Orfan Salman, ICT Projects Director / Head of GRC Consulting Practice

Orfan Salman

ICT Projects Director / Head of GRC Consulting Practice

BIRTH Creative Catalysrt

Location
United Arab Emirates
Education
Bachelor's degree, COMPUTER & COMMUNICATION Engineering
Experience
22 years, 3 Months

Share My Profile

Block User


Work Experience

Total years of experience :22 years, 3 Months

ICT Projects Director / Head of GRC Consulting Practice at BIRTH Creative Catalysrt
  • United Arab Emirates - Abu Dhabi
  • My current job since January 2010

 Head of projects & consulting practice including but not limited to Enterprise ICT Infrastructure, Security, Audit, Governance, Digital Business Transformation, Cloud Computing, Process Analysis Design & Re engineering, Development of Web & Online based business solutions.
 Responsible for managing the three main pillars of the practice: people, delivery and sales enablement.
 Design & Build Enterprise Information Security Architecture & Management System.
 Cyber Security Strategy, Risk Management, Threat Identification, Vulnerability Assessment & Monitoring, Intrusions Monitoring/Detection/Prevention, Periodic Security Audits, Response Planning & Incident Management.
 Assess, maintain and develop policies, processes, procedures, internal controls, , compliance and audit for the governance of ICT infrastructure, local/Wide area networks, Business Applications, Physical, Digital & Cyber security, Database systems, SLAs in line with internationally accepted standards.
 International Standards (ISO/IEC 27001, ISO 22301, PCI-DSS, ISO/IEC 20000)
 Technology Industry Frameworks & Best Practices (COBIT, NIST, SANS, ITIL)
 National Industry Standards (NESA, ADSICv2, ISR, DHCC, DIFC)
 UAE Federal Laws & Regulations (3/1987, 3/2003, 1/2006, 5/2012), Dubai Law 23/2006
 Telecommunication (TRA) Specific Regulations
 Accountable for operational/financial metrics and overall business results of the practice.
 Responsible for maintaining and ensuring quality of the practice delivery.
 Lead and orchestrate customer facing consulting practice & digital transformation engagements.
 Build relationship on C level with senior client leaders and key stakeholders
 Develop client business conduct methodologies into the latest technologies enablement and best utilization.
 Identify opportunities where new services and applications can provide benefit to the client’s business or address the client’s existing challenges..
 Design and prepare detailed ICT technical & coomercial proposals in response to requirement/RFP
 Lead client meetings related to proposed solutions at Pre & Post Bid Meetings
 Work with clients throughout proposal development phases:
 Business opportunity identification and assessment
 Requirements & needs
 Feasabile alternatrive options
 Solution design
 Pre-proposal preparation
 Technical proposal development
 Commercial proposal development
 Post-submittal & Contract negotiations
 Managing consulting projects lifecycle (Initiate, Plane, Execute, Monitor & Control, Closure)

Director, Corporate Project Office (CPO) at Emirates Advanced Investments (www.eai.ae)
  • United Arab Emirates
  • September 2007 to December 2009

The Corporate Project Office | PMO is the central area that provides both leadership and hands-on service delivery. This includes providing advice, assistance, monitoring and assurance for EAI program &/ project managers. The Director role is a high-profile position that works to ensure that:
 Projects and programs are operating in alignment with corporately accepted policies, frameworks and methodologies
 Project managers and program offices are supported in meeting corporate project management requirements.
 The project management policy is implemented at appropriate governance structure.
 Project management frameworks and methodologies adapt and evolve in line with ongoing organisational needs

Tasks
 Manage, Advise and mentor EAI project managers and program management.
 Monitor and assure significant EAI projects’ management approach and operation.
 Support projects in meeting their strategic, tactical & operations requirements.
 Be the source of authoritative advice regarding how projects are managed based on corporately accepted policies, frameworks and methodologies
 Support the identification and management of cross-project dependencies.
 Lead three teams within the CPO | PMO:
 The Project Office team, which provides services in areas such as project finance, benefits realisation, documentation requirements, reporting, quality, contracts, cost control, human resources, …etc
 The Program/project management team, which provides direct project support for projects managed within the EAI Corporate Operations Program.
 The business analyst team, which provides feasibility study and analysis for new/current projects and opportunities.

Program Director / Senior ICT Consultant at The Central Agency for Information Technology, Ministry of Planning (www.mop.gov.kw)
  • Kuwait
  • November 2002 to August 2007

