كلما زادت طلبات التقديم التي ترسلينها، زادت فرصك في الحصول على وظيفة!

إليك لمحة عن معدل نشاط الباحثات عن عمل خلال الشهر الماضي:

عدد الفرص التي تم تصفحها

عدد الطلبات التي تم تقديمها

استمري في التصفح والتقديم لزيادة فرصك في الحصول على وظيفة!

هل تبحثين عن جهات توظيف لها سجل مثبت في دعم وتمكين النساء؟

اضغطي هنا لاكتشاف الفرص المتاحة الآن!
نُقدّر رأيكِ

ندعوكِ للمشاركة في استطلاع مصمّم لمساعدة الباحثين على فهم أفضل الطرق لربط الباحثات عن عمل بالوظائف التي يبحثن عنها.

هل ترغبين في المشاركة؟

في حال تم اختياركِ، سنتواصل معكِ عبر البريد الإلكتروني لتزويدكِ بالتفاصيل والتعليمات الخاصة بالمشاركة.

ستحصلين على مبلغ 7 دولارات مقابل إجابتك على الاستطلاع.


تم إلغاء حظر المستخدم بنجاح
Rishad أشرف, Information Security Lead

Rishad أشرف

Information Security Lead·Confidential

الإمارات العربية المتحدة

ماجستير, Computer Systems Management

الخبرة العملية

مجموع سنوات الخبرة: 16 سنوات, 0 أشهر

Information Security Lead

مارس 2023 - حتى الآن

Confidential

أبو ظبي، الإمارات العربية المتحدة

مارس 2023 - حتى الآن

As the in-house InfoSec Lead, I am responsible for everything InfoSec, as detailed below :
• Responsible for the complete ISO 27001 project and successfully obtained the certification.
• Created policies, standards, guidelines, procedures and plans in-line with the ISO standard.
• Performs the Gap Assessment and Risk Assessment activities.
• Established an Internal Audit Program and findings are reviewed with the InfoSec Steering Committee periodically.
• Responsible for conducting the Security Awareness programs for the employees.
• Complete management of the external SOC.
• Act as the SPOC for all the SOC escalations and ensure that corrective actions are taken promptly.
• Ensure the onboarding of log sources and creation of relevant use cases for SOC.
• Manages the Digital Forensics and Incident Response activities.
• Conduct annual Red Teaming and VAPT projects. Ensure the findings are mitigated in a prompt manner.
• Conduct annual Firewall Audits and ensure the recommendations are implemented accordingly.
• Performs routine Vulnerability Scans and ensure the findings are mitigated promptly.
• Ensure the endpoint management agents are deployed on all the machines, across all OS.
• Responsible for the end-to-end management and administration of the Endpoint Protection (EPP), EDR and DLP solutions.

Projects completed :
• Completed the ISO 27001 certification project successfully.
• Identified gaps in the old EPP, EDR and DLP solutions and got them replaced with robust and advanced solutions that has better features and more visibility on the endpoints.
• Completed the annual Red Teaming and VAPT projects for the past 2 years with clear improvements in the security posture.
• Established a Digital Forensics and Incident Response program with an external vendor.
• Successfully migrated from an old SOC provider to a new one with a much wider scope and coverage.
• Completed annual Firewall Audits for the past 2 years and implemented several improvements.

مجال الشركة:
الخدمات العسكرية
الدور الوظيفي:
تكنولوجيا المعلومات

IT Security Engineer

يونيو 2012 - مارس 2023

Dar Al Handasah

دبي، الإمارات العربية المتحدة

يونيو 2012 - مارس 2023

• Serve as SME for core IT Risk, Compliance, and Assurance with a good understanding of threats, vulnerabilities, risks and possible countermeasures.
• Serve as a primary SPOC for investigating security cases, performing root cause analysis, and offering in-depth solutions.
• Perform Business Impact Analysis within the business domain with an understanding of Confidentiality, Integrity and Availability.
• Contribute to the development and maintenance of ISMS including information security policies, procedures and guidelines based on industry standards such as ISO 27001, ISO 22301, CIS and NIST.
• Act as the primary point of contact within the organization for members of staff, regulators, and any relevant public bodies on issues related to Data Protection & Privacy, in-line with ISO 27001.
• Possess broad knowledge on data protection regulations such GDPR.
• Maintain and update the risk register to ensure the most accurate risk posture is reflected at any given time and conduct regular follow up with risk owners and ensure the closure of the open risks within the agreed timelines.
• Measure and ensure security baseline documents are defined, communicated, and updated covering critical IT assets.
• Attend and support internal and external Information Systems Audit engagements.
• Maintain audit tracker, conduct regular follow up with stake holders and ensure the closure of audit gaps within the agreed timelines. Ensure findings are not repeated in subsequent audits.
• Conduct security program assessments and build roadmaps to improve business’ security posture.
• Monitor and review reports/logs from Microsoft Windows Defender, Antivirus Solution, EDR, Firewalls, IPS, Vulnerability Assessment Tools, SIEM and other sources. Potential security threats are then triaged and mitigated.
• Configure and administer Antivirus solution with EDR to provide whitelisting, device control, web control, malware prevention, anomaly monitoring and real time metrics reporting.

