Soor Tantawy, IT Security Specialist

Soor Tantawy

IT Security Specialist

Kuwait Finance House

Lieu
Koweït - Al Farawaniyah
Éducation
Baccalauréat, Bachelor of Commerce, Computer and Information systems Program
Expérience
26 years, 11 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :26 years, 11 Mois

IT Security Specialist à Kuwait Finance House
  • Koweït - Al Koweït
  • Je travaille ici depuis octobre 2014

Acting Vulnerability Assessment / Penetration Testing Head - IT Security Specialist
• Managing the IT Security Vulnerability Management including:
 Conducting Security Vulnerability assessment on the bank systems (production and per-production)
 Continue security assessment to identify weaknesses and vulnerabilities within the system and proposing/implementing countermeasures.
 Integration of security tools with build environments to ensure iterative scanning during the Secure-SDLC.
 Conducting security assessment over all changes on the live / production systems
 Conducted penetration testing of the bank systems (web application, O.S and network)
 Consulting on vulnerability remediation on multiple platforms (Windows and Unix)
 Designing of minimum security baseline documents for system
 Designing O.S and application Security hardening Guide (OWASP, NIST, CIS, DISA).
 Providing formal security assessment report for each application / System.
 Patch management.
• Vendor selection exercise for security software and products.
• PCI DSS
• Carried out security incident management, root cause analysis.
• Ensure complaining with the Bank Information Security Policy and Procedure
• Security auditing business applications in the areas of banking and finance which includes online Web application, internet, core banking application and payment gateways etc.
• Developed Application Security testing framework for the organization, consisting of methodology, vulnerability database, test plans and reporting structure.

Team Leader - IT Audit à Kuwait Finance House
  • Koweït - Al Koweït
  • janvier 2013 à octobre 2014

• Audit planning, fieldwork and reporting for information technology, information security, system and integrated audit engagements; assess business / technology risks and the related controls and then provide practical, value-added remediation plans
• Prepare audit reports that accurately summarize the most significant control weaknesses and resulting impacts to the organization
• Participate in multiple and simultaneous risk-based audits, while maintaining departmental quality standards. Function as part of a team or operate independently as required
• Represent Corporate Audit on company initiatives and special projects
• Understand the organization and develop relationships to provide value-added solutions and best-practices
• Assist in developing and executing annual audit plans focused on the most significant risks in the audit universe
• Verifying of the Bank current IT and security controls line up with the standards and/or Vendor Best Practices based on international standard.
• Verifying of The IT process includes procedures to collect and examine controls which impact the effectiveness and help identify deficiencies in the Information Security Program. Additionally, the examination process includes the ability to archive supporting data, documentation, and evidence that is used to support the conclusions with clear audit trails.
 Trace IT and IT Security Audit process that is help evaluate the effectiveness of and adherence to your organization’s Information Security Policy controls such as; (Virtualization environment, Authentication and Access Controls, Network/Host/Application Security, Physical & Personnel Security, Encryption and Data Security)

IT Security Officer à Boubyan Bank
  • Koweït
  • janvier 2012 à décembre 2012

- Assist in management and mitigation risks related to the bank's information systems and comply with central bank regulations related to information systems.

• Conducting periodic information risk assessments to identify current and future security vulnerabilities, determine level of risk which is acceptable to management and recommend the best ways to reduce information security risks to acceptable level.
• Handling Information Security & IT audits conducted by internal & external entities
• Assist in identifying information systems risks and assist in establishing procedures to mitigate any breach.
• Implement and assist in periodically updating IT security policy.
• Ensure that policies are strictly complied with and enforced across all bank's activities.
• Identify solutions to mitigate information systems risks.
• Provide solutions to information security problems.
• Evaluate, Implement and Manage network security devices (FWSM, Firewall, WEB Proxy, WAF, IPS etc.).
• Prepare periodically security management reports.
• Assist in creating and reviewing systems roles and profiles.
• Manage critical systems and application access control.

Senior IT Security Engineer à Universe Computers Co. - Kuwait Finace House, ISMS Project
  • Koweït - Al Koweït
  • mars 2008 à décembre 2011

• Designing and Implementing Enterprise Information Security, including IT Infrastructure Security Monitoring, Web Filtering, End Point Security, Vulnerability Management, Patch Management, etc.
• Conducting periodic information risk assessments to identify current and future security vulnerabilities, determine level of risk which is acceptable to management and recommend the best ways to reduce information security risks to acceptable level.
• Identifying security violations, security risks and vulnerabilities and reporting it to the attention of the Management.
• Coordinate and direct the development, management approval, implementation, and promulgation of objectives, goals, policies, standards, guidelines, and other requirements needed to support technology risk initiatives in the bank.
• Developing Security Incident Management Methodologies based on industry best practices.
• Adopt a security assessment Activity for all new projects
• Recommend security controls which help to elevate the security posture of the systems
• Penetration Test to Evaluate the computer System/Network Security
• SOA Security infrastructure design.
• Incidents and Risk management
• Evaluating new Security Systems/Network/Application Appliances and Software include (Web Application Firewall, IPS, Unified Firewall and Logs coloration and Reporting)
• Perform Security assessment and Hardening Systems/Applications include (Web Server, Application, Unix/Linux Server, Virtualization environment and Microsoft Windows/Exchange/DNSSEC/AD)
• GPO Design and Implement for Enterprise

System and Network Security Engineer à Networkers FZLLC
  • Émirats Arabes Unis
  • juillet 2006 à décembre 2007

