Tauseef Aslam, CISO

Tauseef Aslam

CISO

United Bank Limited

Location
Pakistan - Karachi
Education
Master's degree, Computer Science
Experience
20 years, 0 Months

Share My Profile

Block User


Work Experience

Total years of experience :20 years, 0 Months

CISO at United Bank Limited
  • Pakistan - Karachi
  • My current job since May 2022

CISO for UBL Pakstan, UAE, Qatar & Bahrain

Cluster Business Security Officer (CISO) at Telenor Asia
  • Pakistan - Islamabad
  • June 2020 to May 2022

It was a Security Leadership (Virtual CISO / vCISO) role reporting to Group CISO of Telenor.
1- Security Leadership role for Emerging Asian Business units of Telenor and core member of Telenor Group Security management team.
2- Ensured effective collaboration among security functions of business units to achieve group driven KPI’s.

Business Security Officer (CISO) at Telenor Group
  • Pakistan - Islamabad
  • March 2019 to May 2022

(It’s a CISO Role for Telenor Pakistan, COO minus one).
1. Entire portfolio of information security.
2. Governance of physical security and service frauds

General Secretary at Cloud Security Alliance, Pakistan Chapter
  • Pakistan - Islamabad
  • January 2016 to January 2022

1. Manage communication for the chapter affairs with internal / external stakeholders and the CSA Global.
2. An outstanding member of event management team to organize the chapter events.
3. A subject matter expert for cloud security affairs from CSA Pakistan chapter platform.

Advisor GRC and Security Architecture & Solutions at Telenor Group.
  • Pakistan - Islamabad
  • March 2013 to March 2019

(It’s a leadership role with a breadth of expertise in security Governance, Security reviews, Risks and security transformation projects. In this role, I have worked with Telenor as Telco & bank. Refer Appendix-A for projects on Risk, Audit and security transformations.
---> Security compliance Manager (Pentest, Reviews & Audits)
1. Security risk assessment, Audits & reviews of Enterprise and Business partner’s information system during development, acquisition and operations stages.
2. To provide security assurance by conducting risk based IT Audits, reviews and VAPT and applicable security standards.
---> GRC Manager
3. Security risk assessments to identify major risks in projects follow through and facilitate mitigations.
4. Keep management aware of major risk and audit/reviews findings.
5. IS awareness across Telenor Pakistan 3rd party eco system to fortify the overall security posture.
6. Worked on People, process and products to achieve secure operating model and continually evolve security posture.
7. Developed and enforced a vendor security framework to effectively manage security around 3rd party eco system of TP, conduct regular vendor reviews and track risk against vendors.
8. Worked to translate group security strategy in local strategy and conduct technology review against approved strategy.
---> Telenor Asia Security Lead
9. Working as central security lead for all Asian Business Units of Telenor, a core network transformation using private cloud on open stack to ensure defendable security architecture.
10. Leading IT DA project security stream for Asia BU’s in Risk assessment and periodic security reviews of deliverables.
---> Security Architecture Management
11. Worked as Security lead architect to uplift Enterprise IT transformation project to defendable architecture state based on zero trust model, from technology stand point this involve latest IT & security solution from Cisco, F5, HP, MS and VMware etc. This project heavily involved risk assessments, design/Implementation reviews and periodic operational audits.
12. Successfully contributed risk based security control design of multiple technology solutions and business projects.

Head of Information Security/IT (as Assistant Manager) at ZED Group - AEDesign Pvt. ltd. (& a fore star hotel, ZED energy)
  • Pakistan - Lahore
  • December 2010 to March 2013

Assistant Manager, IS/IT http://www.aedesign.com.pk/
(A people manager role, Started as Information security consultant in Dec 2010 and got promotion after 1 year as head of IT & IS).

1. Leading the IT & Information security role and to ensure secure yet smooth continuity of business operation for AEDesign and sister concerns.
o Driven the ISMS ISO 27001 certification project from scratch till Certificate issuance.
o Developed and maintained the Information Security policy in light of ISO 27001 and ensured continued compliance.
o Building IS awareness in a legacy environment to improve overall security posture.
o Conducted security assessments and incorporated risk based approach in transforming IT infrastructure & processes to improve overall security stance of organization.
o Deployment of DLP solution to proactively deter data leakage attempts.

