سراج شمس الدين, Information Security Specialist

سراج شمس الدين

Information Security Specialist

Qatar Islamic Bank

البلد
قطر - الدوحة
التعليم
ماجستير, Master of Business Administration in IT and Systems
الخبرات
15 years, 0 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :15 years, 0 أشهر

Information Security Specialist في Qatar Islamic Bank
  • قطر - الدوحة
  • أشغل هذه الوظيفة منذ نوفمبر 2020

Led the development of on-site and cloud security architecture, ensuring compliance with standards. Monitored digital banking projects for security, privacy, and compliance. Conducted assessments on internal and third-party applications, performed risk assessments, and oversaw annual penetration testing services. Reviewed security architecture, managed Security Impact Assessments, and addressed vulnerability reduction in the software development lifecycle. Provided recommendations for security enhancement, analyzed emerging threats, and coordinated security investigations for information systems and applications.

Information Security Officer في Commercial Bank of Qatar
  • قطر - الدوحة
  • يناير 2017 إلى أكتوبر 2020

Provided crucial support to the CISO in cybersecurity strategy planning, risk assessment, reporting, and control implementation. Initiated tests and conducted risk assessments to ensure the adequacy of security protocols. Maintained information security policies, procedures, and standards. Accountable for the VA and PT program using both internal and vendor resources. Played a key role in gathering threat and vulnerability information, adjusting scanning strategies, and addressing evolving threat landscapes. Led the DLP system, including policy creation, fine-tuning, incident analysis, participation in investigations, and provision of forensic evidence. Contributed to the resolution of security weaknesses and updated information security program policies, procedures, and standards.

Security Analyst في ShiftPoint L.L.C
  • قطر - الدوحة
  • يوليو 2015 إلى سبتمبر 2016

As an Information Security Analyst, I provided hands-on engineering, analysis, and systems integration for the implementation of authentication and authorization, application onboarding, and PKI-related projects. Ensured the proper implementation of Public Key Infrastructure (PKI) and certificate management. Managed information security incidents, creating solution architectures, models, and designs aligned with client operational and security requirements. Responded to user-raised security incidents, addressing phishing attempts, malware outbreaks, and unauthorized access attempts.

Network & Security Administrator في ADE
  • قطر - الدوحة
  • ديسمبر 2007 إلى أبريل 2014

Designed, implemented, and documented new information security architectures, standards, and risk analysis methodologies. Evaluated practices and diagrams for security measures. Developed and delivered organization-wide information security programs. Administered network firewalls, messaging security, and internet proxies. Led security measures for information systems, managed endpoint security projects, and supervised network support. Resolved application security issues, managed antivirus systems, and configured firewall IPS, IDS, content filter, email filter, and network access protocol. Oversaw Group Policy, network and system infrastructure, including servers and Active Directory. Handled system administration, networking, and hardware management. Implemented best practices, ensured prompt issue resolution, and maintained user accounts. Managed IT infrastructure, enhanced network performance, and coordinated firewall, router, switch, DHCP, DNS, and VPN activities. Conducted weekly security reviews and ensured policy compliance. Implemented IT infrastructure consolidation. Liaised with department heads to identify and resolve performance bottlenecks.

الخلفية التعليمية

ماجستير, Master of Business Administration in IT and Systems
  • في ICFAI University Tripura
  • ديسمبر 2021
بكالوريوس, Computer Applications
  • في Mahatma Gandhi University
  • مايو 2007

Computer Application

Specialties & Skills

Network Security
Risk Assessment
Data Loss Prevention
Vulnerability Management
Endpoint Security
Vulnerability Management
Web Application Security
Information Security Architecture
Risk Analysis and Mitigation
Network Security
Cloud Security
Security Governance
Intrusion Detection and Prevention Systems (IDPS)
Security Risk Assessment
Security Patch Management
Threat Intelligence
Security Auditing
Disaster Recovery Planning
Security Metrics and Reporting
Penetration Testing
Business Continuity Planning
Security Consulting
Authentication and Authorization
Identity and Access Management (IAM)
Secure Network Design
Data Classification
Data Encryption
Security Analytics
Secure System Configuration
Defence in Depth
Security Policy Development
Security Incident Response
Vulnerability Assessment
Security Awareness Training
Security Compliance
Cryptography
Firewall Configuration and Managemen
Web Security
Secure Software Development
Endpoint Security
Application Security
Data Protection
Azure Security
Zero Trust - ZTNA
Security Automation

اللغات

الانجليزية
متمرّس

التدريب و الشهادات

ITIL V3 Foundation (الشهادة)
تاريخ الدورة:
February 2010
CompTIA Security+ (الشهادة)
تاريخ الدورة:
March 2010
Certified Ethical Hacker (CEH) (الشهادة)
تاريخ الدورة:
May 2015
Certified Force-Point DLP Administrator (الشهادة)
تاريخ الدورة:
July 2018
Information Systems Security Architecture Professional (CISSP-ISSAP) (الشهادة)
تاريخ الدورة:
May 2023
صالحة لغاية:
June 2026
Certificate of Cloud Security Knowledge (CCSK) (الشهادة)
تاريخ الدورة:
November 2022
Certified Security Blue Team Level 1 (الشهادة)
تاريخ الدورة:
June 2023
Certified Information Systems Security Professional (CISSP) (الشهادة)
تاريخ الدورة:
June 2019
صالحة لغاية:
June 2025

الهوايات

  • Playing Football
    .