 PMO Director of Kuwiat Information Network (KIN) a high speed, flexible, redundant, full-tolerance, secure, expandable, multi-protocol, open-standards digital ICT infrastructure that will provide computer network inter-connection among all governmental institutions and will ease sharing of information resources and flow, exchange, and use of information between these institutions.
 Provide technical consultancy &/ support on: Routers, Switches, Bridges, Ethernet, ATM, Frame Relay, Web-Content switching, Caching, Load-Balancing, DNS, Proxy, Wireless LAN, VoIP, VPN, VLAN, PKI, Sniffers, Firewalls, IDS & Vulnerability Assessment technologies.
 Provide Consultancy on IBM Mainframe, Local area networks, wide area networks, IS security, Internet, Cryptography, and high-end data communication systems, ICT projects …etc to large corporate sectors, ministries and other governmental institutions in Kuwait as part of MOP role and commitments.
 Identify, Design & Implement adequate ICT infrastructure and architecture including LAN, MAN & WAN in the government agencies in the state of kuwait
 Provide Consultancy on Audit Management, Planning and Organization of IS, Technical Infrastructure and Operational Practices, Security & Protection of Information Assets, Disaster Recovery and Business Continuity, Business Application System Development, Acquisition, Implementation and Maintenance & Business Process Evaluation and Risk Management
 Manage & Superintend Enterprise ICT Projects life cycle activities (Initiating, planning, execution, monitoring & control, closing) according to PMI.org book of knowledge.
 Kuwait E-government project consultant.
 Design and implement an Integrated and secured Web-enabled Access to MOP host (IBM Z/800) utilizing IBM Webshpere Host Integration solution, IBM Tivoli Access Manager for E-Business & Tivoli Risk Manager.
 Prepare the RFPs & supervise the building of the E-Government first portal in the state of kuwait (www.egov.gov.kw) in a three tier security architecture model.
 Design a consolidated secure architecture to integrate Minstry of Planning and other governmental bodies Wide Area Networks with remote sites covering the whole state of Kuwait .
 Web-enabling and full implementation of TCP/IP on IBM Z/800 mainframe hosting major state scale applications.
 Explore the technicalities of diverse scenarios & implement the migration of the MOP S/390 SNA private WAN to IP virtual private WAN through service providers with more than 200 remore sites utilizing IPsec 3DES security protocol.
 Studying, Evaluating & Auditing ICT yearly budgets and requirements for ministries and other governmental bodies & institutions in the state of Kuwait.
 Preparing ICT Request For Proposals for LAN, WAN, Portals and PKI at MOP.
 Design and implementation of LANs and WANs at MOP through the four phases of network management life cycle (Analysis & Specification, Design, Implementation & Maintenance)
 Prepare Minstry of Planning-Kuwait report in the International Summit for Information Societies.
 Design and Implement Remote Access Authentication to MOP network through Cisco Secure TACACS AAA server.
 Set the specifications for implementing Public Key Infrastructure solution at MOP.
 Administer, Monitor & Support existing LAN, WAN communication & security equipment (Cisco high-end routers, ISDN Access servers, Web-content Switches, Checkpoint & Cisco PIX Firewalls, Gateways, L3 Switches, IDS, Hubs …..).
 Supporting IBM Mainframe - SNA Communication (S/390): VTAM, Netview, Netview Access, NPM, NCP, JES, OSA and IBM eNetwork Communication Server
 Provide technical support on ATM, Frame Relay, Ethernet, Gigabit Ethernet and IBM Token Ring Networks.
 Designing and Implementing TCP/IP Networks.
 Replacing IBM Front End Processors (FEPs) with High end Routers.
 Exploring and Evaluating new ICT(Networks and Telecommunication) products and technologies.

ICT Senior Consultant at Zajil Telecom / Internet Services Provider
  • Kuwait - Al Kuwait
  • August 2003 to December 2006

 Provide consulting services on developing a coherent competent business strategy.
 Providing consulting services to Teleccom. /Service Providers to Develop:
* Network & Security Managed Services solutions.
* Data Center & Disaster Recovery Business sloutions.
* Professional Services.
* Internet value-added services.
 Provide consulting services during the PDCA cycle of the followings:

ICT Consultant at Kuwait Institute for Scientific Research Kuwai
  • Kuwait - Al Kuwait
  • February 2002 to March 2005

preparation and proposal evaluation & selection.
 ICT Budget Preparation & Auditing.
 E-government Consultant.
 Generic ICT Consulation & Auditing.
 ICT Strategic Planning.
 Data Calssification.
 Information Security Policy Consultation & Development.
 E-enabling KISR Consultant.
 Design & Develop an ICT budget follow up application.

ICT infrastructure Consultant at Kuwait University Center for Information Systems (KUCIS)
  • Kuwait
  • July 2002 to June 2004

 ICT RFPs preparation and proposals evaluation.
 LAN/MAN/WAN & security consultation.
 Techincal Documentation.

Education

Bachelor's degree, COMPUTER & COMMUNICATION Engineering
  • at AMERICAN UNIVERSITY OF BEIRUT, AUB
  • June 1990

Cerificates PMP, CISA, CISSP,CCAI, ISO 27001 LA, ITIL CERTIFIED

Specialties & Skills

ICT Security
IT Audit
IT Infrastructure
ICT Governance
ICT Consulting
ASSETS RECOVERY
BUDGETING
BUSINESS DEVELOPMENT
ICT BUSINESS STRATEGY
CONSULTING
INFORMATION TECHNOLOGY
NETWORKING
ethical hacking of systems and networks
Diagnosing and troubleshooting security related problems
Excellent communication skills in Arabic and English
Penetration testing
IT Risks
IT security
IT best practices, security standards and governing controls
ICT Systems vulnerabilities and exploitation
IS Auditing
compliance
Data & Security Governance
DOD 8570 compliance
Business impact analysis (BIA)
Governance
Digital Transformation
Intrusion prevention and threat intelligence
Security Management & Analysis SIEM
Vulnerability Management
Cyber threats and attacks
Enterprise Solution Architecture
Data Protection, Digital & Cyber Security
Designing & Building Security Operation Center SOC
Business Continuity & Disaster Recovery
operating systems (Linux, Windows)
Train and educate users
Project management
ISO 27001 Complaince

Languages

Arabic
Native Speaker
English
Expert
French
Beginner

Memberships

PMI.org
  • Member
  • September 2006
www.isaca.org/
  • Member
  • July 2005
ISO.org
  • Memeber
  • May 2004
www.isc2.org
  • Member
  • October 2005

Training and Certifications

ISO 27001:2005 Lead Auditor, www.BSI.org (Certificate)
Date Attended:
May 2004
Valid Until:
May 2017
Certified Information Systems Security Professional, CISSP – www.isc2.org (Certificate)
Date Attended:
October 2005
Valid Until:
August 2016
Certified Information Systems Auditor, CISA – www.isaca.org (Certificate)
Date Attended:
July 2005
Valid Until:
July 2017
Project Management Professional, PMP (Certificate)
Date Attended:
September 2006
Valid Until:
September 2017