HAMAD A.

Chief Information Security Officer at Confidential

Riyadh, Saudi Arabia

About

A bilingual professional with expertise in engineering applications, network and Cybersecurity. Highly proficient in providing creative solutions for technical and business challenges. Experienced in financial & insurance industry. Researcher of network algorithms, artificial intelligence, and Cybersecurity. Ambitious team leader, striving for excellence in innovation and industry mastery.

Experience

  • Chief Information Security Officer at Confidential
    Mar 2021 - Present · 5 yrs 5 mos

  • Saudi Home Loans (2 yrs)
    • COVID-19 Committee Member 2020
      Mar 2020 - Mar 2021 · 1 yr 1 mo

      ▪ Identified Critical business functions to BCM ▪ Defined activities of Critical functions. ▪ Helped Critical functions to receive appropriate resources. ▪ Increased Cyber security Alert level to High. ▪ Made sure of the availability of third parties that will support critical functions ▪ Conducted business impact analysis and risk assessment to identify and measure the risk ▪ Increased Cyber security Business resilience ▪ Developed an awareness Program for Working remotely ▪ Brand Protection monitoring and security.

    • Chief Information Security Officer
      Apr 2019 - Mar 2021 · 2 yrs

      Developing and Maintaining, cyber security strategy, cyber security policy, cyber security architecture; cyber security risk management process. Ensuring that detailed security standards and procedures are established, approved and implemented. Delivering risk-based cyber security solutions that address people, process and technology. Developing the cyber security staff to deliver cyber security solutions in a business context. Monitoring of the cyber security activities (SOC monitoring). Monitoring of compliance with cyber security regulations, policies, standards and procedures. Overseeing the investigation of cyber security incidents. Gathering and analysing threat intelligence from internal and external sources. Performing cyber security reviews. Conducting cyber security risk assessments information assets. Proactively supporting other functions on cyber security. Performing information and system classifications. Determining cyber security requirements for important projects. Defining and conducting the cyber security awareness programs. Defined and conducted training for key role positions and employees depending on their job role. Measuring and Reporting the KRIs and KPIs on: cyber security strategy, cyber security policy compliance, cyber security standards and procedures, cyber security programs (e.g., awareness program, data classification program, key cyber security improvements). Optimised core banking application security. Oracle database encryption. Successfully implemented SAMA framework.

    • Change Management Committee Member
      Apr 2019 - Mar 2021 · 2 yrs

      Defined Cybersecurity Change management process Controlling changes to information asset Assessing the impact of requested changes, classification of changes and the review of changes Developed procedure for emergency changes & fall-back and roll-back procedure

  • Deputy CISO at MAWANI | موانئ
    May 2018 - Apr 2019 · 1 yr

    Protects system by defining access privileges, control structures, and resources. Recognises problems, by identifying abnormalities; reporting violations. Implements security improvements by assessing current situation; evaluating trends; anticipating requirements. Upgrades system by implementing and maintaining security controls. Keeps users informed by preparing performance reports; communicating system status. Maintains quality service by following organisation standards. Maintains technical knowledge by attending educational workshops; reviewing publications. Contributes to team effort by accomplishing related results as needed. Knowledge of Kali linux . Verifying vulnerabilities using Kali linux.

  • Information Technology Security Manager at Solidarity Insurance Company
    Sep 2017 - May 2018 · 9 mos

    plans, designs, builds, implements and maintain new existing information security instructor including web application and network fire walls, Intrusion detection systems, identity management and access control systems, Vulnerability management systems, data Leakage prevention. Anti-malware and all related information security that help protect information assets •Develop and direct implementation of security standards and best practices for the organization •Knowledge of risk assessment tools, technologies and method •Designing secure Network systems and applications architecture. •monitor disaster recover data center daily backup •Contributing to the development and implication of data security policies, procedures, standers, and guidelines. •Recommend security enhancements to IT Management. • strong understanding of endpoint security solutions to include File Integrity monitoring and data loss prevention and data encryption. •Ensure security and audit compliance. •Cybersecurity Polices, Cybersecurity Awareness training. •Ensure that IT security audits are conducted periodically or as needed (e.g., when a security breach occurs)

  • Computer Engineer at Riyadh Municipality
    Jul 2017 - Sep 2017 · 3 mos

    Installing software and hardware, analysing and testing the operating system for hardware and software malfunctions, and ensuring that software applications and networks are working properly. Implementing, maintaining, supporting, developing and, in some cases, designing communication networks within an organisation or between organisations. The goal was to ensure the integrity of high availability network infrastructure to provide maximum performance for the users.