Salman Radhi, Manager, Information Security

Salman Radhi

Manager, Information Security

Gulf International Bank

Location
Bahrain - Manama
Education
Diploma, PCI Professional (PCIP)
Experience
21 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :21 years, 4 Months

Manager, Information Security at Gulf International Bank
  • Bahrain - Manama
  • My current job since December 2014

Coordinate the PCI DSS review and collect the evidence requirements for PCI DSS
Perform the risk assessment activity for PCI DSS card holder environment
Review and develop security configuration standard for windows 2012 and IIS 8.0
Configure and implement group policy for windows 2012 server (domain member and Domain controller)
Review access on several applications
Develop access matrix for new applications
perform security applications

Cyber Security Consultant at Honeywell
  • Saudi Arabia - Eastern Province
  • My current job since December 2014
Information Security Manager at Arab Financial Services
  • Bahrain - Manama
  • My current job since August 2011

• Perform security audits and PCI DSS reviews. This including create and implement compliance reviews:
o Firewall review
o IPS review
o Network components review
o Access control review
o System Configuration review
o Antivirus configuration and logs review
o SIEM review
o Internal vulnerability scan
o Card holder data scan
o Wireless scan
o Incident management review
o Patch management review
• Ensure completeness of risk assessment to the IT related changes and enhancements.
• Coordinate with vendors on information security related assessment.
• Develop and Maintain security standards, policies and reviews.
• Monitor and investigate SIEM logs and alters of system logins, Active directory, CMS, Firewall, IPS and etc.
• Serve as an internal information security consultant.
• Coordination between the security vendors and IT team.
• Cooperation with IT in devising and implementing new solutions and related roadmaps.
• Backup in absence of Head of Department.

Senior Information Security Officer at LMRA, Bahrain
  • Bahrain - Manama
  • October 2007 to August 2011

• Assist in forming Information Security Strategic plan and arrange for reviews and updates.
• Develops, implement and manage security standards, baselines, procedures, policies and guidelines for multiple platforms and systems environments.
• Ensures ongoing integration of Information Security and business strategies.
• Perform continues risk assessment and audits to ensure that sites, infrastructure or system are adequately secured.
• Monitor and analyze security events and logs to identify threats or weaknesses.
• Perform security administration tasks on user accounts, data and systems.
• Acquire profound knowledge of current and future Information Security controls, technology, threats and trends. Identify areas of improvement or weakness and assess their impact on LMRA IT environment in form of research and reports.

Security and IT Auditor at KPMG, Bahrian
  • Bahrain - Manama
  • April 2006 to September 2007

Main duties:
• IT General Controls review
• Data Analysis and Integrity review
• Penetration Test
• Infrastructure security review
• Assist in courses provided by KPMG

Sample of clients performed security and audit activates with:
• APICORP, Saudi Arabia (IT General Control Review)
• BATELCO(Assist in ACL Training, Database review, IT General Control Review, Specific System Review)
• National bank of Bahrain (Raffle draw review using ACL Application)
• Standard Chartered (IT General Controls)
• Bahrain Islamic Bank (IT General Controls)
• Korea Exchange Bank (IT General Controls)
• GFH (System Implementation Review)
• Al Salam Bank (Penetration Test)
• Saudi National Commercial Bank (IT General Control Review)
• Khaleeji Finance House (IT General Control and Network Review)
• Bahrain Stock Exchange (IT General Control and Network Review)
• SICO (It General Control Review)
• ARIG (IT General Control Review)
• Trust Reinsurance (IT General Control Review)
• Solidarity (IT General Controls)

IT Administrator at Arabian Malaysian Takaful EC, Bahrain
  • Bahrain - Manama
  • February 2004 to April 2006

Manage all IT activities including
• Domain Management
• Help Desk
• Backup
• Database Management
• Access Control
• Network
• Internet connection

Admin Support at TrustRE
  • Bahrain - Manama
  • January 2003 to January 2004

perform the admin side after policy signed

Education

Diploma, PCI Professional (PCIP)
  • at PCI SSC
  • June 2013
Diploma, Payment Card Industry-Internal Security Assessor (PCI ISA)
  • at PCI SSC
  • September 2012
Diploma, CPISI - Certified Payment Card Industry Security Implementer
  • at SISA
  • March 2012
Diploma, Network Security
  • at CCNA Security, Cisco Academy, Bahrain
  • May 2011
Diploma, CCNA
  • at Cisco Academy
  • October 2010
Diploma, CISSP
  • at ISC2
  • May 2010
Diploma, ISO 27001:2005 Information Security Management System Implementation
  • at BSI
  • December 2008
Diploma, OfficeScan 8.0 Technical eLearning Course
  • at TrendMicro
  • December 2008
Diploma, Internal Auditor 9001:2000
  • at TUV
  • August 2008
Diploma, Certified Ethical Hacker
  • at EC-Council
  • August 2007
Diploma, IT Audit Training
  • at KPMG
  • May 2006
Bachelor's degree, Business Information Systems
  • at University Of Bahrain
  • June 2005

Specialties & Skills

Information Security Management
PCI DSS
IT Audit
risk assessment

Languages

English
Expert
Arabic
Expert

Hobbies

  • karting
    1st place GIB race