Sumedha Wijeratne, Head of IT Governance & Risk Management

Sumedha Wijeratne

Head of IT Governance & Risk Management

Commercial Bank International

Location
Australia
Education
Master's degree, Management of Technology
Experience
23 years, 10 Months

Share My Profile

Block User


Work Experience

Total years of experience :23 years, 10 Months

Head of IT Governance & Risk Management at Commercial Bank International
  • United Arab Emirates - Dubai
  • My current job since February 2017

Drive the IT Governance, IT Risk Management and IT Compliance agendas through the IT Steering Committee and the Information Security Steering Committee. Establish longer-term strategies/ roadmaps to closely align IT initiatives, projects and activities with business priorities and to enable IT driven business innovation through timely adoption of new technologies and IT capabilities.

Role further involves:
- Establishing, and articulating IT and information security goals and objectives;
- Establishing, formulating, and maintaining IT and information security strategy and roadmap;
- Establish and embed IT and information security governance, frameworks, policies and processes aligned with leading industry practices such as COBIT, ISO27001, ITIL, PMBOK and ISO22301.
- Planning, budgeting and overseeing the implementation of the IT and information security strategy/ roadmap to achieve the set goals/ objectives;
- Providing leadership for successful project/ product delivery;
- Providing leadership and coordinate IT audits and information security reviews/ assessments;
- Providing leadership for legal, regulatory and industry standard compliance: FCA, DPA, PCI-DSS, ISO27001, etc.
- Providing leadership to and establishing processes and practices for transferring knowledge and embedding leading processes and practices.

Head, Group Information Security at Ahli United Bank
  • Bahrain - Manama
  • September 2014 to November 2016

Drive the information security agenda through the Group IT Steering Committee and the Group Operational Risk Committee
Role further involves:
- Articulating security objectives and formulating/ maintaining information security governance and strategy;
- Planning, budgeting and operationalizing the information security strategy/ roadmap;
- Providing leadership for successful project/ product delivery across the group;
- Providing leadership to security monitoring, security reviews/ assessments, Security Operations Centre, brand protection, data leakage prevention and vulnerability management;
- Providing leadership for legal, regulatory and industry standard compliance: FCA, DPA, PCI-DSS, ISO27001, etc.
- Cascading information security awareness at different levels, across departments and across the group.

Formed strong relationships and trust with subsidiary/ JV teams and between departments across multiple levels; becoming a go-to person for getting-things done across the group.

Responsible for IT and information security audit and operational risk coordination; trusted and relied upon for review and assistance in discussing audit observations with internal audit and external auditors.
I have developed the IT Security Function to a higher level of performance and following are key examples demonstrating this:
- Information security contribution recognized leading to doubling both the headcount and annual information security budget for 2016;
- Increased engagement in all IT projects as well as IT initiatives;
- viewed as an ally to help identify suitable risk mitigation strategies as well practical solutions for challenges;
- Recognized to play an advisory role across IT governance and IT service management initiatives;
- Engaged in identifying improvements to IT governance and IT service management practices

Senior Manager, IT Risk & Assurance at Ernst & Young
  • Qatar - Doha
  • July 2011 to March 2014

Headed the Technology and Security Risk Services practice providing IT Consulting, IT Assurance, Information Security and Business Continuity/ Disaster Recovery advisory services.

Manager, Technology Security Risk Services at Ernst & Young
  • Qatar - Doha
  • September 2006 to June 2011

Led the Technology and Security Risk Services practice, providing IT Consulting, IT Assurance, Information Security and Business Continuity/ Disaster Recovery services.

Senior Consultant, Information and Communication Technology Consulting at PwC
  • Sri Lanka - Colombo 2
  • December 1999 to September 2006

Headed the Information & Communication Technology consulting division, providing consulting services on IT Governance, Information Security, Software Development.

Education

Master's degree, Management of Technology
  • at University of Moratuwa
  • September 2006
Bachelor's degree, Electrical, Electronic & Telecommunication Engineering
  • at University of Peradeniya
  • August 1999
Higher diploma, Systems Analysis and Computer System Design
  • at National Institute for Business Management
  • July 1994

Specialties & Skills

IT Risk
IT Security
Cyber Security
IT Governance
Information Security
IT Governance
IT Strategy
Information Security Governance
Information Security Management
Network & Telecommunications
Software Development
IT Audit
Information Security Strategy
System Integration
IT Project Management
Virtualization Technologies
Backup and Archival Systems
Database Administration
Business Continuity Management
Storage Systems and SAN
Server Administration

Languages

English
Expert

Training and Certifications

Certified Ethical Hacker (CEH) (Certificate)
Date Attended:
July 2013
Certified Information Systems Auditor (CISA) (Certificate)
Date Attended:
September 2009
ISO 27001 Lead Implementer (Certificate)
Date Attended:
January 2007
ISO 27001 Lead Auditor (Certificate)
Date Attended:
March 2010
Certified Information Security Manager (CISM) (Certificate)
Date Attended:
April 2007
Certified Information Systems Security Professional (CISSP) (Certificate)
Date Attended:
August 2008

Hobbies

  • Traveling
    Traveled to 1) USA & Alaska 2) United Kingdom - work and holiday 3) France 4) Italy 5) Spain 6) Netherlands 7) Australia 8) Austria 9) Hungary 10) Czech Republic 11) Singapore 12) Malaysia 13) Thailand 14) Vietnam 15) Indonesia 16) Egypt - work and holiday 17) Oman - work 18) Kuwait - work 19) United Arab Emirates - lived and worked 20) Bahrain - lived and worked 21) Qatar - lived and worked
  • Information Security Conferences
    Attended 1. Gartner IT Risk and Cyber Security Conference 2016 2. ISC2 Information Security Conference 2015