Zikria Muhammad, Divisional Head – Technology Compliance

Zikria Muhammad

Divisional Head – Technology Compliance

Allied Bank Limited

Location
Pakistan
Education
Diploma, Malicious Software and its Underground Economy: Two sides of story
Experience
34 years, 7 Months

Share My Profile

Block User


Work Experience

Total years of experience :34 years, 7 Months

Divisional Head – Technology Compliance at Allied Bank Limited
  • Pakistan - Lahore
  • My current job since February 2015

• As Divisional Head - Technology Compliance responsible for developing IS Compliance Program and monitoring the implementation of Information Security strategy, policies based on regulatory requirements and guidelines from ISO27001, ITIL, CoBIT, PCI-DSS.
• Actively take part in development and review of policies and procedures to ensure the regulatory requirements are appropriately covered for effective design of general and application controls within the Bank’s IT Infrastructure.
• Collaborate with Information Security team for managing technology risks and exposures at Bank wide.
• Review Incident reports and root cause analysis reports covers the appropriate remedial/ mitigation actions to address the identified/ related weaknesses.
• Obtain compliance action plans for observations raised in IS and Management Audit reports of SBP/ 3rd Party / Internal audit.
• Monitor and review Vulnerability Assessment reports and obtain compliances of exceptions
• Coordination for BCP document preparation, and BCP exercises as per schedule/ requirements.
• Work closely with the different compliance functions to achieve the goals set by Compliance Group.
• Development of Compliance Risk review checklist of regulatory requirements for technology infrastructure.
• Manage and coordinate the execution of user acceptance test (UAT) to assure functionality developed by technology is in alignment with business requirements.
• Coordinate for extraction of Top100 depositor data by IT for off-site review as per regulatory requirements.
• Review FATCA data for US indicia and forward results for off-site review.

Unit Head – Service Quality Assurance & Compliance at Allied Bank Limited
  • Pakistan - Lahore
  • April 2011 to January 2015

• As Unit Head - Service Quality Assurance & Compliance in Information Security, responsible for developing and implementation of Information Security Program.
• Design, implement and integrate security solutions to address enterprise risks and exposures.
• Develop Information Security policies in coordination with concerned and follow-up with internal IT functions for its implementation.
• Responsible for developing, administering and monitoring the Information governance; IT related standards & compliance.
• Develop IT Security Architecture
• Develop procedures which are necessitated by information security policies, in coordination with respective IT functions.
• Develop and implement IT control self-assessment program.
• Coordinate for external/ 3rd party penetration test.
• Develop and implement vulnerability management plan.
• Coordinate in Technical Risk Assessment
• Log Analysis and its reporting using SIEM tool (ArcSight of HP, )
• Designated PoC for coordination of audit activity by internal auditors/ external auditors/ regulator.
• Designated PoC for coordination of compliance implementation of observations raised in IS/ IT audit reports.
• Monitor Data Centers to verify compliance of required controls
• Act as IT Surveillance team member to monitor the legitimacy of email and internet use as per policy and execute warning alerts to violators.

Head Networks & Communications at Allied Bank Limited
  • Pakistan - Lahore
  • December 2006 to April 2011

• As Head Networks & Communication responsible to Plan, Develop & implement the Telecommunication Connectivity for bank’s all branches, controlling offices and main office locations.
• Coordinate to design and establish bank’s new Data Center for a centralized core banking application with co-existence of legacy application on distributed network.
• Responsible for complete project life cycles, including requirements determination, capacity planning, design, security, implementation, testing, and define post-implementation network support procedures.
• Ensure smooth operations of countrywide LAN/WAN Connectivity through dual links.
• Having the ability to negotiate existing contracts to deliver better price and or service. Managed 3rd party telecoms service providers to ensure service SLA’s are met.
• Designing and coordinating in Call Centers PRI, PABX, IVR, call logging software for telecom helpline, NAC and LAN.
• Budgeting for Projects in line with vision/ strategy/ business needs and bank’s policies.
• Ensure compliances of policies
• Provided server administration to include backups, patching, anti-virus, security, active directory, monitoring, review of logs, change and configuration management, tuning and monitoring
• Managing Audio/Video Local and International Conferences.
• Managed effectively core network services, including firewalls, switches and load balancers.
• To investigated, recommended and implement new server, network, storage, and virtualization and application delivery technologies.

