Soor Tantawy, IT Security Specialist

Soor Tantawy

IT Security Specialist

Kuwait Finance House

Location
Kuwait - Al Farawaniyah
Education
Bachelor's degree, Bachelor of Commerce, Computer and Information systems Program
Experience
26 years, 11 Months

Share My Profile

Block User


Work Experience

Total years of experience :26 years, 11 Months

IT Security Specialist at Kuwait Finance House
  • Kuwait - Al Kuwait
  • My current job since October 2014

Acting Vulnerability Assessment / Penetration Testing Head - IT Security Specialist
• Managing the IT Security Vulnerability Management including:
 Conducting Security Vulnerability assessment on the bank systems (production and per-production)
 Continue security assessment to identify weaknesses and vulnerabilities within the system and proposing/implementing countermeasures.
 Integration of security tools with build environments to ensure iterative scanning during the Secure-SDLC.
 Conducting security assessment over all changes on the live / production systems
 Conducted penetration testing of the bank systems (web application, O.S and network)
 Consulting on vulnerability remediation on multiple platforms (Windows and Unix)
 Designing of minimum security baseline documents for system
 Designing O.S and application Security hardening Guide (OWASP, NIST, CIS, DISA).
 Providing formal security assessment report for each application / System.
 Patch management.
• Vendor selection exercise for security software and products.
• PCI DSS
• Carried out security incident management, root cause analysis.
• Ensure complaining with the Bank Information Security Policy and Procedure
• Security auditing business applications in the areas of banking and finance which includes online Web application, internet, core banking application and payment gateways etc.
• Developed Application Security testing framework for the organization, consisting of methodology, vulnerability database, test plans and reporting structure.

Team Leader - IT Audit at Kuwait Finance House
  • Kuwait - Al Kuwait
  • January 2013 to October 2014

• Audit planning, fieldwork and reporting for information technology, information security, system and integrated audit engagements; assess business / technology risks and the related controls and then provide practical, value-added remediation plans
• Prepare audit reports that accurately summarize the most significant control weaknesses and resulting impacts to the organization
• Participate in multiple and simultaneous risk-based audits, while maintaining departmental quality standards. Function as part of a team or operate independently as required
• Represent Corporate Audit on company initiatives and special projects
• Understand the organization and develop relationships to provide value-added solutions and best-practices
• Assist in developing and executing annual audit plans focused on the most significant risks in the audit universe
• Verifying of the Bank current IT and security controls line up with the standards and/or Vendor Best Practices based on international standard.
• Verifying of The IT process includes procedures to collect and examine controls which impact the effectiveness and help identify deficiencies in the Information Security Program. Additionally, the examination process includes the ability to archive supporting data, documentation, and evidence that is used to support the conclusions with clear audit trails.
 Trace IT and IT Security Audit process that is help evaluate the effectiveness of and adherence to your organization’s Information Security Policy controls such as; (Virtualization environment, Authentication and Access Controls, Network/Host/Application Security, Physical & Personnel Security, Encryption and Data Security)

IT Security Officer at Boubyan Bank
  • Kuwait
  • January 2012 to December 2012

- Assist in management and mitigation risks related to the bank's information systems and comply with central bank regulations related to information systems.

• Conducting periodic information risk assessments to identify current and future security vulnerabilities, determine level of risk which is acceptable to management and recommend the best ways to reduce information security risks to acceptable level.
• Handling Information Security & IT audits conducted by internal & external entities
• Assist in identifying information systems risks and assist in establishing procedures to mitigate any breach.
• Implement and assist in periodically updating IT security policy.
• Ensure that policies are strictly complied with and enforced across all bank's activities.
• Identify solutions to mitigate information systems risks.
• Provide solutions to information security problems.
• Evaluate, Implement and Manage network security devices (FWSM, Firewall, WEB Proxy, WAF, IPS etc.).
• Prepare periodically security management reports.
• Assist in creating and reviewing systems roles and profiles.
• Manage critical systems and application access control.

Senior IT Security Engineer at Universe Computers Co. - Kuwait Finace House, ISMS Project
  • Kuwait - Al Kuwait
  • March 2008 to December 2011

• Designing and Implementing Enterprise Information Security, including IT Infrastructure Security Monitoring, Web Filtering, End Point Security, Vulnerability Management, Patch Management, etc.
• Conducting periodic information risk assessments to identify current and future security vulnerabilities, determine level of risk which is acceptable to management and recommend the best ways to reduce information security risks to acceptable level.
• Identifying security violations, security risks and vulnerabilities and reporting it to the attention of the Management.
• Coordinate and direct the development, management approval, implementation, and promulgation of objectives, goals, policies, standards, guidelines, and other requirements needed to support technology risk initiatives in the bank.
• Developing Security Incident Management Methodologies based on industry best practices.
• Adopt a security assessment Activity for all new projects
• Recommend security controls which help to elevate the security posture of the systems
• Penetration Test to Evaluate the computer System/Network Security
• SOA Security infrastructure design.
• Incidents and Risk management
• Evaluating new Security Systems/Network/Application Appliances and Software include (Web Application Firewall, IPS, Unified Firewall and Logs coloration and Reporting)
• Perform Security assessment and Hardening Systems/Applications include (Web Server, Application, Unix/Linux Server, Virtualization environment and Microsoft Windows/Exchange/DNSSEC/AD)
• GPO Design and Implement for Enterprise

