Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Rishad Ashraf, Information Security Lead

Rishad Ashraf

Information Security Lead·Confidential

United Arab Emirates

Master's degree, Computer Systems Management

Work experience

Total years of experience: 16 years, 0 months

Information Security Lead

March 2023 - Present

Confidential

Abu Dhabi, United Arab Emirates

March 2023 - Present

As the in-house InfoSec Lead, I am responsible for everything InfoSec, as detailed below :
• Responsible for the complete ISO 27001 project and successfully obtained the certification.
• Created policies, standards, guidelines, procedures and plans in-line with the ISO standard.
• Performs the Gap Assessment and Risk Assessment activities.
• Established an Internal Audit Program and findings are reviewed with the InfoSec Steering Committee periodically.
• Responsible for conducting the Security Awareness programs for the employees.
• Complete management of the external SOC.
• Act as the SPOC for all the SOC escalations and ensure that corrective actions are taken promptly.
• Ensure the onboarding of log sources and creation of relevant use cases for SOC.
• Manages the Digital Forensics and Incident Response activities.
• Conduct annual Red Teaming and VAPT projects. Ensure the findings are mitigated in a prompt manner.
• Conduct annual Firewall Audits and ensure the recommendations are implemented accordingly.
• Performs routine Vulnerability Scans and ensure the findings are mitigated promptly.
• Ensure the endpoint management agents are deployed on all the machines, across all OS.
• Responsible for the end-to-end management and administration of the Endpoint Protection (EPP), EDR and DLP solutions.

Projects completed :
• Completed the ISO 27001 certification project successfully.
• Identified gaps in the old EPP, EDR and DLP solutions and got them replaced with robust and advanced solutions that has better features and more visibility on the endpoints.
• Completed the annual Red Teaming and VAPT projects for the past 2 years with clear improvements in the security posture.
• Established a Digital Forensics and Incident Response program with an external vendor.
• Successfully migrated from an old SOC provider to a new one with a much wider scope and coverage.
• Completed annual Firewall Audits for the past 2 years and implemented several improvements.

Company industry:
Military & Defense
Job role:
Information Technology

IT Security Engineer

June 2012 - March 2023

Dar Al Handasah

Dubai, United Arab Emirates

June 2012 - March 2023

• Serve as SME for core IT Risk, Compliance, and Assurance with a good understanding of threats, vulnerabilities, risks and possible countermeasures.
• Serve as a primary SPOC for investigating security cases, performing root cause analysis, and offering in-depth solutions.
• Perform Business Impact Analysis within the business domain with an understanding of Confidentiality, Integrity and Availability.
• Contribute to the development and maintenance of ISMS including information security policies, procedures and guidelines based on industry standards such as ISO 27001, ISO 22301, CIS and NIST.
• Act as the primary point of contact within the organization for members of staff, regulators, and any relevant public bodies on issues related to Data Protection & Privacy, in-line with ISO 27001.
• Possess broad knowledge on data protection regulations such GDPR.
• Maintain and update the risk register to ensure the most accurate risk posture is reflected at any given time and conduct regular follow up with risk owners and ensure the closure of the open risks within the agreed timelines.
• Measure and ensure security baseline documents are defined, communicated, and updated covering critical IT assets.
• Attend and support internal and external Information Systems Audit engagements.
• Maintain audit tracker, conduct regular follow up with stake holders and ensure the closure of audit gaps within the agreed timelines. Ensure findings are not repeated in subsequent audits.
• Conduct security program assessments and build roadmaps to improve business’ security posture.
• Monitor and review reports/logs from Microsoft Windows Defender, Antivirus Solution, EDR, Firewalls, IPS, Vulnerability Assessment Tools, SIEM and other sources. Potential security threats are then triaged and mitigated.
• Configure and administer Antivirus solution with EDR to provide whitelisting, device control, web control, malware prevention, anomaly monitoring and real time metrics reporting.

Company industry:
Business Consultancy Services
Job role:
Information Technology

Technical Consultant

December 2011 - May 2012

Sutherland Global Services - India

Cochin, India

December 2011 - May 2012

• Analyze, troubleshoot and resolve technical issues for voice, internet or data installation, email clients, VOIP and connection issues for one of the largest Internet Services Provider in United States.
• Deliver service and support to end-users using and operating automated call distribution phone software, via remote connection or over the Internet.
• Accurately process and record transactions using a computer and designated tracking software.