Sr. Manager (IT) Networks at Ibrahim Fibres Limited
  • Pakistan
  • March 1997 to November 2006

• Primary responsibility is to manage and develop the IT network operations through out the Group. Give plan, design and support in installation of all server and network systems enterprise wide.
• Provide consultation/ coordination to Allied Bank (having 735 branches network countary wide) ownd by the Group.
• Provide consultation/ coordination to AASML a sister company in ERP deployment project.
• Started as Senior Officer LAN & Communication and promoted to Assistant IT Manager on first years completion. Keeping my outcome in front, management was pleased to promote me as Project Manager after a year and half to meet the upcoming new projects
• Responsible for complete project life cycles, including requirements determination, technical planning, scheduling, design, implementation, testing, and define post-implementation support procedures.
• Served as liaison between company and ABL technical and executive management teams to got old eMail system replaced with Microsoft based platform.
• Decide & define standards for purchase of all required software and hardware to integrate new systems into existing network or for new deployments.
• Served as Project Coordinator and Team Lead for multiple installation, on-site support, and system administrator training.
• Developed and implemented security procedure improvements in several areas and liaised on with vendor in configuration of routers, firewalls and Anti-Virus gateway Appliance.
• Organized managed backup functions for all non-production servers and clients.
• Organize company-wide hardware and software audit. Designed provisions for automatically maintaining audit on quarterly basis.
• Attended many seminars/ workshops and exhibitions at national/ international level.
PROJECTS List can be provided if desired.

Data Center Incharge at Schon Bank Limited
  • Pakistan
  • March 1996 to February 1997

• Primary responsibilities were to manage and develop the IT network operations at the Branch level.
• Provide technical support to all users to ensure the accuracy of Banking transactions, Payroll System and Loan/ Advance System.
• Execute all Applications Processes of PIBAS Banking Software and Transfer compiled data to H/O on daily basis, using PCAnywhere.
• Perform Strat of Day of Branch system to enable daily Banking transactions/ business.
• Run End-of-Day process to compile daily data.
• Take Printouts of required MISs for respective departments to meet the internal audit requirements to keep the branch operation alive with the help of these printed results.
• Served as liaison between IT vendors and Branch’s IT matters/ complaints.
• Decide for purchase of all required accessories and their arrangements.

PC Support Officer at Zainab Textile Mills Limited
  • Pakistan
  • October 1992 to March 1996

• Primary responsibility was to provide support of Business Applications on AS/400 systems, Hardware issues support, Data Communication Issues of all inter-networked sites.
• Perform posting process of Applications on AS/400, like, Payroll, Sales, General Ledger and Payables.
• Provide technical support for procurement of new Hardware and Software.
• Maintain Backups of Applications and AS/400 system configuration.
• Configure Communication lines on AS/400 system for WAN/ remote connectivity establishment and do the needful to keep the LAN operation smooth.
• Installation of 5250 emulation adaptors, installation of Microsoft Applications on clients, Group wide.
• Administrate the working of Voice Mail System VM-2000 being in use with SIEMENS Hi-Com 130 and Call logging/ Call Attendant software.
• Provide support at remote locations like: Sale office, Godown and others.
• Performed additional jobs assigned time to time
• Liaison IT vendors as per requirement/ need.
• Developed initial Sale System and Vehicle Insurance System
• Liaison with bandwidth service provider.

Programmer at Sh. Yaqoob & Co.
  • Pakistan
  • October 1991 to October 1992

My primary responsibility was to develop Inventory System in D Base III plus to manage their stock. In addition to this I had performed these tasks:
•Prepare accounts in custom made accounting package.
•Prepare all MIS reports (detail/ summary reports) required time to time.