System and Network Security Engineer at Networkers FZLLC
  • United Arab Emirates
  • July 2006 to December 2007

• Worked in the Doha Asian Games 2006 as Video over IP Engineer "Media Links MD6000"
• Design and implement security solutions for systems / networks
• Implement security baseline, policy and procedures for systems (MS servers 2000/2003 include DNS, DHCP, Active Directory, IIS, IAS, GPO, RRAS and NLB/Cluster - exchange 2000/2003 and MS ISA 2000/2004)
• Provide systems security vulnerability, threat and risk rating Assessment.
• Provide support for Systems and Network
• Design .Configure & maintain CISCO routers, switches, CISCO Firewalls and Juniper NS and SSG.
• LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering.
• Plan design, implement and administer MS-Exchange 2003 email system, windows Active Directory, DNS, DHCP
• Plan, design, implement, support and administer IDPs and VPN

Network supervisor at BOURAK Tours
  • Egypt
  • October 2005 to June 2006

•LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering.

•Managing wireless LINKSYS ADSL router and CISCO switches

•Plan design, implement and administer MS-Exchange 2003 email system, windows Active Directory, DNS, DHCP

•Plan, design, implement, support and administer MS-ISA 2004 and RADIUS.

•Backup and restore servers using VERITAS software V9.0

•Design, prepare and apply LAN/ WAN policies and procedures

•Installing, configuring and managing Trend Micro Office Scan Enterprise Edition, including (Client, Server, Interwall and Mail protection

System & Network Administrator at NewHorizons
  • Qatar
  • December 2002 to August 2005

•LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering using CISCO routers, switches and CISCO PIX Firewall.

•Plan design, implement and administer MS-Exchange email system, domains, and active directory services.

•Plan, design, implement, support and administer MS-ISA, and MS-SQL Server servers.

•Backup / Restore using VERITAS Backup Solution.

•Installing, configuring and managing Trend Micro Office Scan Enterprise Edition, including (Client, Server, Firewall, and Mail Protection).

System & Network Administrator at Condor Tours
  • Egypt - Cairo
  • May 2001 to December 2002

•LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering using CISCO routers and switches.

•Plan design, implement and administer MS-Exchange email system, domains, and active directory services.

•Plan, design, implement, support and administrate MS-ISA, and MS-SQL Server servers.

•Installing, configuring and managing MCafee Enterprise Edition.

•Design and implementing policies.

Maintenance Manager at Trade City Supplies & Trading / Apple User for Computer Systems
  • Egypt
  • January 1999 to May 2001

•Act as lead manager on PCs/ Networking projects overseeing quality assurance, technical support, and customer interface.

•Provide technical expertise to those who need assistance in PCs and networking implementation and maintenance.

•Plan and schedule work orders and the team to specific customer projects.

•Installation, upgrading, networking, application installation, software and hardware configuration.

•Prepare network solution for clients.

Maintenance Manager at Ram For Trading and Computer Systems
  • Egypt
  • March 1997 to December 1998

•Provide technical support for PCs hardware / software, servers and networks.

•Designed, implemented and administered LANs using Windows NT Networking.

•Configured and maintained CISCO routers and switches.

Education

Bachelor's degree, Bachelor of Commerce, Computer and Information systems Program
  • at Ain shams University
  • August 2011

Specialties & Skills

IT Solutions
Security Infrastructure
Information Security Management
Enterprise Risk Management
IT Audit
Servers: MS Exchange ,Forefront TMG, MS-Windows Servers (AD, DHCP, DNS Ect.), MS SQL
O.S Windows MS Office
Unix / Linux
Cisco Technologies ( Routing, Switching, VPN, IPS/IDS)
Ethical Hacking (Backtrack, Metasploit etc.), Web Application Security
Gained sound technical expertise in Security Incident Management
Source fire IPS, Qualys, Juniper SSG / NS
Designing Information Security baseline / guidelines and procedures
Technical forte includes Vulnerability Management, IPS, WAF, Web Application Security
Vulnerability Management and Information Security Audits
ISS Technologies, Symantec Technologies, AV Systems, Websense, Secure Email Gateways, VPN, NAC
Technology Risk & Information Security Management
IT Project Management
Firewalls, SIEM, ISS Technologies, Symantec Technologies, AV Systems, Websense
ISO27001
IT Infrastructure Management

Languages

Arabic
Expert
English
Intermediate

Training and Certifications

Certified Information Security Manager (CISM) (Certificate)
Date Attended:
December 2011
Valid Until:
December 2012
Certified Network Associate (CCNA) (Certificate)
Date Attended:
December 2002
Valid Until:
December 2003
Auditing of Web Application Security (Certificate)
Date Attended:
December 2013
Valid Until:
December 2013
Microsoft Certified Systems Administrator (MCSA) and (MCSA Messaging) (Certificate)
Date Attended:
December 2001
Valid Until:
December 2002
CISCO Secure PIX Firewall Advanced (CSPFA) (Certificate)
Date Attended:
December 2003
Valid Until:
December 2004
CISCO Certified Network Professional (CCNP) (Certificate)
Date Attended:
December 2005
Valid Until:
December 2006
COBIT 5 Foundation (Certificate)
Date Attended:
October 2013
Valid Until:
November 2013
Microsoft Certified Systems Engineer (MCSE) (Certificate)
Date Attended:
December 2001
Valid Until:
December 2002