nazia sharieff, Senior IT Governance Analyst

nazia sharieff

Senior IT Governance Analyst

Aspire zone foundation

Location
Qatar - Doha
Education
Bachelor's degree, Information Science
Experience
13 years, 9 Months

Share My Profile

Block User


Work Experience

Total years of experience :13 years, 9 Months

Senior IT Governance Analyst at Aspire zone foundation
  • Qatar - Doha
  • September 2012 to July 2019

Since September 2012, I have worked with AZF to strategize, plan, design, build and control the IT
governance framework, implemented service management improvements, coordinated enterprise
projects to facilitate greater synergies between business and IT stakeholders. I led and managed the
development of information security policies, standards and guidelines from the scratch. In addition, was
involved in the planning, alignment and implementation of IT Strategic Roadmap to combat change
resistance and ensure value delivery, resource management, and risk and performance measurement.
From 2015 to 2017, led continuous improvement initiatives across IT processes for both demand and
supply-side to achieve standard accreditation such as ISO 27001/20000. Directed and organized the
development and implementation of a fully Integrated Management System based on ISO 22001:2013 and ISO/IEC20000 and National Information Assurance Policy (NIA Qatar), involving training, process, and workshops facilitation. Formulated and established a formalized approach to enable enforce ISO
policies, standards and further carry out Compliance Audits across the organization on periodic basis as
part of IT Governance practice. Was instrumental in aiding AZF IT Department achieve the Integrated
ISO Certification for three consecutive years. In addition, was responsible for carrying out both internal
and external ICT audits and configuration Audits from a Service Management perspective.
From 2014 to 2015, played a key role in the strategic project to establish and implement an Enterprise
Risk Management (ERM) and Business Continuity Management (BCM) framework involving workshops
with various Heads of Departments and senior management at AZF. ERM framework is currently being
used by all departments across the organization and forms the basis for strategic and operational risk
assessment, management and reporting.
Other areas that I have been working on include, formulating the IT Strategy/Road map for AZF duly
approved by Chief Technology officer which was in line with AZF’s 2020 vision and liaising with various
Business Functions, Audit, Marketing, Legal/Strategy team & 3rd party/Vendors on regular basis on IT
compliance issues. Developed and implemented an IT Balanced Scorecard based on COBIT 5.1 and
ensured alignment of the IT performance metrics with the AZF’s Strategic objectives.
From 2012 to 2013, was responsible to design and direct governance activities to ensure compliance
with application and enterprise architecture. Responsibilities included IT strategy setting and ensuring
coordination of strategy implementation amongst business units, risk management, service management
process design and implementation. Also, created and enforced the IT User Policy across AZF and led
continuous improvement initiatives and provided recommendations for problem solving. Developed and
managed the ERP Governance Framework that defined the authority and access matrix, process
workflows, roles and responsibilities across AZF’s strategic Business units.

IT GRC Consultant at Wipro Consulting Services
  • India - Bengaluru
  • January 2010 to August 2012

Led and managed a SOX Compliance project for a leading US based media publishing firm and was responsible for administration of Sarbanes-Oxley standards relating to Information Technology. Established a compliance scoring framework and performed assessment and internal audit and control activities as part of the Sarbanes-Oxley (SOX) compliance program.

Performed System Security Auditing & Assessment (Vulnerability Assessment & Penetration Testing) for one of Middle East’s leading banking firms. The objective of this project was to re-validate the findings identified during the phase one of penetration testing for the banking application and to propose recommendations based on best practices to mitigate the risks attached to the observations or vulnerabilities identified.

Associate Consultant at Wipro Consulting Services
  • India
  • September 2008 to December 2009

Bengaluru, India
Extended all project related IT research and analysis support for clients of Wipro Consulting spread
across multiple practices and geographies. Performed extensive research across various domains in
Information Technology and created important metrics and KPIs for benchmarking.
Contributed actively to thought leadership by authoring Point of Views and research papers on
contemporary topics. Also, engaged in key research assignments for clients across the globe and
worked with cross cultural teams for implementing strategic and consulting engagements.

Senior Software Engineer at Wipro Technologies
  • United Arab Emirates
  • November 2005 to August 2008

Bengaluru, India
Designed, developed, and implemented Microsoft BizTalk based interfaces to implement various
business workflows that would enable comprehensive management of laboratory data for one of Europe's
leading Energy and Utilities Company (Shell).
Facilitated the automation of production information, order management, shipping & receiving, and
invoice & payment functions for the customers, distributors, vendors, etc. and substantially reduced the
company's cost-to-serve and business partners’ cost through the implementation of these interfaces.
Developed and implemented an interactive IPTV Service, for a reputed Telecom company. The project
was implemented using Windows Presentation Foundation (Dot Net Framework 3.0) and was

Education

Bachelor's degree, Information Science
  • at Visvesvaraya Technological University
  • January 2005

information technology

Specialties & Skills

ISO 27001
IT Governance
Compliance
IT Audit
IT Risk
CONSULTING
Governance
Risk management
Compliance
Performance Management
IT Strategy and Governance
Service Management
internal audit

Languages

English
Expert
Arabic
Beginner

Memberships

ISACA
  • ISACA Member
  • February 2018

Training and Certifications

ISO 27001:2013 Lead Auditor (Certificate)
Date Attended:
January 2022
COBIT 4.1 Foundation Certificate (Certificate)
Date Attended:
June 2010
Certified in Risk and Information Systems Control™ (CRISC) (Certificate)
Date Attended:
April 2019
Certified NIA Policy Implementer (Certificate)
Date Attended:
July 2018
ITIL V3 Foundation (Certificate)
Date Attended:
June 2009
ISO 31000 Risk Management Professional (Certificate)
Date Attended:
November 2013
ISO/IEC 20000 Lead Auditor (Certificate)
Date Attended:
December 2015