
IT Security & Operational Risk Analyst at The Industrial Bank of Kuwait
Kuwait

IT Security & Operational Risk Analyst at The Industrial Bank of Kuwait
Kuwait
IT Audits
IT Security Review
Policies and Procedures
IT Governance Implementation
ISMS / ITIL Implementation
Business Process Improvement
Technology Risk Management
Vulnerability Assessment and Penetration Testing
IT Governance (COBIT, COSO, Basel II)
IT Service Management (ITSM, ITIL)
Information Security Management System (ISMS ISO 27001)
Network Security (NIST, NSA, PCI DSS )
(Banking industry)
April 2008 — Present (1 year 8 months)
Managing Operational Risk
IT Security Strategic Planning
Technology Risk Management
Develop, maintain and implement IT Security Policies and Procedures
Develop IT Security Standards and Baselines
ISMS and IT Governance Implementation
Security Incident Management
Business Continuity Planning and Management
Vulnerability Assessment and Penetration Testing
Legal and Regulatory Compliance for IT Security
Information Security Awareness Training
(Partnership; 51-200 employees; RSMI; Management Consulting industry)
April 2006 — April 2008 (2 years 1 month)
IT Audits
IT Security Review
Policies and Procedures
IT Governance Implementation
ISMS / ITIL Implementation
Business Process Improvement
Technology Risk Management
Vulnerability Assessment and Penetration Testing
(Partnership; 51-200 employees; GTI; Management Consulting industry)
October 2003 — February 2006 (2 years 5 months)
(Public Company; 10,001 or more employees; HCL; Computer Networking industry)
August 2003 — October 2003 (3 months)
Network Support
Network Security
Bachelor of Engineering , Information Technology , 1999 — 2003
IT Security IT Governance ITIL, ISO 27001, CoBiT, NIST Business Process Improvement Risk Management
ISSA - Information Systems Security Association
ISACA - Information Systems Audit & Control Association
CISA CISM