Computer Operator/ Programmer at Al-Noor Hospital (Pvt.) Limited.
  • Pakistan
  • October 1989 to September 1991

I was responsible for the installation of software and hardware & development of small application programs as per office requirement in Dbase III plus. Other tasks which undertaken are listed below:
•I had developed an application program for fetal bio-matery calculations.
•Designed & programmed formats of Ultra Sound reports in WinWord for automatic printing after taking certain inputs from the operator.
•Prepared a fully automated presentation /slid show of 3 hours for provincial level conference of Doctors (Ultra Sound Specialists)
•Worked to compile data of research on biopsy and case study to be presented at international conference of orthopedics at Karachi, PAKISTAN.

Education

Diploma, Malicious Software and its Underground Economy: Two sides of story
  • at University of London
  • July 2014
Diploma, Business Continuity Management System (ISO22301)
  • at SGS Pakistan (Pvt) Limited
  • March 2014

BCMS (Business Continuity Management System Auditor/ Lead Auditor Course. Course Number A17494: certified by the International Register of Certified Auditors (IRCA)

Diploma, ArcSight Enterprise Security Analyzer (AESA)
  • at COMGUARD Dubai
  • March 2014
Diploma, Tracking Criminals through Digital Forensics
  • at Risk Associates
  • March 2014
Diploma, NeXpose Enterprise Implementation
  • at Trillium Information Security Systems - RAPID7
  • March 2014
Diploma, The Leader Integrator
  • at Management Development Center - ABL
  • July 2011
Diploma, Managing Services Operation
  • at REDC - LUMS
  • April 2010
Diploma, Planning & Conducting IS Audit
  • at PIM
  • December 2004
Diploma, Domino 6.5
  • at LMKR
  • July 2004
Diploma, CCSP - CISCO Certified Security Professional
  • at National Engineers Training Services
  • July 2004
Diploma, Information Security
  • at AIKCS
  • June 2004
Diploma, Linux Advanced Server 2.1 ASE Operating System
  • at CORVIT
  • September 2003
Diploma, CCNA 2.0
  • at CISCO
  • December 2000
Diploma, MCSE - 2000
  • at Microsoft
  • September 2000
Master's degree, Computer Science
  • at Preston University
  • May 2000
Bachelor's degree, Commerce
  • at Govt. College of Commerce
  • July 1989
High school or equivalent, Intermediat of Commerce
  • at Govt. Municiple Degree College
  • June 1986
High school or equivalent, Science
  • at Govt. Technical High School
  • March 1984

Specialties & Skills

Data Center
Installation
Management
Science
MS Office 97/ 2000
LAN setup with Structured cabling
Help Desk Support
Dealing with the Vendors
Technical Writer
Multimedia Presentations
Software Development
Business Application Support on IBM AS/400
Hardware Support
Internetworking Project Management
MS Windows NT/ 2000
MS Exchange 5.5/ 2000

Languages

Urdu
Intermediate
English
Intermediate

Training and Certifications

Certified Ethical Hacker (CEH)V8 (Certificate)
Date Attended:
January 2015
Valid Until:
January 2018
Information Security Management System (ISMS) – IRCA ISO 27001:2005 (Certificate)
Date Attended:
January 2014
Valid Until:
January 2017
Business Continuity Management System (BCMS) - IRCA (Certificate)
Date Attended:
January 2014
Valid Until:
January 2017
Managing Services Operation (Training)
Training Institute:
Lahore University of Management Sciences (REDC)
Building High Performance Teams (Training)
Training Institute:
Management Development Center - ABL
Date Attended:
April 2012
Information Security and Risk Management in Context (Training)
Training Institute:
University of Washington
Date Attended:
April 2014
Duration:
60 hours
The Leader Integrator Workshop (Training)
Training Institute:
Management Development Center - ABL
PCI-DSS (Training)
Training Institute:
Institue of Bankers Pakistan
Operation’s Excellence (Training)
Training Institute:
Cybernet and MIT (Joint arrangement)