Tauseef Aslam, CISO

Tauseef Aslam

CISO

United Bank Limited

Lieu
Pakistan - Karachi
Éducation
Master, Computer Science
Expérience
20 years, 1 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :20 years, 1 Mois

CISO à United Bank Limited
  • Pakistan - Karachi
  • Je travaille ici depuis mai 2022

CISO for UBL Pakstan, UAE, Qatar & Bahrain

Cluster Business Security Officer (CISO) à Telenor Asia
  • Pakistan - Islamabad
  • juin 2020 à mai 2022

It was a Security Leadership (Virtual CISO / vCISO) role reporting to Group CISO of Telenor.
1- Security Leadership role for Emerging Asian Business units of Telenor and core member of Telenor Group Security management team.
2- Ensured effective collaboration among security functions of business units to achieve group driven KPI’s.

Business Security Officer (CISO) à Telenor Group
  • Pakistan - Islamabad
  • mars 2019 à mai 2022

(It’s a CISO Role for Telenor Pakistan, COO minus one).
1. Entire portfolio of information security.
2. Governance of physical security and service frauds

General Secretary à Cloud Security Alliance, Pakistan Chapter
  • Pakistan - Islamabad
  • janvier 2016 à janvier 2022

1. Manage communication for the chapter affairs with internal / external stakeholders and the CSA Global.
2. An outstanding member of event management team to organize the chapter events.
3. A subject matter expert for cloud security affairs from CSA Pakistan chapter platform.

Advisor GRC and Security Architecture & Solutions à Telenor Group.
  • Pakistan - Islamabad
  • mars 2013 à mars 2019

(It’s a leadership role with a breadth of expertise in security Governance, Security reviews, Risks and security transformation projects. In this role, I have worked with Telenor as Telco & bank. Refer Appendix-A for projects on Risk, Audit and security transformations.
---> Security compliance Manager (Pentest, Reviews & Audits)
1. Security risk assessment, Audits & reviews of Enterprise and Business partner’s information system during development, acquisition and operations stages.
2. To provide security assurance by conducting risk based IT Audits, reviews and VAPT and applicable security standards.
---> GRC Manager
3. Security risk assessments to identify major risks in projects follow through and facilitate mitigations.
4. Keep management aware of major risk and audit/reviews findings.
5. IS awareness across Telenor Pakistan 3rd party eco system to fortify the overall security posture.
6. Worked on People, process and products to achieve secure operating model and continually evolve security posture.
7. Developed and enforced a vendor security framework to effectively manage security around 3rd party eco system of TP, conduct regular vendor reviews and track risk against vendors.
8. Worked to translate group security strategy in local strategy and conduct technology review against approved strategy.
---> Telenor Asia Security Lead
9. Working as central security lead for all Asian Business Units of Telenor, a core network transformation using private cloud on open stack to ensure defendable security architecture.
10. Leading IT DA project security stream for Asia BU’s in Risk assessment and periodic security reviews of deliverables.
---> Security Architecture Management
11. Worked as Security lead architect to uplift Enterprise IT transformation project to defendable architecture state based on zero trust model, from technology stand point this involve latest IT & security solution from Cisco, F5, HP, MS and VMware etc. This project heavily involved risk assessments, design/Implementation reviews and periodic operational audits.
12. Successfully contributed risk based security control design of multiple technology solutions and business projects.

Head of Information Security/IT (as Assistant Manager) à ZED Group - AEDesign Pvt. ltd. (& a fore star hotel, ZED energy)
  • Pakistan - Lahore
  • décembre 2010 à mars 2013

Assistant Manager, IS/IT http://www.aedesign.com.pk/
(A people manager role, Started as Information security consultant in Dec 2010 and got promotion after 1 year as head of IT & IS).

1. Leading the IT & Information security role and to ensure secure yet smooth continuity of business operation for AEDesign and sister concerns.
o Driven the ISMS ISO 27001 certification project from scratch till Certificate issuance.
o Developed and maintained the Information Security policy in light of ISO 27001 and ensured continued compliance.
o Building IS awareness in a legacy environment to improve overall security posture.
o Conducted security assessments and incorporated risk based approach in transforming IT infrastructure & processes to improve overall security stance of organization.
o Deployment of DLP solution to proactively deter data leakage attempts.

