نفيد أحمد, Cyber Security & Governance Consultant

نفيد أحمد

Cyber Security & Governance Consultant

National Information Center - SDAIA

البلد
المملكة العربية السعودية - الرياض
التعليم
بكالوريوس, Electrical and Electronics
الخبرات
33 years, 0 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :33 years, 0 أشهر

Cyber Security & Governance Consultant في National Information Center - SDAIA
  • المملكة العربية السعودية - الرياض
  • أشغل هذه الوظيفة منذ أبريل 2013

Transformed the Information Security (now Cyber Security) function from an ad hoc, unstructured entity to a strategized, organized and resourced one.
Setup the Risk Management Function, Policies, Procedures and Automated GRC processes
Expert in the Functional Design & Implementation of all Modules of RSA Archer
Efficiently adopted global benchmarks for enhancing Risk Management (Cobit for Risk, ISO 31000, NIST RMF and ISF Risk framework) 
Effectively Accomplished all Risk Management projects on-time
Consulted and Advised Cross Functional Technical Teams on Cybersecurity best practices and controls (NCA ECC & CCC)
Assessed Organizational Maturity against NIST, & CIS Top20.
Modelled Cybersecurity program using NIST CS framework
Defined Information Security Strategy with Initiatives designed to achieve Enterprise goals.
SME (Subject Matter Expert) for the Design, Implementation, Certification and Sustenance of the ISMS benchmarked to ISO 27001:2013
Mentored Colleagues in the fields of Strategy, Risk Management, GRC, VAPT, Cyber security incident management and forensics.
Championed Initiatives for Enterprise wide IT Governance using Cobit 5.

Head - IT Security في Dubai Customs
  • الإمارات العربية المتحدة - دبي
  • نوفمبر 2007 إلى أبريل 2013

Change Enablement, adoption and implementation of Cobit integrated with existing ISO standards
Strategized, defined and setup Information Security Office function (Vision, Mission, Goals, KPI’s, Business decomposition)
Managed Implementation and sustenance of ISO 27001 
Certification for all locations and all divisions
Addressed Identified gaps in Technology through best of breed tool Implementation management
Mentoring of teams' Security Cyber forensics capability enhancement. (Data acquisition, analysis, investigations, chain of custody and reporting) 
Managed development and implementation of Information security policy, standards, guidelines and procedures
Automation of Security processes through a cycle of Demand outline, Business case, Evaluations and Implementation of technologies that have helped the organization climb the InfoSec maturity scale from 2 to 3

Head - Technology & Risk Management Division في Saudi Paramount Computer Systems
  • المملكة العربية السعودية - الرياض
  • ديسمبر 2003 إلى نوفمبر 2007

Led and Managed the Professional Services Consulting division
Worked collaboratively in a team environment
Supervised and Managed all Information security projects (technical and consulting engagements) for customers across verticals and geographies.
Resolved all customer issues professionally and in a timely manner
Instilled the need for  Information Security by regional speaking engagements and paper presentations.
Modernized outdated information security awareness programs for several corporations.
Audited IS and Processes for UN body leading to adoption of best practices standards and frameworks

Principal Consultant في Wipro Infotech
  • الهند - بنغالورو
  • أبريل 2003 إلى ديسمبر 2003

Accomplished 4 assigned Information Security projects on-time
Led Pre-Sales Initiatives and engagements with customers in different verticals.
Overseen Implementation of Consulting Information Security projects pertaining to BCDR, Identity Management, VAPT and Risk Assessments
Utilized strong interpersonal and communications skills to serve customers

Practice Head - Information Security في Vinciti Networks
  • الهند - بنغالورو
  • سبتمبر 2002 إلى أبريل 2003

Initiated Information Practice to serve Customers in India and in the US.
Handled Pre-Sales and supported sales team
Devised enterprise security strategies safeguarding information assets and ensuring compliance with regulatory mandates
Supported the delivery of Technological Projects

Project Manager - Information Security في Hp - India (Digital)
  • الهند - بنغالورو
  • سبتمبر 2001 إلى أغسطس 2002

Worked collaboratively in team environment to enhance Digital's Information Security.
Handled all in-house Security implementations
Managed teams driving IT Security implementations across all Digital campuses.
Supported other technical teams (Infra, systems etc) and advised on IT Security requirements
Championed the cause for Information Security Awareness
Guided cross-functional teams in the design, validation, acceptance testing and implementation of secure, networked communications across remote sites for several key clients.

Security Consultant في iLantus Technologies
  • الهند - بنغالورو
  • يوليو 2000 إلى سبتمبر 2001

Led projects on Identity management to successfully on-time completion
Handled Pre-Sales activities for clients in India and the US.
Successful project implementation for US stock exchanges in the West and East coasts
Enabled key changes in Customer awareness programs to ensure reduction in Security Incidents

Senior Electrical Engineer في GE / Siemens
  • الإمارات العربية المتحدة - أبو ظبي
  • ديسمبر 1990 إلى يناير 2000

Managed various Projects for customers across UAE and parts of the Arab world
Engineered Power generation and distribution projects
Engineered Electrical Lighting projects for stadiums, race courses, roads and townships.
Instrumental in Manufacturing and Setup of Glass reinforced plastic enclosures for distribution panels etc.

الخلفية التعليمية

بكالوريوس, Electrical and Electronics
  • في University of Madras
  • أبريل 1990

Specialties & Skills

ISO 27001
Cloud Computing
Risk Management
Cyber Security
Governance
RSA Archer
ITSM; ITIL; ISO 20000
BUSINESS CASE
COMMUNICATION SKILLS
CONFERENCES
CONSULTING
DELIVERY
Risk Management
Cyber Forensics; Encase
Time Management
Security incident management
ISMS , ISO 27001
Cyber Security
IT Governance, Cobit
Cloud Security
Audit and Compliance
Leadership

حسابات مواقع التواصل الاجتماعي

الموقع الشخصي
الموقع الشخصي

لقد تم حذف الرابط بسبب انتهاكه لسياسة الموقع. يرجى التواصل مع قسم الدعم لمزيد من المعلومات.

اللغات

الانجليزية
متمرّس
العربية
متوسط
الأوردو
اللغة الأم
الهندية
متمرّس

العضويات

ISC2
  • Member
  • February 2001
ISACA
  • GRA
  • February 2012

التدريب و الشهادات

Forensics Acquisition & Analysis (تدريب)
معهد التدريب:
Access Data
تاريخ الدورة:
February 2011
CCSK Plus (تدريب)
معهد التدريب:
CSA, Black Hat
تاريخ الدورة:
March 2012
RSA Security Analytics Core Admin (SA) (تدريب)
معهد التدريب:
RSA
تاريخ الدورة:
February 2016
RSA Archer Administration (تدريب)
معهد التدريب:
RSA
تاريخ الدورة:
January 2016
ISO 2000 Practitioner (الشهادة)
تاريخ الدورة:
June 2012
ISO 27001 Implementation and Lead Auditor (الشهادة)
تاريخ الدورة:
March 2013
COBIT 5 Foundation (الشهادة)
تاريخ الدورة:
January 2013
CGEIT (الشهادة)
تاريخ الدورة:
February 2009
CISA (الشهادة)
تاريخ الدورة:
May 2005
CISM (الشهادة)
تاريخ الدورة:
May 2007
CISSP (الشهادة)
تاريخ الدورة:
September 2001