Data acquisition, analysis, investigations, chain of custody and reporting) 
Managed development and implementation of Information security policy, standards, guidelines and procedures
Automation of Security processes through a cycle of Demand outline, Business case, Evaluations and Implementation of technologies that have helped the organization climb the InfoSec maturity scale from 2 to 3

Head - Technology & Risk Management Division at Saudi Paramount Computer Systems
  • Saudi Arabia - Riyadh
  • December 2003 to November 2007

Led and Managed the Professional Services Consulting division
Worked collaboratively in a team environment
Supervised and Managed all Information security projects (technical and consulting engagements) for customers across verticals and geographies.
Resolved all customer issues professionally and in a timely manner
Instilled the need for  Information Security by regional speaking engagements and paper presentations.
Modernized outdated information security awareness programs for several corporations.
Audited IS and Processes for UN body leading to adoption of best practices standards and frameworks

Principal Consultant at Wipro Infotech
  • India - Bengaluru
  • April 2003 to December 2003

Accomplished 4 assigned Information Security projects on-time
Led Pre-Sales Initiatives and engagements with customers in different verticals.
Overseen Implementation of Consulting Information Security projects pertaining to BCDR, Identity Management, VAPT and Risk Assessments
Utilized strong interpersonal and communications skills to serve customers

Practice Head - Information Security at Vinciti Networks
  • India - Bengaluru
  • September 2002 to April 2003

Initiated Information Practice to serve Customers in India and in the US.
Handled Pre-Sales and supported sales team
Devised enterprise security strategies safeguarding information assets and ensuring compliance with regulatory mandates
Supported the delivery of Technological Projects

Project Manager - Information Security at Hp - India (Digital)
  • India - Bengaluru
  • September 2001 to August 2002

Worked collaboratively in team environment to enhance Digital's Information Security.
Handled all in-house Security implementations
Managed teams driving IT Security implementations across all Digital campuses.
Supported other technical teams (Infra, systems etc) and advised on IT Security requirements
Championed the cause for Information Security Awareness
Guided cross-functional teams in the design, validation, acceptance testing and implementation of secure, networked communications across remote sites for several key clients.

Security Consultant at iLantus Technologies
  • India - Bengaluru
  • July 2000 to September 2001

Led projects on Identity management to successfully on-time completion
Handled Pre-Sales activities for clients in India and the US.
Successful project implementation for US stock exchanges in the West and East coasts
Enabled key changes in Customer awareness programs to ensure reduction in Security Incidents

Senior Electrical Engineer at GE / Siemens
  • United Arab Emirates - Abu Dhabi
  • December 1990 to January 2000

Managed various Projects for customers across UAE and parts of the Arab world
Engineered Power generation and distribution projects
Engineered Electrical Lighting projects for stadiums, race courses, roads and townships.
Instrumental in Manufacturing and Setup of Glass reinforced plastic enclosures for distribution panels etc.

Education

Bachelor's degree, Electrical and Electronics
  • at University of Madras
  • April 1990

Specialties & Skills

ISO 27001
Cloud Computing
Risk Management
Cyber Security
Governance
RSA Archer
ITSM; ITIL; ISO 20000
BUSINESS CASE
COMMUNICATION SKILLS
CONFERENCES
CONSULTING
DELIVERY
Risk Management
Cyber Forensics; Encase
Time Management
Security incident management
ISMS , ISO 27001
Cyber Security
IT Governance, Cobit
Cloud Security
Audit and Compliance
Leadership

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Expert
Arabic
Intermediate
Urdu
Native Speaker
Hindi
Expert

Memberships

ISC2
  • Member
  • February 2001
ISACA
  • GRA
  • February 2012

Training and Certifications

Forensics Acquisition & Analysis (Training)
Training Institute:
Access Data
Date Attended:
February 2011
CCSK Plus (Training)
Training Institute:
CSA, Black Hat
Date Attended:
March 2012
RSA Security Analytics Core Admin (SA) (Training)
Training Institute:
RSA
Date Attended:
February 2016
RSA Archer Administration (Training)
Training Institute:
RSA
Date Attended:
January 2016
ISO 2000 Practitioner (Certificate)
Date Attended:
June 2012
ISO 27001 Implementation and Lead Auditor (Certificate)
Date Attended:
March 2013
COBIT 5 Foundation (Certificate)
Date Attended:
January 2013
CGEIT (Certificate)
Date Attended:
February 2009
CISA (Certificate)
Date Attended:
May 2005
CISM (Certificate)
Date Attended:
May 2007
CISSP (Certificate)
Date Attended:
September 2001