Resume
About Me
Cybersecurity and GRC leader who has worked both sides of the regulator’s table: conducting ECC/TCC and cloud service provider audits as an NCA representative, then leading technology-risk oversight inside a SAMA-regulated Saudi bank. More than a decade spanning IT, business, and cybersecurity, with 5+ years dedicated to cybersecurity and technology risk across banking, defense, government, and critical national infrastructure in Saudi Arabia. Strong background in data protection (PDPL, NCA DCC) and regulatory engagement across the NCA, SAMA, and CST ecosystems. I work in Arabic and English across policy, board reporting, and regulator correspondence. Based in Riyadh, Saudi Arabia.
Experience
Senior Manager – Technology & Cybersecurity Oversight @ Confidential Bank
2024-Present
- Own the technology-risk reporting line into the Operational Risk Committee, authoring board-level risk posture reports and leading technology-risk readiness for supervisory examinations.
- Lead enterprise-wide risk assessments across IT and cybersecurity, aligning 200+ controls with SAMA ITGF and strengthening audit outcomes.
- Led robotic process automation (RPA) initiatives in support of the department's Maturity Level 4 objectives under the SAMA IT Governance Framework (ITGF).
- Re-engineered Jira-based risk workflows and built a department-wide remediation tracker and reporting dashboard, embedding KRIs, KPIs, and residual risk scoring.
- Unified risk treatment documentation across audit, compliance, and IT, creating a single source of truth for Three Lines of Defense (3LoD) reporting.
- Integrated threat modelling and asset sensitivity data into risk registers, improving control-mapping accuracy and remediation prioritization.
- Oversee incident investigations and root-cause analysis, annual risk assessments of critical systems, and risk reviews of technology change requests (CRs).
Cybersecurity & Data Protection Specialist @ SAMI AEC
2023 - 2024
- Built and implemented data governance controls aligned to NCA DCC, achieving 100% compliance in the targeted data protection domain.
- Drove broader compliance initiatives across NCA and CST frameworks, with all identified non-conformities closed and verified at re-audit.
- Served as Acting Cybersecurity Department Head during management transition, directing a 6-person team and overseeing the incident response function and keeping incident-response SLAs on track.
- Designed an integrated IT/OT risk assessment framework mapped to NCA OTCC and ECC, increasing threat visibility across 50+ industrial control systems (ICS).
- Deployed the enterprise DRM platform hands-on with the vendor engineer, including the network, traffic, and device encryption groundwork; repaired the data-classification integration, closed DLP detection gaps on uncovered file types, and rolled out FIM and DLP with the SOC and endpoint teams.
Senior Cybersecurity Consultant, NCA Representative @ National Cybersecurity Authority (NCA)
2023 - 2023
- Planned and executed deep-dive ECC/TCC audits across public-sector organizations, preparing audit working papers and findings reports, and identifying critical control gaps overlooked in prior third-party reviews.
- Conducted cloud security governance reviews of Cloud Service Providers supporting national infrastructure, assessing them against NCA CCC and identifying high-risk gaps for remediation by accountable stakeholders.
- Authored strategic reports adopted by CISOs to reshape compliance roadmaps and prioritize risk mitigation budgets.
Cybersecurity GRC Consultant @ I(TS)²
2022 - 2023
- Performed control gap assessments for SABIC (global) and ACWA Power, supporting ISO 27001 audit readiness through documentation review, preparedness activities, and coordination throughout the external audit process.
- Developed 15+ policies aligned with NCA ECC and ISO 27001 and supported their rollout, lifting assessed control maturity by a full level across client programs.
- Designed executive and staff-level security awareness programs that reached 500+ employees and supported stronger cyber hygiene across client organizations.
- Established a new data privacy consulting service, developing PDPL frameworks that expanded the firm's offering and supported business growth.
Information Security Developer (GRC) @ General Authority for Statistics
2021 - 2022
- Implemented 25+ internal controls mapped to NCA ECC/TCC standards, contributing to the organization's first compliant assessment.
- Led a large-scale endpoint security rollout across the authority, deploying a secure golden image and managing the project team.
- Managed SIEM and vulnerability-scanner configurations across 4 review cycles, supporting security monitoring and the vulnerability management cycle.
- Built a governance tracker covering device inventory, ownership, and accountability, with a live progress application for management visibility.
Founder @ Mr. Wireless
2017 - 2020
- Founded and ran a consumer electronics business to profitability within 18 months, owning P&L, vendor contracts and negotiation, and payment-security compliance.
- Automated inventory tracking and sales workflows, improving stock accuracy and customer turnaround time.
Technical Support Specialist @ Aljabiyah Trading Est.
2008 - 2012
- Provided front-line technical support across software, hardware, and network issues, prioritizing and resolving a steady flow of user requests and helping refine help-desk protocols.
Education & Certifications
Professional Certifications | ISACA · PECB · OCEG
2021 - 2024
CISM, ISACA (2024)
CISA, ISACA (2022)
ISO/IEC 27001 Lead Implementer, PECB (2022)
GRCP / GRCA, OCEG (2022)
CompTIA Security+ · CySA+ · CEH (2021)
BSc in Information Technology | DePaul University
2013 - 2017
Hands-On Technical Skills
I keep the technical side current in my Security Lab | 20+ interactive cybersecurity demonstrations covering network reconnaissance, web application attacks, cryptography, and compliance frameworks.
Industry Experiences & Prime Clients
Topic: Data Privacy: Key insights, approaches, challenges and pitfalls, recommendations.
Speaker at MENA ISC 2022
Oil, Gas, Energy
Acwa Power
Fintech
Raqamyah
Public & Government Sector
General Authority for Statistics
Oil, Gas, Energy
SABIC (Local and International Regions)
Public & Government Sector
Al Madinah Region Development Authority
Finance
AlJabr Finance
Hiring for a security leadership role?
Replies within two business days, in English or Arabic.