Zikria محمد, Divisional Head – Technology Compliance

Zikria محمد

Divisional Head – Technology Compliance

Allied Bank Limited

البلد
باكستان
التعليم
دبلوم, Malicious Software and its Underground Economy: Two sides of story
الخبرات
34 years, 7 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :34 years, 7 أشهر

Divisional Head – Technology Compliance في Allied Bank Limited
  • باكستان - لاهور
  • أشغل هذه الوظيفة منذ فبراير 2015

• As Divisional Head - Technology Compliance responsible for developing IS Compliance Program and monitoring the implementation of Information Security strategy, policies based on regulatory requirements and guidelines from ISO27001, ITIL, CoBIT, PCI-DSS.
• Actively take part in development and review of policies and procedures to ensure the regulatory requirements are appropriately covered for effective design of general and application controls within the Bank’s IT Infrastructure.
• Collaborate with Information Security team for managing technology risks and exposures at Bank wide.
• Review Incident reports and root cause analysis reports covers the appropriate remedial/ mitigation actions to address the identified/ related weaknesses.
• Obtain compliance action plans for observations raised in IS and Management Audit reports of SBP/ 3rd Party / Internal audit.
• Monitor and review Vulnerability Assessment reports and obtain compliances of exceptions
• Coordination for BCP document preparation, and BCP exercises as per schedule/ requirements.
• Work closely with the different compliance functions to achieve the goals set by Compliance Group.
• Development of Compliance Risk review checklist of regulatory requirements for technology infrastructure.
• Manage and coordinate the execution of user acceptance test (UAT) to assure functionality developed by technology is in alignment with business requirements.
• Coordinate for extraction of Top100 depositor data by IT for off-site review as per regulatory requirements.
• Review FATCA data for US indicia and forward results for off-site review.

Unit Head – Service Quality Assurance & Compliance في Allied Bank Limited
  • باكستان - لاهور
  • أبريل 2011 إلى يناير 2015

• As Unit Head - Service Quality Assurance & Compliance in Information Security, responsible for developing and implementation of Information Security Program.
• Design, implement and integrate security solutions to address enterprise risks and exposures.
• Develop Information Security policies in coordination with concerned and follow-up with internal IT functions for its implementation.
• Responsible for developing, administering and monitoring the Information governance; IT related standards & compliance.
• Develop IT Security Architecture
• Develop procedures which are necessitated by information security policies, in coordination with respective IT functions.
• Develop and implement IT control self-assessment program.
• Coordinate for external/ 3rd party penetration test.
• Develop and implement vulnerability management plan.
• Coordinate in Technical Risk Assessment
• Log Analysis and its reporting using SIEM tool (ArcSight of HP, )
• Designated PoC for coordination of audit activity by internal auditors/ external auditors/ regulator.
• Designated PoC for coordination of compliance implementation of observations raised in IS/ IT audit reports.
• Monitor Data Centers to verify compliance of required controls
• Act as IT Surveillance team member to monitor the legitimacy of email and internet use as per policy and execute warning alerts to violators.

Head Networks & Communications في Allied Bank Limited
  • باكستان - لاهور
  • ديسمبر 2006 إلى أبريل 2011

• As Head Networks & Communication responsible to Plan, Develop & implement the Telecommunication Connectivity for bank’s all branches, controlling offices and main office locations.
• Coordinate to design and establish bank’s new Data Center for a centralized core banking application with co-existence of legacy application on distributed network.
• Responsible for complete project life cycles, including requirements determination, capacity planning, design, security, implementation, testing, and define post-implementation network support procedures.
• Ensure smooth operations of countrywide LAN/WAN Connectivity through dual links.
• Having the ability to negotiate existing contracts to deliver better price and or service. Managed 3rd party telecoms service providers to ensure service SLA’s are met.
• Designing and coordinating in Call Centers PRI, PABX, IVR, call logging software for telecom helpline, NAC and LAN.
• Budgeting for Projects in line with vision/ strategy/ business needs and bank’s policies.
• Ensure compliances of policies
• Provided server administration to include backups, patching, anti-virus, security, active directory, monitoring, review of logs, change and configuration management, tuning and monitoring
• Managing Audio/Video Local and International Conferences.
• Managed effectively core network services, including firewalls, switches and load balancers.
• To investigated, recommended and implement new server, network, storage, and virtualization and application delivery technologies.