• Worked in the Doha Asian Games 2006 as Video over IP Engineer "Media Links MD6000"
• Design and implement security solutions for systems / networks
• Implement security baseline, policy and procedures for systems (MS servers 2000/2003 include DNS, DHCP, Active Directory, IIS, IAS, GPO, RRAS and NLB/Cluster - exchange 2000/2003 and MS ISA 2000/2004)
• Provide systems security vulnerability, threat and risk rating Assessment.
• Provide support for Systems and Network
• Design .Configure & maintain CISCO routers, switches, CISCO Firewalls and Juniper NS and SSG.
• LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering.
• Plan design, implement and administer MS-Exchange 2003 email system, windows Active Directory, DNS, DHCP
• Plan, design, implement, support and administer IDPs and VPN

Network supervisor à BOURAK Tours
  • Egypte
  • octobre 2005 à juin 2006

•LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering.

•Managing wireless LINKSYS ADSL router and CISCO switches

•Plan design, implement and administer MS-Exchange 2003 email system, windows Active Directory, DNS, DHCP

•Plan, design, implement, support and administer MS-ISA 2004 and RADIUS.

•Backup and restore servers using VERITAS software V9.0

•Design, prepare and apply LAN/ WAN policies and procedures

•Installing, configuring and managing Trend Micro Office Scan Enterprise Edition, including (Client, Server, Interwall and Mail protection

System & Network Administrator à NewHorizons
  • Qatar
  • décembre 2002 à août 2005

•LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering using CISCO routers, switches and CISCO PIX Firewall.

•Plan design, implement and administer MS-Exchange email system, domains, and active directory services.

•Plan, design, implement, support and administer MS-ISA, and MS-SQL Server servers.

•Backup / Restore using VERITAS Backup Solution.

•Installing, configuring and managing Trend Micro Office Scan Enterprise Edition, including (Client, Server, Firewall, and Mail Protection).

System & Network Administrator à Condor Tours
  • Egypte - Le Caire
  • mai 2001 à décembre 2002

•LAN/ WAN network infrastructure designing, installing, configuring, troubleshooting and administering using CISCO routers and switches.

•Plan design, implement and administer MS-Exchange email system, domains, and active directory services.

•Plan, design, implement, support and administrate MS-ISA, and MS-SQL Server servers.

•Installing, configuring and managing MCafee Enterprise Edition.

•Design and implementing policies.

Maintenance Manager à Trade City Supplies & Trading / Apple User for Computer Systems
  • Egypte
  • janvier 1999 à mai 2001

•Act as lead manager on PCs/ Networking projects overseeing quality assurance, technical support, and customer interface.

•Provide technical expertise to those who need assistance in PCs and networking implementation and maintenance.

•Plan and schedule work orders and the team to specific customer projects.

•Installation, upgrading, networking, application installation, software and hardware configuration.

•Prepare network solution for clients.

Maintenance Manager à Ram For Trading and Computer Systems
  • Egypte
  • mars 1997 à décembre 1998

•Provide technical support for PCs hardware / software, servers and networks.

•Designed, implemented and administered LANs using Windows NT Networking.

•Configured and maintained CISCO routers and switches.

Éducation

Baccalauréat, Bachelor of Commerce, Computer and Information systems Program
  • à Ain shams University
  • août 2011

Specialties & Skills

IT Solutions
Security Infrastructure
Information Security Management
Enterprise Risk Management
IT Audit
Servers: MS Exchange ,Forefront TMG, MS-Windows Servers (AD, DHCP, DNS Ect.), MS SQL
O.S Windows MS Office
Unix / Linux
Cisco Technologies ( Routing, Switching, VPN, IPS/IDS)
Ethical Hacking (Backtrack, Metasploit etc.), Web Application Security
Gained sound technical expertise in Security Incident Management
Source fire IPS, Qualys, Juniper SSG / NS
Designing Information Security baseline / guidelines and procedures
Technical forte includes Vulnerability Management, IPS, WAF, Web Application Security
Vulnerability Management and Information Security Audits
ISS Technologies, Symantec Technologies, AV Systems, Websense, Secure Email Gateways, VPN, NAC
Technology Risk & Information Security Management
IT Project Management
Firewalls, SIEM, ISS Technologies, Symantec Technologies, AV Systems, Websense
ISO27001
IT Infrastructure Management

Langues

Arabe
Expert
Anglais
Moyen

Formation et Diplômes

Certified Information Security Manager (CISM) (Certificat)
Date de la formation:
December 2011
Valide jusqu'à:
December 2012
Certified Network Associate (CCNA) (Certificat)
Date de la formation:
December 2002
Valide jusqu'à:
December 2003
Auditing of Web Application Security (Certificat)
Date de la formation:
December 2013
Valide jusqu'à:
December 2013
Microsoft Certified Systems Administrator (MCSA) and (MCSA Messaging) (Certificat)
Date de la formation:
December 2001
Valide jusqu'à:
December 2002
CISCO Secure PIX Firewall Advanced (CSPFA) (Certificat)
Date de la formation:
December 2003
Valide jusqu'à:
December 2004
CISCO Certified Network Professional (CCNP) (Certificat)
Date de la formation:
December 2005
Valide jusqu'à:
December 2006
COBIT 5 Foundation (Certificat)
Date de la formation:
October 2013
Valide jusqu'à:
November 2013
Microsoft Certified Systems Engineer (MCSE) (Certificat)
Date de la formation:
December 2001
Valide jusqu'à:
December 2002