
Risk Specialist - IT Security at Burgan Bank
Kuwait

Risk Specialist - IT Security at Burgan Bank
Kuwait
About 12 years of professional experience
• Certified Information Security Manager (CISM)
• Certified Information Systems Auditor (CISA)
• Business Continuity Certified Professional (BCCS)
• BS7799-2 : 2002 Certified Implementer
• ISO 27001:2005 Certified Implementer
• Conducted pre-certification internal audits on BS7799 & ISO 27001 compliance
• Conducted systems and application functionality audits for an organization who is a major player in providing value added services for mobile users
• Implemented Information Security Strategy and assisted 2 organizations to achieve BS7799-2: 2002 and ISO 27001 certification
• Developed security and privacy policies, standards and procedures aligned to the business objectives
• Developed organization wide and department/project specific BCPs
• Developed and conducted Risk Assessment & Management practices
• Conducted network security and vulnerability assessments
Information Security implementation and audits based on ISO 27001:2005 standard, Business Continuity Development and Implementation, Enterprise Risk Assessment and Management
(Public Company; Banking industry)
January 2009 — Present (11 months)
(Privately Held; 11-50 employees; Information Technology and Services industry)
December 2007 — October 2008 (11 months)
Developing the Information Security practice
Managing ISMS projects delivered to various clients
(Privately Held; 51-200 employees; Information Technology and Services industry)
May 2006 — October 2007 (1 year 6 months)
Deputed at BankMuscat, Muscat, Oman
Lead the IT Security team towards implementing security controls and certifying against ISO 27001
Key member in carrying out Risk Assessment exercise for the entire bank
(Privately Held; 1001-5000 employees; Information Technology and Services industry)
April 2000 — April 2006 (6 years 1 month)
IT Security Team Lead
Led the organization towards implementation of security controls and certifying against BS7799
At US Technology International, United States of America.
Installed and implemented Courier mail server using OpenLdap for authentication on Linux platform and Squirrel Mail for mail server web access.
Setup a Data Center to host organizations critical servers at Los Angeles.
Implemented perimeter security devices (Cisco PIX) at both corporate office and data center.
At Amersham General Hospital, United Kingdom
Migration of all servers running Windows NT 4.0 to Windows 2000 Advance Server including the Domain Controllers.
Installed and configured the Exchange 2000 server to be routed through an Exchange 5.5 server.
Established the connectivity for the users at different hospitals (at different geographical locations) and users from the Internet to access the Clinical Web Application.
ISACA, BCMI, ISSA