Sadeem Alolayan, Cyber Security GRC Specialist

Sadeem Alolayan

Cyber Security GRC Specialist

Confidential

Location
Saudi Arabia
Education
Bachelor's degree, Information Technology
Experience
2 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :2 years, 4 Months

Cyber Security GRC Specialist at Confidential
  • Saudi Arabia - Riyadh
  • My current job since July 2022

• Working on SAMA framework to help SMEs to acquire the license to operate.
• Ensures that our clients comply with the regulatory requirements with respect to any changes
or updates in cybersecurity laws in Saudi Arabia.
• Working on BC and DR Plans for our clients.
• Working on developing and implementing ISMS Documents.
• Assist in the identification and evaluation of Cyber Security risks and threats, and work with / guide the relevant stakeholders in mitigating identified risks.
• Applying CSF by SAMA, and collect the evidences.
• Ensure that all corrective actions are performed.
• Lead the information security compliance framework, ensuring client activities, processes, and procedures meet defined requirements, policies, and regulations.
• Develop a cybersecurity awareness program and plan, as well as liaise with respective business units and external vendors.
• Oversee the cybersecurity strategy and ensure achieving the short and long term strategic objectives.
• Monitor the client's information risk profile and risk appetite to achieve an optimal balance between business risk and opportunity.

cyber security intern at stc pay
  • Saudi Arabia - Riyadh
  • May 2021 to September 2021

• Worked on internal/external audit experience.
• Worked on SAMA controls and framework.
• Worked on periodic reviews and update the IT security policies and authorized roles.
• Worked closely with the security awareness, phishing simulation, and training program.

Education

Bachelor's degree, Information Technology
  • at Princess Nourah Bint Abdulrahman University
  • June 2022

With second class honor

Specialties & Skills

Network Security
IT Security
Compliance
Risk Management
Governance
KPI/KRI
Regulatory Compliance
Governance: Information Security Management System (ISMS) development, board communications
Information systems auditing, monitoring, controlling, and assessment process.
Blockchain Security
Cryptography and PKI
Specialized knowledge in developing and implementing cyber security documentation.
Firewall
SAMA - NCA Frameworks
security awareness training
Identity and Access Management
Risk Management

Social Profiles

Languages

Arabic
Native Speaker
English
Expert

Memberships

Saudi Council of Engineers
  • Specialist
  • March 2023

Training and Certifications

ISO 27001 Lead Implementer (Certificate)
Date Attended:
October 2021
Certified Information Systems Security Officer (Certificate)
Date Attended:
January 2024
Security+ (Certificate)
Date Attended:
January 2022

Hobbies

  • swimming
  • Reading
  • Traveling