Umair Ahmad, Manager Information Security and Risk

Umair Ahmad

Manager Information Security and Risk

Baker Tilly International

Location
Oman
Education
Master's degree, MS in Information Securi ty
Experience
15 years, 1 Months

Share My Profile

Block User


Work Experience

Total years of experience :15 years, 1 Months

Manager Information Security and Risk at Baker Tilly International
  • Bahrain - Manama
  • My current job since September 2017

• Managing Information Security for multiple companies at a time (as vCISO) i.e. Arcapita, Bahrain Dev Bank, Osool, Albaraka, and Khaleeji Commercial Bank.
• Heading a team of over 50 consultants and secondees, deputed with multiple clients in the Middle East Region.
• Achieved less than 3% failure rate within 8 months for anti-phishing campaigns using a self-designed testing framework.
• Lead and achieved remarkable satisfaction and appreciations for successful and timely closure of several projects as well as maintaining quality service delivery.
• Multiple Digital Transformation projects with different Banks regarding security matters.
• Representing clients for relevant regulatory bodies, boards and auditors.
• Oversee, lead, plan, design and implement the functioning of the cyber security and readiness measures in the client organizations by analyzing the control effectiveness and Key Risk Indicators (KRIs).
• Designing necessary procedures related to cyber security, risk management, accreditation, certification, etc.
• Implementation and Certification of ISMS ISO 27001 in 2 companies (a wealth Management Company and a Government Authority/Ministry).
• Internal and External information security audits for multiple clients.
• Implementation of Cyber Security Framework by Saudi Arabian Monetary Agency in 2 Insurance companies and a bank in KSA.
• Review and development of Information Security Policies and Procedures.
• Create and deliver Information Security Awareness Programs, such as computer-based training courses, lectures, newsletters, and security tips.
• Designed and implemented Incident Management, Business Continuity, Disaster Recovery and Resilience Plans for several organizations.
• Established efficient measures to assess the efficiency of IS frameworks using Key Performance Indicators (KPIs).

Assistant Manager Information Security at Abraj Energy Services Oman
  • Oman - Muscat
  • March 2016 to September 2017

• Enterprise Cyber Security Risk Management.
• Information Security Documentation Framework.
• Formulation of Disaster Recovery Plans.
• Information Security Awareness.

Senior Executive Information Security at Ufone - Etisalat
  • Pakistan - Islamabad
  • July 2013 to March 2016

 Performing risk assessments and testing of data processing systems
 Training staff on network and information security procedures
 Develop Information security strategy/Plan
 Develop an in-depth framework of Information Security Policies, Procedures and guidelines
 Day to day management of enterprise wide information security issues
 Conduct risk assessment and risk mitigation exercise to
 Define policies and procedures and other related ISMS documents
 Conduct regular audits in compliance with all ISMS policies and procedures
 Development of a formalized Business Continuity/Disaster Recovery Plan
 Responsible to keep policies, procedures and guidelines current
 Responsible to maintain central repository of all ISMS documentation
 Ensure Compliance with company policies including all security policies.
 Responsible to present information security incidents to Management
 Remediating audit objections by enforcing policies

GRC Analyst at Trillium Information Security Systems
  • Pakistan - Islamabad
  • September 2011 to July 2013

Trillium Information Security Systems is a Pakistan’s leading security solution provider and vendor that is providing consultancy to a number of multi-national, public and private sector organizations. My job duties as a Governance, Risk and Compliance Analyst (GRC Analyst) were to lead my team for carrying out the following domains:
 Conducting Risk assessment and providing a framework of Risk Management to Certain Organizations
 ISO 27001 Implementation and Audit; Certified one Commercial Bank and a public organization.
 Engagement with technical process owners from respective organizations to understand technical process steps, identify risks, and drive towards a completed documentation that aligns with the IT Governance and Risk Management programs
 Designing Business Continuity Plans for the desired clients
 Designing Disaster Recovery Plans for the desired clients
 Providing Information Security Awareness to certain clients
 Design and conduct proof-of-concept tests to replicate third-party findings and propose solutions to resolve discovered security issues
 Prepare detailed reports on findings and relate findings to real-world risks and provide specific, actionable recommendations for resolution
 Perform research activities to investigate vulnerabilities and technologies which may impact the product suite, and present findings at industry conferences and tradeshows
 Proactively develop threat models to assess how attackers may attack the Information System
 Assess and recommend additional tools and technologies as needed

IT Security Officer at The Bank of Khyber
  • Pakistan - Peshawar
  • February 2010 to September 2011

 Internal Information Security Audits
 Information Security related policies drafting, formulation and implementation
 Configuration and maintenance of network services, equipment and devices
 Member of Information Security Awareness Team in the Bank
 Planning and supporting Security infrastructure
 Analysis of security risks to servers, and workstations
 Management of user accounts, permissions, email, anti-virus, anti-spam

Internee at Habib Rafiq Industries Pvt. Ltd
  • Pakistan - Peshawar
  • May 2009 to August 2009

Networks

Internee at MYSON Engineering Systems (NOKIA)
  • Pakistan - Peshawar
  • June 2008 to August 2008

Internee
Telecommunication

Intern at Acdemics
  • Pakistan
  • June 2007 to August 2007

Research and Development

Education

Master's degree, MS in Information Securi ty
  • at National University of Science and Technology, Islamabad
  • December 2013

18 Years of Education, Vulnerability Assessment, ISMS, Network/Wireless Security, Digital Forensics, Cryptography.

Bachelor's degree, Information Technology
  • at NWFP UET Peshawar
  • September 2009

16 Years of Education

Specialties & Skills

Information Security Management
Penetration Testing
Risk Assessment
Business Continuity
Information Security AUDITS
DISASTER RECOVERY
EMERGENCY RESPONSE
SECURITY INFRASTRUCTURE
VULNERABILITY ASSESSMENT
ISMS Implementation (ISO 27001)
ISMS Implementation (ISO 27001)
Security Policy Design
Business Continuity Planning
Risk Assessment and Management
Information Security Awareness
Policy Documentation
Disaster Recovery Planning
Audit Report writing
Reporting and Compliance

Languages

Urdu
Expert
Arabic
Intermediate
English
Expert

Training and Certifications

SIEM (Certificate)
Date Attended:
April 2012
Valid Until:
April 2012
Workshop on Information Security Tools & Techniques (Certificate)
Date Attended:
October 2011
Valid Until:
October 2011
ISMS Foundations Exam (Certificate)
Date Attended:
May 2013
Valid Until:
May 2013

Hobbies

  • Stamps and Coins Collection
    I have more than 2000 coins and number of stamps of different countries