2. Oversee and manage the IT infrastructure to ensure continued availability of IT services.
o Supervised infrastructure up-gradation/optimization to improve CIA.
o Supervised IT services operations, Capacity planning, IT room management and vendor management.

3. Successfully established & supervise the IT service desk to manage the IT incident response with customer oriented approach.
o Minimized IT downtime (below 0.5% including time required to work on users IT services requests) with continuous improvement approach to achieve agreed SLA.
o Established a knowledge management process to avoid rework for already faced problems.
o Removed personal dependencies by successfully delivering an employee’s training program to cross train my team.
o Worked on ITIL to improve IT services.

Assistant Manager IT at Confidential
  • Pakistan - Islamabad
  • January 2006 to December 2010

Assistant Manager, IT/IS

A people manager role, started as System Admin, later lead IT infrastructure & virtualization team and finally represented the IS function).
Acted as subject matter expert for Information Security policy and oversee its development and maintenance.

Assistant Network Administrator at World Call ( An Omman Telecom Company )
  • Pakistan - Lahore
  • April 2004 to September 2005

• Management and deployment of enterprise network at different office locations.
• Responsible for maintaining different servers on windows/Linux required by enterprise.
• Change management of configuration and upgrades in compliance with ISO 9001.

Liason Officer (Internship) at Livestock & Dairy Development
  • Pakistan - Lahore
  • January 2004 to April 2004

• Automation of Livestock and Dairy Dept, Government of Punjab.
• Negotiate software requirements with all required security requirements for its different parts.

Education

Master's degree, Computer Science
  • at University of Engineering & Technology Lahore
  • August 2008

Network and communication Security Wireless communication and security Applied cryptography Distributed system Advanced Software engineering Digital image processing

Bachelor's degree, B.Sc. (Hons) in Computer Science
  • at UET Lahore, (University of Engineeing & Technology Lahore)
  • April 2003

Specialties & Skills

Leadership
Security Architecture Design
IT Audit
Information Security Management
Network Security
Network Security & Administration (CCNA Security & CCNA)
System Administration (MCTS)
IS Audit/Compliance (CISA)
DataCenter Management
ISO 27001 (ISO 27001 Lead Auditor & Lead implementor)
Information Security (CISSP)
Vulnerability Assesment/ Pen testing (CEH)
Web application firewalls (F5 & imperva)
CRISC (RISK)
Defendable Security Architecture
SABSA ( Security Architecture)
CISM (Security Management)
Security Transformation

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Intermediate

Memberships

ISC2, USA
  • Professional Membership
  • March 2009
ISCACA, USA
  • Professional Membership
  • January 2010
Ec-counsil
  • Professional Membership
  • April 2014
Cloud Security Alliance (CSA)
  • General Secretary, CSA PK.
  • March 2016

Training and Certifications

Web Application Firewall, BIG-IP F5 (Training)
Training Institute:
F5, Red education
Date Attended:
March 2016
Duration:
28 hours
Web Application Firewall, Imperva Secure Sphere (Training)
Training Institute:
Imperva
Date Attended:
March 2016
Duration:
32 hours
HP ArcSight (Training)
Training Institute:
HP
Date Attended:
August 2015
Duration:
32 hours
ISO 27001 Lead Auditor (Certificate)
Date Attended:
January 2012
Certified Information Systems Security Professional (CISSP) (Certificate)
Date Attended:
January 2009
CCNA & CCNA Security (Certificate)
Date Attended:
January 2009
MCTS ISA & Exchange (Certificate)
Date Attended:
January 2008
CISA (Certified information System Auditor) (Certificate)
Date Attended:
January 2010
Ethical hacking and countermeasures Workshop (CEH) (Training)
Training Institute:
Riphah University, Islamabad
Date Attended:
September 2013
Duration:
40 hours

Hobbies

  • internet browsing, reading, spent leisure time with friends.