سلمان Radhi, Manager, Information Security

سلمان Radhi

Manager, Information Security

Gulf International Bank

البلد
البحرين - المنامة
التعليم
دبلوم, PCI Professional (PCIP)
الخبرات
21 years, 4 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :21 years, 4 أشهر

Manager, Information Security في Gulf International Bank
  • البحرين - المنامة
  • أشغل هذه الوظيفة منذ ديسمبر 2014

Coordinate the PCI DSS review and collect the evidence requirements for PCI DSS
Perform the risk assessment activity for PCI DSS card holder environment
Review and develop security configuration standard for windows 2012 and IIS 8.0
Configure and implement group policy for windows 2012 server (domain member and Domain controller)
Review access on several applications
Develop access matrix for new applications
perform security applications

Cyber Security Consultant في Honeywell
  • المملكة العربية السعودية - الشرقية
  • أشغل هذه الوظيفة منذ ديسمبر 2014
Information Security Manager في Arab Financial Services
  • البحرين - المنامة
  • أشغل هذه الوظيفة منذ أغسطس 2011

• Perform security audits and PCI DSS reviews. This including create and implement compliance reviews:
o Firewall review
o IPS review
o Network components review
o Access control review
o System Configuration review
o Antivirus configuration and logs review
o SIEM review
o Internal vulnerability scan
o Card holder data scan
o Wireless scan
o Incident management review
o Patch management review
• Ensure completeness of risk assessment to the IT related changes and enhancements.
• Coordinate with vendors on information security related assessment.
• Develop and Maintain security standards, policies and reviews.
• Monitor and investigate SIEM logs and alters of system logins, Active directory, CMS, Firewall, IPS and etc.
• Serve as an internal information security consultant.
• Coordination between the security vendors and IT team.
• Cooperation with IT in devising and implementing new solutions and related roadmaps.
• Backup in absence of Head of Department.

Senior Information Security Officer في LMRA, Bahrain
  • البحرين - المنامة
  • أكتوبر 2007 إلى أغسطس 2011

• Assist in forming Information Security Strategic plan and arrange for reviews and updates.
• Develops, implement and manage security standards, baselines, procedures, policies and guidelines for multiple platforms and systems environments.
• Ensures ongoing integration of Information Security and business strategies.
• Perform continues risk assessment and audits to ensure that sites, infrastructure or system are adequately secured.
• Monitor and analyze security events and logs to identify threats or weaknesses.
• Perform security administration tasks on user accounts, data and systems.
• Acquire profound knowledge of current and future Information Security controls, technology, threats and trends. Identify areas of improvement or weakness and assess their impact on LMRA IT environment in form of research and reports.

Security and IT Auditor في KPMG, Bahrian
  • البحرين - المنامة
  • أبريل 2006 إلى سبتمبر 2007

Main duties:
• IT General Controls review
• Data Analysis and Integrity review
• Penetration Test
• Infrastructure security review
• Assist in courses provided by KPMG

Sample of clients performed security and audit activates with:
• APICORP, Saudi Arabia (IT General Control Review)
• BATELCO(Assist in ACL Training, Database review, IT General Control Review, Specific System Review)
• National bank of Bahrain (Raffle draw review using ACL Application)
• Standard Chartered (IT General Controls)
• Bahrain Islamic Bank (IT General Controls)
• Korea Exchange Bank (IT General Controls)
• GFH (System Implementation Review)
• Al Salam Bank (Penetration Test)
• Saudi National Commercial Bank (IT General Control Review)
• Khaleeji Finance House (IT General Control and Network Review)
• Bahrain Stock Exchange (IT General Control and Network Review)
• SICO (It General Control Review)
• ARIG (IT General Control Review)
• Trust Reinsurance (IT General Control Review)
• Solidarity (IT General Controls)

IT Administrator في Arabian Malaysian Takaful EC, Bahrain
  • البحرين - المنامة
  • فبراير 2004 إلى أبريل 2006

Manage all IT activities including
• Domain Management
• Help Desk
• Backup
• Database Management
• Access Control
• Network
• Internet connection

Admin Support في TrustRE
  • البحرين - المنامة
  • يناير 2003 إلى يناير 2004

perform the admin side after policy signed

الخلفية التعليمية

دبلوم, PCI Professional (PCIP)
  • في PCI SSC
  • يونيو 2013
دبلوم, Payment Card Industry-Internal Security Assessor (PCI ISA)
  • في PCI SSC
  • سبتمبر 2012
دبلوم, CPISI - Certified Payment Card Industry Security Implementer
  • في SISA
  • مارس 2012
دبلوم, Network Security
  • في CCNA Security, Cisco Academy, Bahrain
  • مايو 2011
دبلوم, CCNA
  • في Cisco Academy
  • أكتوبر 2010
دبلوم, CISSP
  • في ISC2
  • مايو 2010
دبلوم, ISO 27001:2005 Information Security Management System Implementation
  • في BSI
  • ديسمبر 2008
دبلوم, OfficeScan 8.0 Technical eLearning Course
  • في TrendMicro
  • ديسمبر 2008
دبلوم, Internal Auditor 9001:2000
  • في TUV
  • أغسطس 2008
دبلوم, Certified Ethical Hacker
  • في EC-Council
  • أغسطس 2007
دبلوم, IT Audit Training
  • في KPMG
  • مايو 2006
بكالوريوس, Business Information Systems
  • في University Of Bahrain
  • يونيو 2005

Specialties & Skills

Information Security Management
PCI DSS
IT Audit
risk assessment

اللغات

الانجليزية
متمرّس
العربية
متمرّس

الهوايات

  • karting
    1st place GIB race