Sr. Manager (IT) Networks في Ibrahim Fibres Limited
  • باكستان
  • مارس 1997 إلى نوفمبر 2006

• Primary responsibility is to manage and develop the IT network operations through out the Group. Give plan, design and support in installation of all server and network systems enterprise wide.
• Provide consultation/ coordination to Allied Bank (having 735 branches network countary wide) ownd by the Group.
• Provide consultation/ coordination to AASML a sister company in ERP deployment project.
• Started as Senior Officer LAN & Communication and promoted to Assistant IT Manager on first years completion. Keeping my outcome in front, management was pleased to promote me as Project Manager after a year and half to meet the upcoming new projects
• Responsible for complete project life cycles, including requirements determination, technical planning, scheduling, design, implementation, testing, and define post-implementation support procedures.
• Served as liaison between company and ABL technical and executive management teams to got old eMail system replaced with Microsoft based platform.
• Decide & define standards for purchase of all required software and hardware to integrate new systems into existing network or for new deployments.
• Served as Project Coordinator and Team Lead for multiple installation, on-site support, and system administrator training.
• Developed and implemented security procedure improvements in several areas and liaised on with vendor in configuration of routers, firewalls and Anti-Virus gateway Appliance.
• Organized managed backup functions for all non-production servers and clients.
• Organize company-wide hardware and software audit. Designed provisions for automatically maintaining audit on quarterly basis.
• Attended many seminars/ workshops and exhibitions at national/ international level.
PROJECTS List can be provided if desired.

Data Center Incharge في Schon Bank Limited
  • باكستان
  • مارس 1996 إلى فبراير 1997

• Primary responsibilities were to manage and develop the IT network operations at the Branch level.
• Provide technical support to all users to ensure the accuracy of Banking transactions, Payroll System and Loan/ Advance System.
• Execute all Applications Processes of PIBAS Banking Software and Transfer compiled data to H/O on daily basis, using PCAnywhere.
• Perform Strat of Day of Branch system to enable daily Banking transactions/ business.
• Run End-of-Day process to compile daily data.
• Take Printouts of required MISs for respective departments to meet the internal audit requirements to keep the branch operation alive with the help of these printed results.
• Served as liaison between IT vendors and Branch’s IT matters/ complaints.
• Decide for purchase of all required accessories and their arrangements.

PC Support Officer في Zainab Textile Mills Limited
  • باكستان
  • أكتوبر 1992 إلى مارس 1996

• Primary responsibility was to provide support of Business Applications on AS/400 systems, Hardware issues support, Data Communication Issues of all inter-networked sites.
• Perform posting process of Applications on AS/400, like, Payroll, Sales, General Ledger and Payables.
• Provide technical support for procurement of new Hardware and Software.
• Maintain Backups of Applications and AS/400 system configuration.
• Configure Communication lines on AS/400 system for WAN/ remote connectivity establishment and do the needful to keep the LAN operation smooth.
• Installation of 5250 emulation adaptors, installation of Microsoft Applications on clients, Group wide.
• Administrate the working of Voice Mail System VM-2000 being in use with SIEMENS Hi-Com 130 and Call logging/ Call Attendant software.
• Provide support at remote locations like: Sale office, Godown and others.
• Performed additional jobs assigned time to time
• Liaison IT vendors as per requirement/ need.
• Developed initial Sale System and Vehicle Insurance System
• Liaison with bandwidth service provider.

Programmer في Sh. Yaqoob & Co.
  • باكستان
  • أكتوبر 1991 إلى أكتوبر 1992

My primary responsibility was to develop Inventory System in D Base III plus to manage their stock. In addition to this I had performed these tasks:
•Prepare accounts in custom made accounting package.
•Prepare all MIS reports (detail/ summary reports) required time to time.

