Riyadh, Saudi Arabia
At Elm Company, I develop robust cybersecurity strategies and ensure regulatory compliance. With the GIAC Security Leadership certification, I've spearheaded initiatives that align with the latest NCA guidelines and address emerging threats. As a GRC Senior Manager, I have proactively formulated policies, assessed IT controls, and established robust cybersecurity measures. Standards. Collaborating with auditors and cross-functional teams has validated our security measures. As a hands-on leader, I am committed to continuous improvement and leading our organization through the evolving landscape of cybersecurity governance, risk, and compliance.
- Managing and leading the Cybersecurity GRC toward a business enabler function. - Support executive management with decision-making by reporting a well-designed risk identification and reporting structure. - Cybersecurity Governance and Strategy: Develop and oversee the implementation of cybersecurity governance frameworks, policies, and standards to align with organizational and regulatory requirements. - Risk and Third-Party Management: Lead risk assessment processes, identify potential cybersecurity risks, and collaborate with cross-functional teams to implement risk mitigation strategies. Oversee third-party risk management activities, including vendor assessments, due diligence, and monitoring. - Compliance Oversight: Ensure compliance with cybersecurity regulations, frameworks, and standards, including regular assessments and audits to maintain adherence. - Stakeholder Engagement & Reporting: Regularly communicate cybersecurity risk status and compliance metrics to senior management and relevant stakeholders, providing insights and recommendations.
- Managing and leading the Cybersecurity GRC toward a business enabler function. - Support executive management with decision-making by reporting a well-designed risk identification and reporting structure. - Conducting various qualitative asset-based risk assessments, maintaining an up-to-date information security risk register, and overseeing the implementation of identified mitigation plans with relative stakeholders. - Perform various cybersecurity awareness activities throughout the organization (incl. Roles and responsibilities, job-related threats, incident management, policies, violations, risks, compliance, etc.) - Developing and implementing Cybersecurity Strategy, Policies, Procedures, and Standards. - Ensuring compliance with regulatory requirements such as NCA and Staying up-to-date with regulatory changes, emerging threats, and industry trends related to cybersecurity GRC. - Collaborating with internal and external auditors to ensure the organization's efforts are adequately assessed and validated.
• Perform daily security analysis, scanning, and assessment for information security risks, threats and vulnerabilities. • Responsible for all communications and Requests between Elm and NCA. • Work and coordinate with all internal departments to comply to NCA requirements through their tools. • Security monitoring of all Elm networks for internal and external threat attacks and taking appropriate action to mitigate those attacks. • Using (SIEM) System to monitor and follow up all related security incidents, cases and events.
• Serves as a trusted advisor to the Partner, and create a mutually beneficial plan for the future. • Drives end-to end HPE revenue, profitability, and pipeline by creating JBP and leading data-driven sales efforts with the Partner. • Responsible for partners technical consulting in selling and supporting company products, services and systems, or software. • Coordinates and executes HPE activities with the Partner to drive HPE marketing strategy to the customer. • Identifies probable competition and product roll-out data/training needs and evaluates relative company strengths. • Identifies the growth path and scalability options of a solution and includes these in design activities.
• Security monitoring of all Elm networks for internal and external threat attacks and taking appropriate action to mitigate those attacks. • Using (SIEM) System to monitor and follow up all related security incidents, cases and events.
o Manage and Administrate the following: • WLAN (Aruba) • Network Access Control (ClearPass) • Internet Proxy (BlueCoat) • LAN/WAN Firewalls (Palo Alto) (Juniper) • LAN Services “DNS and DHCP” (Infoblox) o ITNS Second/Third Level of Support
Talking to clients to get details of faults.. Working out the reasons for a fault and explaining these to the client.. Fixing equipment, including printers and scanners.. Setting up new equipment and upgrading existing systems.. Training clients on new systems or software applications..