مجال الشركة:
خدمات الاستشارات التجارية
الدور الوظيفي:
تكنولوجيا المعلومات

Technical Consultant

ديسمبر 2011 - مايو 2012

Sutherland Global Services - India

Cochin، الهند

ديسمبر 2011 - مايو 2012

• Analyze, troubleshoot and resolve technical issues for voice, internet or data installation, email clients, VOIP and connection issues for one of the largest Internet Services Provider in United States.
• Deliver service and support to end-users using and operating automated call distribution phone software, via remote connection or over the Internet.
• Accurately process and record transactions using a computer and designated tracking software.

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

Trainee Engineer

يونيو 2010 - نوفمبر 2011

Hash Solutions

Cochin، الهند

يونيو 2010 - نوفمبر 2011

• Assisting with implementing installation projects, maintenance and fault rectifications at customer sites.
• Providing first line technical and applications support to customers and distributors via email, telephone and team viewer sessions.
• Occasional on-site service support and maintenance of the Companys products.
• Assist in the documentation and organization of the internal systems.

مجال الشركة:
خدمات تكنولوجيا المعلومات
الدور الوظيفي:
تكنولوجيا المعلومات

التعليم

Heriot-watt University Dubai

نوفمبر 2018

نوفمبر 2018

ماجستير، Computer Systems Management

الإمارات العربية المتحدة

المعدل التراكمي (نسبة مئوية): 84.61%

المعدل التراكمي (نسبة مئوية): 84.61%

Courses Taken : Software Engineering, Digital and Knowledge Economy, Project Management, Information Systems Methodologies, Databases and Information Systems, Computer Network Security, Big Data Management, Research Methods and Project Planning, Masters Project and Dissertation (Facial Emotion Recognition using Deep Learning)

Skills

CISSP
Expert
CISSP
Expert
CISA
Expert
CISA
Expert
ISO Auditor
Expert
ISO Auditor
Expert
IT Audit
Expert
IT Audit
Expert
IT Security
Expert
IT Security
Expert
Azure
Beginner
Azure
Beginner
GTB DLP
Expert
GTB DLP
Expert
CIS
Intermediate
CIS
Intermediate
ISO 27001
Expert
ISO 27001
Expert
CISA
Expert
CISA
Expert
Gap Assessment
Intermediate
Gap Assessment
Intermediate
ISO 22301
Expert
ISO 22301
Expert
Google Cloud
Beginner
Google Cloud
Beginner
Linux
Beginner
Linux
Beginner
Red teaming
Intermediate
Red teaming
Intermediate
Risk Management
Expert
Risk Management
Expert
Auditing
Intermediate
Auditing
Intermediate
KnowBe4
Expert
KnowBe4
Expert
Endpoint Central
Expert
Endpoint Central
Expert
Splunk
Beginner
Splunk
Beginner
CISSP
Expert
CISSP
Expert
VAPT
Beginner
VAPT
Beginner
Firewall Audit
Beginner
Firewall Audit
Beginner
SOC
Expert
SOC
Expert
Nexpose
Intermediate
Nexpose
Intermediate
Nessus
Intermediate
Nessus
Intermediate
LogRhythm
Intermediate
LogRhythm
Intermediate
Kaspersky Antivirus
Expert
Kaspersky Antivirus
Expert
Attivo Botsink
Beginner
Attivo Botsink
Beginner
Symantec Endpoint Protection
Expert
Symantec Endpoint Protection
Expert
Symantec EDR
Expert
Symantec EDR
Expert
Symantec DLP
Expert
Symantec DLP
Expert
Symantec Encryption
Beginner
Symantec Encryption
Beginner
ESET Enterprise Protect
Expert
ESET Enterprise Protect
Expert
NIST
Beginner
NIST
Beginner
Cisco ESA
Intermediate
Cisco ESA
Intermediate
Libraesva ESG
Beginner
Libraesva ESG
Beginner
Digital Forensics
Beginner
Digital Forensics
Beginner
Incident Response
Intermediate
Incident Response
Intermediate

حسابات مواقع التواصل الاجتماعي

الموقع الشخصي
الموقع الشخصي

لقد تم حذف الرابط بسبب انتهاكه لسياسة الموقع. يرجى التواصل مع قسم الدعم لمزيد من المعلومات.

اللغات

الانجليزية
متمرّس
العربية
مبتدئ
الهندية
متوسط
الملايام
اللغة الأم

التدريب و الشهادات

الشهادات
Certified Information Systems Security Professional (CISSP)
Oct 2022
CCNA (R&S)
Jun 2015 - Jun 2019
Oracle Cloud Infrastructure Certified Associate
Jun 2020 - Jul 2022
Google Cloud Platform : Associate Cloud Engineer
Dec 2019 - Dec 2021
Microsoft Certified : Azure Fundamentals
Sep 2020 - Sep 2022
ISACA Certified Information Systems Auditor (CISA)
Jan 2022 - Jan 2026
Microsoft Certified : Azure Administrator
Sep 2020 - Sep 2022
ISO 27001 Lead Auditor
Feb 2020