Computer Operator/ Programmer في Al-Noor Hospital (Pvt.) Limited.
  • باكستان
  • أكتوبر 1989 إلى سبتمبر 1991

I was responsible for the installation of software and hardware & development of small application programs as per office requirement in Dbase III plus. Other tasks which undertaken are listed below:
•I had developed an application program for fetal bio-matery calculations.
•Designed & programmed formats of Ultra Sound reports in WinWord for automatic printing after taking certain inputs from the operator.
•Prepared a fully automated presentation /slid show of 3 hours for provincial level conference of Doctors (Ultra Sound Specialists)
•Worked to compile data of research on biopsy and case study to be presented at international conference of orthopedics at Karachi, PAKISTAN.

الخلفية التعليمية

دبلوم, Malicious Software and its Underground Economy: Two sides of story
  • في University of London
  • يوليو 2014
دبلوم, Business Continuity Management System (ISO22301)
  • في SGS Pakistan (Pvt) Limited
  • مارس 2014

BCMS (Business Continuity Management System Auditor/ Lead Auditor Course. Course Number A17494: certified by the International Register of Certified Auditors (IRCA)

دبلوم, ArcSight Enterprise Security Analyzer (AESA)
  • في COMGUARD Dubai
  • مارس 2014
دبلوم, Tracking Criminals through Digital Forensics
  • في Risk Associates
  • مارس 2014
دبلوم, NeXpose Enterprise Implementation
  • في Trillium Information Security Systems - RAPID7
  • مارس 2014
دبلوم, The Leader Integrator
  • في Management Development Center - ABL
  • يوليو 2011
دبلوم, Managing Services Operation
  • في REDC - LUMS
  • أبريل 2010
دبلوم, Planning & Conducting IS Audit
  • في PIM
  • ديسمبر 2004
دبلوم, Domino 6.5
  • في LMKR
  • يوليو 2004
دبلوم, CCSP - CISCO Certified Security Professional
  • في National Engineers Training Services
  • يوليو 2004
دبلوم, Information Security
  • في AIKCS
  • يونيو 2004
دبلوم, Linux Advanced Server 2.1 ASE Operating System
  • في CORVIT
  • سبتمبر 2003
دبلوم, CCNA 2.0
  • في CISCO
  • ديسمبر 2000
دبلوم, MCSE - 2000
  • في Microsoft
  • سبتمبر 2000
ماجستير, Computer Science
  • في Preston University
  • مايو 2000
بكالوريوس, Commerce
  • في Govt. College of Commerce
  • يوليو 1989
الثانوية العامة أو ما يعادلها, Intermediat of Commerce
  • في Govt. Municiple Degree College
  • يونيو 1986
الثانوية العامة أو ما يعادلها, Science
  • في Govt. Technical High School
  • مارس 1984

Specialties & Skills

Data Center
Installation
Management
Science
MS Office 97/ 2000
LAN setup with Structured cabling
Help Desk Support
Dealing with the Vendors
Technical Writer
Multimedia Presentations
Software Development
Business Application Support on IBM AS/400
Hardware Support
Internetworking Project Management
MS Windows NT/ 2000
MS Exchange 5.5/ 2000

اللغات

الأوردو
متوسط
الانجليزية
متوسط

التدريب و الشهادات

Certified Ethical Hacker (CEH)V8 (الشهادة)
تاريخ الدورة:
January 2015
صالحة لغاية:
January 2018
Information Security Management System (ISMS) – IRCA ISO 27001:2005 (الشهادة)
تاريخ الدورة:
January 2014
صالحة لغاية:
January 2017
Business Continuity Management System (BCMS) - IRCA (الشهادة)
تاريخ الدورة:
January 2014
صالحة لغاية:
January 2017
Managing Services Operation (تدريب)
معهد التدريب:
Lahore University of Management Sciences (REDC)
Building High Performance Teams (تدريب)
معهد التدريب:
Management Development Center - ABL
تاريخ الدورة:
April 2012
Information Security and Risk Management in Context (تدريب)
معهد التدريب:
University of Washington
تاريخ الدورة:
April 2014
المدة:
60 ساعة
The Leader Integrator Workshop (تدريب)
معهد التدريب:
Management Development Center - ABL
PCI-DSS (تدريب)
معهد التدريب:
Institue of Bankers Pakistan
Operation’s Excellence (تدريب)
معهد التدريب:
Cybernet and MIT (Joint arrangement)