Muhammad Farrukh Zamir

Head of Information Security & ADC Investigation Unit

Karachi Division, Sindh, Pakistan

About

Introducing a seasoned cybersecurity professional with over a decade of expertise, currently serving as the Head of Information Security & ADC Investigation Unit at NBP Funds. In my previous role as Head of IS & Compliance at DataCheck Limited, I amassed extensive experience in compliance management and ISO 27001 compliance. With a robust portfolio of certifications, including CISM, CEH, CC, LPI, and NSE, along with comprehensive training such as CISSP, I have cultivated proficiency across a wide spectrum of security tools. From HP ArcSight ESM to Tenable Nessus, I have demonstrated competence in platforms like McAfee DLP, Cloudflare, and Sophos MDM, among others. Throughout my career, I have spearheaded numerous successful projects, security reviews, and compliance audits. Additionally, I've overseen company-wide security training initiatives, managed IS budgeting, and implemented robust security protocols to mitigate risks and enhance data protection. In summary, I am a highly motivated and dedicated professional known for delivering exceptional results. For further discussion or inquiries, please feel free to contact me at [email protected]

Experience

  • NBP Funds (2 yrs 8 mos)
    • Head of Information Security & ADC Investigations Unit
      Jul 2025 - Present · 1 yr 1 mo

    • VP- Information Security & ADC Investigation Unit
      Dec 2023 - Sep 2025 · 1 yr 10 mos

      • Plans, develops, implements, and manages a strategic enterprise information security and risk management program to ensure the integrity, confidentiality, and availability of information owned, controlled, or processed by the organization. • Identifies and supports security initiatives and establishes governance and Business continuity programs. • Plans, develops, and manages data, systems, and network security policies, standards, procedures, BIA, processes, and guidelines throughout NBP Funds related to information access, security, privacy, compliance and disaster recovery, inclusive of all media formats. • Assists appropriate teams in ongoing management, review, audit, and enforcement, including firewall configuration audits, log analysis, and gap remediation. • Ensures compliance with statutory and regulatory requirements pertaining to information access, security, and privacy for NBP Funds, and its affiliate organizations as requested or necessary. • Supervises, measures, and monitors potential information security exposures, violations of information security policies and procedures, and breaches of information security measures, and reports all significant discoveries to the Deputy Executive Officer, Enterprise Information Management in a timely fashion. • Partners with business and IT leaders on risk and control areas, such as regulatory, external audit and risk management processing, including conducting periodic risk assessments. • Collaborates with the business area management to identify primary risk exposures and ensure the existing security architecture appropriately addresses and mitigates the exposure. • Advises the Company Leadership Team on risks related to information security and recommends actions in support of the NBP Funds wider risk management and security program. Coordinates with all other IT functional areas to provide guidance and direction for the inclusion of appropriate security controls

  • Head of Information Security & Compliance at DataCheck Limited
    May 2022 - Nov 2023 · 1 yr 7 mos

  • Sr. Information Security Engineer at National Clearing Company of Pak Ltd. (Official)
    May 2016 - May 2022 · 6 yrs 1 mo

    • Leading and managing the Security Operations and team of security operational staff members • Primarily responsible for directing security event monitoring, management and response and cyber intelligence • Ensuring incident identification, assessment, quantification, reporting, communication, mitigation, and monitoring • Responsible for overall use of resources and initiation of corrective action where required for the Security Operations Center • Ensuring daily management, administration & maintenance of security devices to achieve operational effectiveness. • Design and implement use cases, and alerts for Security Operation Center in SIEM. • Managing the continuous monitoring, detection, and analysis of potential events via SEIM solution. • Creating Monitoring Dashboards, and responsible for device integration with SIEM solution. • Perform Administrative activities of McAfee DLP, Sophos MDM, Nessus, Email Security Gateway, Cloudflare, etc. • Develop, implement, maintain, and improve processes aimed at ensuring compliance with Company’s Information/Cyber Security framework, policies, and procedures.

  • IT Support Engineer at Warid Telecom
    Jul 2014 - May 2016 · 1 yr 11 mos

  • IT Support Engineer at Jaffer Brothers (Pvt) Limited
    Mar 2014 - Jun 2014 · 4 mos

    • IT Support Engineer • Deployed at KE Project. • Contractual Employee