Sher Zamin Khan, Senior Security Architect

Sher Zamin Khan

Senior Security Architect

Olayan Saudi Holding Company

Location
Saudi Arabia - Riyadh
Education
Bachelor's degree, Information Technology
Experience
19 years, 7 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 7 Months

Senior Security Architect at Olayan Saudi Holding Company
  • Saudi Arabia - Riyadh
  • My current job since January 2019

• Working as senior security Architect with Olayan group Riyadh responsible for implementation of I.T Security and Cybersecurity measures.
• Supervised Cybersecurity operation and I.T security operation of more than 20 operating companies under OLAYAN group, build new SOC with Rapid 7 SIEM and SOAR solution.
• Managed Cybersecurity and solution delivery projects provided support to business and I.T on projects and initiative that require Cybersecurity involvement.
• Managed and conducted penetration testing and vulnerability scanning according to relevant policies and procedures.
• Performed quarterly vulnerability assessments and presented results to senior management with remediation plans.
• Conduct Periodic compliance reviews against regulatory Information Security requirements, Policies, procedures, and standards.

Senior Security Adminisrator at Olayan Saudi Holding Company
  • Saudi Arabia - Riyadh
  • January 2015 to December 2018

• Managed Cybersecurity operation and I.T security operation of more than 20 operating companies under OLAYAN group.
• Performed administration of security devices Palo alto firewalls, Fortinet firewalls, cisco Firewalls, IDS/IPS, SIEM, EDR, carbon black Application control, Forcepoint proxy, LogRhythm SIEM and cloud security office 365, GCP, Azure.
• Coordinated with external vendors on several projects including product selection, POC deployments, internal/external compliance scans and remediation.
• Performed web security testing on internet facing applications and worked with application teams to fix issues and charged with evaluating new security technologies.
• Collaborate with developers, system/network administrators, and other stakeholders to ensure correct design, development, and implementation of applications and networks.
• Managed log-rhythm SIEM project deployment and performed integration of Security devices, network devices, windows servers, database servers with log-rhythm SIEM Solution.

Senior Security Analyst at Saudi Basic Industries Corporation - Sabic
  • Saudi Arabia - Jubail
  • August 2013 to January 2015

• Worked as Senior cyber security Analyst in SABIC Global SOC (24/7) operation.
• Researched and adopted new technologies to add value to existing offerings
Installed system updates to address vulnerabilities and reduce security issues.
• Investigated SOC intrusion attempts and performed in-depth analysis of exploits, provided effective decision making when to declare security incident.
• Worked with Dell Secure works (managed SOC) team to integrate all SABIC regions including more than 25 operating companies.
• Performed Implementation of Splunk SIEM solution and integrated all servers and network devices logs.

Network Security Engineer at University of Dammam
  • Saudi Arabia - Dammam
  • April 2011 to July 2013

• Worked as Network/Information Security Engineer in University of Dammam was responsible for all information/network security activities including planning, designing and implementation of security measures which safeguard access to university I.T infrastructure components and information Assets.
• Managed network security of university data center and more than 20 colleges.
• Deployed, upgraded, and maintained several security tools and technologies, including anti-malware, Firewalls, EDR, web proxy and SIEM products.
• Selected appropriate intrusion detection system solutions for implementation at facilities

I.T Security Officer at National Defense university
  • Pakistan - Islamabad
  • March 2009 to December 2010

• Worked as Sys Admin/ I.T Security Officer in Well-known Public Sector University managed network security of university campus, Hostels and more than 20 departments.
• Performed Installation, configuration and troubleshooting of Cisco ASA and open-source Firewalls, Configuration of DMZ Security Zones on Cisco ASA, and configuration of Remote access IPSEC VPN.
• Coordination with internal and external security agencies with respect to any security incident.

Network Administrator at Ministry of information technology
  • Pakistan - Islamabad
  • November 2006 to February 2009

• Worked as Network Administrator in Ministry of I.T and Telecommunication, performed Installation, configuration, and troubleshooting of DSL routers, CISCO Catalyst switches, CISCO, and Juniper hardware firewalls.
• Performed day-to-day LAN and WAN administration, maintenance, and support.
• Monitored system performance and responded to alerts.
• Implemented network security measures to minimize data loss.
• Analyzed network traffic and performance metrics to optimize system performance

System/Network Administrator at Aptech Computer Educaton
  • Pakistan - Hyderabad
  • July 2004 to November 2006

• Worked as system/Network Administrator in APTECH, Performed Installation and configuration of windows server 2003 domain controller backup domain controller and child domain in 30 computer Labs each Lab contain 50 computers.
• Installed, configured, and supported local area network (LAN), wide area network (WAN) and Internet system.
• Planned and implemented upgrades to system hardware and software.
• Monitored networks and network devices to resolve technical problems quickly

Education

Bachelor's degree, Information Technology
  • at University Of Sindh
  • January 2004

Bachelor Of computer and information technology(4-year degree)

Specialties & Skills

IT Security
Web Application Security
Information Security
Incident Management
Cyber Security
Cybersecurity operation
Network Security
Incident Response Management
Application Security
Compliance Management
Vulnerability Assessment
Firewall Management
Intrusion Detection
Risk Assessment
Network Security Management
DDoS Prevention

Languages

English
Expert
Urdu
Expert
Arabic
Beginner

Hobbies

  • Cricket