2. Oversee and manage the IT infrastructure to ensure continued availability of IT services.
o Supervised infrastructure up-gradation/optimization to improve CIA.
o Supervised IT services operations, Capacity planning, IT room management and vendor management.

3. Successfully established & supervise the IT service desk to manage the IT incident response with customer oriented approach.
o Minimized IT downtime (below 0.5% including time required to work on users IT services requests) with continuous improvement approach to achieve agreed SLA.
o Established a knowledge management process to avoid rework for already faced problems.
o Removed personal dependencies by successfully delivering an employee’s training program to cross train my team.
o Worked on ITIL to improve IT services.

Assistant Manager IT à Confidential
  • Pakistan - Islamabad
  • janvier 2006 à décembre 2010

Assistant Manager, IT/IS

A people manager role, started as System Admin, later lead IT infrastructure & virtualization team and finally represented the IS function).
Acted as subject matter expert for Information Security policy and oversee its development and maintenance.

Assistant Network Administrator à World Call ( An Omman Telecom Company )
  • Pakistan - Lahore
  • avril 2004 à septembre 2005

• Management and deployment of enterprise network at different office locations.
• Responsible for maintaining different servers on windows/Linux required by enterprise.
• Change management of configuration and upgrades in compliance with ISO 9001.

Liason Officer (Internship) à Livestock & Dairy Development
  • Pakistan - Lahore
  • janvier 2004 à avril 2004

• Automation of Livestock and Dairy Dept, Government of Punjab.
• Negotiate software requirements with all required security requirements for its different parts.

Éducation

Master, Computer Science
  • à University of Engineering & Technology Lahore
  • août 2008

Network and communication Security Wireless communication and security Applied cryptography Distributed system Advanced Software engineering Digital image processing

Baccalauréat, B.Sc. (Hons) in Computer Science
  • à UET Lahore, (University of Engineeing & Technology Lahore)
  • avril 2003

Specialties & Skills

Leadership
Security Architecture Design
IT Audit
Information Security Management
Network Security
Network Security & Administration (CCNA Security & CCNA)
System Administration (MCTS)
IS Audit/Compliance (CISA)
DataCenter Management
ISO 27001 (ISO 27001 Lead Auditor & Lead implementor)
Information Security (CISSP)
Vulnerability Assesment/ Pen testing (CEH)
Web application firewalls (F5 & imperva)
CRISC (RISK)
Defendable Security Architecture
SABSA ( Security Architecture)
CISM (Security Management)
Security Transformation

Profils Sociaux

Site Web Personnel
Site Web Personnel

Le lien a été supprimé pour non-respect des conditions d'utilisation. Veuillez contacter l’équipe d'assistance pour plus d'informations.

Langues

Anglais
Moyen

Adhésions

ISC2, USA
  • Professional Membership
  • February 2009
ISCACA, USA
  • Professional Membership
  • January 2010
Ec-counsil
  • Professional Membership
  • April 2014
Cloud Security Alliance (CSA)
  • General Secretary, CSA PK.
  • February 2016

Formation et Diplômes

Web Application Firewall, BIG-IP F5 (Formation)
Institut de formation:
F5, Red education
Date de la formation:
March 2016
Durée:
28 heures
Web Application Firewall, Imperva Secure Sphere (Formation)
Institut de formation:
Imperva
Date de la formation:
March 2016
Durée:
32 heures
HP ArcSight (Formation)
Institut de formation:
HP
Date de la formation:
August 2015
Durée:
32 heures
ISO 27001 Lead Auditor (Certificat)
Date de la formation:
January 2012
Certified Information Systems Security Professional (CISSP) (Certificat)
Date de la formation:
January 2009
CCNA & CCNA Security (Certificat)
Date de la formation:
January 2009
MCTS ISA & Exchange (Certificat)
Date de la formation:
January 2008
CISA (Certified information System Auditor) (Certificat)
Date de la formation:
January 2010
Ethical hacking and countermeasures Workshop (CEH) (Formation)
Institut de formation:
Riphah University, Islamabad
Date de la formation:
September 2013
Durée:
40 heures

Loisirs

  • internet browsing, reading, spent leisure time with friends.