Company industry:
IT Services
Job role:
Information Technology

Trainee Engineer

June 2010 - November 2011

Hash Solutions

Cochin, India

June 2010 - November 2011

• Assisting with implementing installation projects, maintenance and fault rectifications at customer sites.
• Providing first line technical and applications support to customers and distributors via email, telephone and team viewer sessions.
• Occasional on-site service support and maintenance of the Companys products.
• Assist in the documentation and organization of the internal systems.

Company industry:
IT Services
Job role:
Information Technology

Education

Heriot-watt University Dubai

November 2018

November 2018

Master's degree, Computer Systems Management

United Arab Emirates

GPA (percentage): 84.61%

GPA (percentage): 84.61%

Courses Taken : Software Engineering, Digital and Knowledge Economy, Project Management, Information Systems Methodologies, Databases and Information Systems, Computer Network Security, Big Data Management, Research Methods and Project Planning, Masters Project and Dissertation (Facial Emotion Recognition using Deep Learning)

Skills

CISSP
Expert
CISSP
Expert
CISA
Expert
CISA
Expert
ISO Auditor
Expert
ISO Auditor
Expert
IT Audit
Expert
IT Audit
Expert
IT Security
Expert
IT Security
Expert
Azure
Beginner
Azure
Beginner
GTB DLP
Expert
GTB DLP
Expert
CIS
Intermediate
CIS
Intermediate
ISO 27001
Expert
ISO 27001
Expert
CISA
Expert
CISA
Expert
Gap Assessment
Intermediate
Gap Assessment
Intermediate
ISO 22301
Expert
ISO 22301
Expert
Google Cloud
Beginner
Google Cloud
Beginner
Linux
Beginner
Linux
Beginner
Red teaming
Intermediate
Red teaming
Intermediate
Risk Management
Expert
Risk Management
Expert
Auditing
Intermediate
Auditing
Intermediate
KnowBe4
Expert
KnowBe4
Expert
Endpoint Central
Expert
Endpoint Central
Expert
Splunk
Beginner
Splunk
Beginner
CISSP
Expert
CISSP
Expert
VAPT
Beginner
VAPT
Beginner
Firewall Audit
Beginner
Firewall Audit
Beginner
SOC
Expert
SOC
Expert
Nexpose
Intermediate
Nexpose
Intermediate
Nessus
Intermediate
Nessus
Intermediate
LogRhythm
Intermediate
LogRhythm
Intermediate
Kaspersky Antivirus
Expert
Kaspersky Antivirus
Expert
Attivo Botsink
Beginner
Attivo Botsink
Beginner
Symantec Endpoint Protection
Expert
Symantec Endpoint Protection
Expert
Symantec EDR
Expert
Symantec EDR
Expert
Symantec DLP
Expert
Symantec DLP
Expert
Symantec Encryption
Beginner
Symantec Encryption
Beginner
ESET Enterprise Protect
Expert
ESET Enterprise Protect
Expert
NIST
Beginner
NIST
Beginner
Cisco ESA
Intermediate
Cisco ESA
Intermediate
Libraesva ESG
Beginner
Libraesva ESG
Beginner
Digital Forensics
Beginner
Digital Forensics
Beginner
Incident Response
Intermediate
Incident Response
Intermediate

Social profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Expert
Arabic
Beginner
Hindi
Intermediate
Malayalam
Native Speaker

Training and Certifications

Certifications
Certified Information Systems Security Professional (CISSP)
Oct 2022
CCNA (R&S)
Jun 2015 - Jun 2019
Oracle Cloud Infrastructure Certified Associate
Jun 2020 - Jul 2022
Google Cloud Platform : Associate Cloud Engineer
Dec 2019 - Dec 2021
Microsoft Certified : Azure Fundamentals
Sep 2020 - Sep 2022
ISACA Certified Information Systems Auditor (CISA)
Jan 2022 - Jan 2026
Microsoft Certified : Azure Administrator
Sep 2020 - Sep 2022
ISO 27001 Lead Auditor
Feb 2020