Pakistan
Having keen interest and experience in the field of IT governance (Implementation & Audit), Information Security, Risk Management and Project Management. Also, having experience and impulse for IT services and infrastructure assessment, IT strategy planning, IT support & monitoring, Business Continuity & Disaster Recovery.
Identification of gaps in Information Security Policies, procedures, and guidelines (ISO 27001:2013) Reviewing Information Security Policies, procedures, and guidelines related to cloud security Reviewing and monitoring compliance with the policy statements and contributing to Internal Audit and IT Governance ISMS Internal and external audit liaison as an IT Security and Management representative Assist in Information Security Awareness Program in line with ISO 27001 Monitoring of networks / systems for security & risk assessments (Technology Risk Assessment) Supervision of SOC day to day activities, events and incidents (HOTO, process flows, ticket managements, playbooks w.r.t use cases and tools, rotation plans) Review use cases pertaining to Cloud-based tools, Malware Protection, Privilege Access Management, VPN Monitoring, Threat Intelligence, End-point Detection and response, Vulnerability Management etc. Assisting in cyber security dashboards and case briefings Assisting in risk assessment activity for cloud-based applications and infrastructure Review and improve ISMS mandatory documents including RBAC, risk register, asset register etc. Investigate security breaches including forensics and mitigation with Incident Response team Reviewing security incidents and, where appropriate, recommending strategic improvements to address any root causes Conduct training and knowledge transfer sessions for SOC Team Assist in fixing detected vulnerabilities to maintain a high-security standard (TVM, Change Management) Safeguard information system assets by identifying, solving potential and actual security problems Assist to recommend Information Security Review of projects being presented in Project Approval Board Identifying significant trends and changes to information security risks and, where appropriate, proposing changes to the controls framework and/or policies for example by major strategic initiatives to enhance information security
• Assist in the implementation of IT policies, procedures and guidelines (ISO 27001:2013) • Info. Sec. policy creation, review, update, awareness and monitoring • Assist in performing IT Security Governance activities, IT process analysis and improvement, IT governance reporting • Internal and external audit liaison (Management letters, audit findings) • Administration of key IT processes: E.g. change management, incident management etc. • Servicing and providing secretarial services to designated IT governance forums • IT risk management: Main risk management responsibility is to identify improvements and breakdowns in IT governance elements with significant business impact and feed into IT risk management function which includes maintaining the IT departmental risk register. • Support the Project Management Office with producing regular reports and updates • Create operating instructions, system/business process flow manuals, Design Specifications (SDS), System Requirement Specifications (SRS), Project Reports, pages to help technical support staff, consumers, and other users within a company • Assisting with business case, requirements management and communication • Recommendations to improve documented policies, processes and procedures • Identifying and addressing user education/awareness needs • Assist in internal communications for IT
• Client interaction, gaining understanding of organization's business process, documenting and reporting audit work. • Use and understanding of computer aided audit tools (CAATs) i.e. EMS (Engagement management system) & Pentana • Evaluating and testing automated controls • Performing technical reviews of database and operating systems • Performing technical reviews of ERPs and Network Infrastructure Assessment of IT Governance procedures and policies
http://www.ted.com/profiles/6592872