Parsa Dargahi, IT Security Competency Compliance Manager

Parsa Dargahi

IT Security Competency Compliance Manager

IBM

Location
Denmark
Education
Master's degree, Electronic Engineer
Experience
28 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :28 years, 4 Months

IT Security Competency Compliance Manager at IBM
  • United Arab Emirates - Dubai
  • My current job since January 2012

Acting as Team leader, lead Senior project manager and Security technical advisory for Enterprise Security projects and activities. Furthermore leading & managing daily operational security and compliance activities for both customers and IBM internally. The role requires close customer relationship, elaboration of executive management reporting, profound team leadership, technical oversight, profound and detail understanding of processes/procedures/policies/standards (ITIL, ISO, PCI-DSS, CIS) and audit/review management.

IT Security Manager at IBM
  • Denmark
  • November 2002 to December 2011

IT Security Manager, Responsible for
- Establishment of IT security services based on ISO standards and market best practices e.g. privileged access process, continued business need, security patch management, user revalidation process, data classification and data/system ownership, disaster recovery/business continuity, identity management, compliance management etc.
- ITIL alignment process management, e.g. security incident management, security risk management, change/problem management
- Audit readiness activities, e.g. self assessment analysis
- Assisting and managing both internal and external audit activities, e.g. scope definition, resource allocation, collection of data etc.
- Project management.
- Security policy elaboration
- Elaboration of security/hardening Implementation appendices for variety of systems, e.g. Unix, Windows, Oracle, SQL, SAP, network devices (wired and wireless) etc.
- Staff education
-T op management reporting
- Customer negotiation upon new services and solutions
- Infrastructure design, e.g. Intrusion Prevention System (IPS), malwares protection (anti virus, spam filtering, URL filtering) etc.
- Managing vulnerability scanning and penetration testing
- Establishing and managing Public Key Infrastructure(PKI)
- Forensic investigation

In this period customer within Transport sector (Maersk Line, P.O.Nedloyd and several airliners, e.g. Lufthansa), Retail and distribution sector (Carlsberg, Danish Supermarket group, Maersk Oil & Gas), government sector (ministry of education and ministry of foreign affairs) and financial institutes have been supported.

Senior IT Security Consultant at Devoteam
  • Denmark
  • February 2001 to November 2002

-Elaboration of corporate policies, strategic plan for management and working procedures and processes
-Assisting in Implementing of datacenters and off-site locations
-Conducting business risk analysis to determine assets value to the companies and deciding the proper countermeasure upon the calculated risk.

In this position, customers within industrial sector (Hempel), government sector (Danish Parliament and Ministry of Internal affairs) and public sector (Danish Broadcasting/TV) have been supported.

Security Consultant/Coordinator at Danish Payment Banking System
  • Denmark
  • January 1998 to February 2001

- Responsible for security administration for decentralized systems
- Responsible for IT Security architecture and infrastructure
- Responsible for logical and physical access
- Responsible for log review and analysis for both logical and physical controls
- Elaboration and implementation of security procedures

In this period all security related bank businesses with both national banking companies and international credit companies (VISA/MasterCard/American Express/Diners) and vendors were supported.

IS/IT Auditor at KPMG
  • Denmark
  • January 1996 to January 1998

- Responsible for auditing access controls for decentralized systems and platforms
- Responsible for auditing network infrastructures
- Responsible for physical environments review and inspection
- Developed Excellence in Sales training course.

As auditor both public and private sectors entities and companies were supported according to audit laws in Denmark.

Education

Master's degree, Electronic Engineer
  • at Danish Technical Unversity
  • July 1994

Specialties & Skills

IT Architecture
Hardening
ISO 27001
Information Security Management
IT Governance
Project Management
Service and Delivery management

Languages

Danish
Expert
English
Expert
Arabic
Beginner

Memberships

ISACA
  • Member
  • August 2005
ISC2
  • Member
  • August 2004

Training and Certifications

Certified Senior Security Specialist (Training)
Training Institute:
IBM
Date Attended:
January 2012
Duration:
160 hours
CISCO PIX Firewall Management (Training)
Training Institute:
CISCO
Date Attended:
March 2002
Duration:
40 hours
Security Leadership Essentials For Managers with Knowledge Compression (Training)
Training Institute:
SANS Insitut
Date Attended:
August 2008
UNIX Security Analysis Course (Training)
Training Institute:
IBM
Date Attended:
June 1997
Duration:
40 hours
Intrusion Analysis Course (Training)
Training Institute:
MIS Training institut
Date Attended:
September 2005
Duration:
40 hours

Hobbies

  • Sport
    I am an active sport freak, playing Badminton, Squash, running, basketball and volleyball are among main activities I actively pursue.