خلاصہ

Cyber security specialist with a passion and talent for aligning security architecture, plans, controls, processes, policies, and procedures with security standards and operational goals.

پراجیکٹس

API Security Assessment
ISO 27001 | ISMS Audit
Secure VOIP Service Deployment, End to End Encrypted

تجربہ

کمپنی کا لوگو
Deputy Manager (IT Auditor)
Federal Govt of Pakistan
فروری ۲۰۲۲ - موجودہ | ICT, Pakistan

Conduct IT audits and reviews of systems, processes, applications, etc. post-implementation review, Cyber Security assessment, Manage Internal Audit, Risk assessment, GRC, Audit Report, and recommendation, Recommend improvement in internal controls designed to safeguard resources and to comply with applicable policies, procedures, Government laws, and regulations. Ensure compliance with audit manual and company’s policies and procedures. Assist in the development and implementation of the annual risk-based audit plan and budgeting.

کمپنی کا لوگو
Deputy Manager (IT and OT Security Audit)
ntdc
جنوری ۲۰۲۲ - موجودہ | Lahore, Pakistan

ICS / SCADA Cybersecurity Management,
• OT Cybersecurity,
• VAPT of OT,
• Integration of Security Controls in OT Network i.e. opensource, Palo Alto etc.,
• IT and OT Security Auditing and assessment,
• Critical Infrastructure Cyber Security and Compliance review,
• Review information security Policy and Procedures,
• Information Security / Cyber Security awareness program,
• Pre/Post audit Implementation review,
• Report all draft observations along with Recommendations,
• Recommend improvement in internal controls designed to safeguard resources and to comply with applicable NTDC Policies, Procedures, Government Laws

کمپنی کا لوگو
Assistant Manager (Cyber Security)
NESCOM
دسمبر ۲۰۱۸ - جنوری ۲۰۲۲ | Islamabad, Pakistan

Cyber Threats analysis / threat intelligence
• Vulnerability Assessment and Penetration Testing
• Cryptographic Products evaluation (FIPS -140-2),
• Cyber Security Evaluation of Software and Hardware Products,
• CIS implementation,
• Device hardening,
• Supports the administration and maintenance of security systems, including firewalls, network, host intrusion prevention/detection systems (IPS/IDS),
• virtual private networks (VPNs) analysis,
• endpoint protection,
• email security,
• digital forensic,
• Open Source SIEM Solution Deployment (WAZUH),
• DevSecOps.
• Integration of Web Security Tools (i.e. Acunetix, nmap etc.) in DevSecOps.
• CD / CI pipelining

کمپنی کا لوگو
Assistant Manager (Cyber Security)
Federal Govt of Pakistan
اگست ۲۰۱۸ - جنوری ۲۰۲۲ | Islamabad, Pakistan

IT Security Assessment (Products – Software / Hardware) Cyber Security Policies and Procedures etc.      




Vulnerability Assessment and Penetration Testing.




Develop Cyber Security solutions for IT Systems.




کمپنی کا لوگو
IT Security Auditor
ECAC
جنوری ۲۰۱۸ - دسمبر ۲۰۱۸ | Islamabad, Pakistan

• Perform Technical Audit of PKI Systems,
• Cyber Security policies and procedures audit for PKI Systems,
• IT Infrastructure Security and Risk Assessment,
• APIs Security assessment (REST / SOAP).
• Implementation of Web of Trust Audit Requirements.

کمپنی کا لوگو
Deputy Director - IT Security Auditor (BPS 18 - Project Based)
ECAC, MoIT, Pakistan.
جون ۲۰۱۸ - اگست ۲۰۱۸ | Islamabad, Pakistan

Perform Technical Audit of PKI Systems.               




IT Security policies and procedures audit for PKI Systems.




IT Infrastructure Security and Risk Assessment




کمپنی کا لوگو
Research Officer
Pakistan Air Force
فروری ۲۰۱٦ - جون ۲۰۱۸ | Islamabad, Pakistan

Secure Products (Software & Web Apps) Security Evaluation & Auditing.




Digital Forensics.




Reverse Engineering & Analysis.




Source Code review




Wireless penetration Testing




کمپنی کا لوگو
Researcher (Cyber Security)
Pakistan Air Force
جنوری ۲۰۱٦ - جنوری ۲۰۱۸ | Islamabad, Pakistan

Vulnerability Assessment and Penetration Testing,
• ISO 27001 Implementation
• Secure Products (Software & Web Apps) Security Evaluation & Auditing,
• Digital Forensics,
• Reverse Engineering & Analysis,
• Source Code review,
• Crypto-Products Evaluation (FIPS 140-2),
• Secure Protocol Analysis,
• Windows and Linux exploitation,
• AV evasion,
• Mobile Applications Security Assessment,

کمپنی کا لوگو
IT Administrator
Triangle International Development Pvt Ltd, Islamabad.
اپریل ۲۰۱۵ - فروری ۲۰۱٦ | Islamabad, Pakistan

Manage IT work in Organization.




Virtualization (VMWARE ESXi) Deployment.




Configuration and Management of (AD, FTP, Web Servers)




کمپنی کا لوگو
Lecturer Computer Science
HIC-University of South Asia, Rawalpindi.
اگست ۲۰۱۴ - مارچ ۲۰۱۵ | Rawalpindi, Pakistan

Cryptography, Network Security, Secure Coding, OOP, Visual Programming

کمپنی کا لوگو
Software Developer
ACCEDE Software House
دسمبر ۲۰۱۳ - مئی ۲۰۱۴ | Hyderabad, Pakistan

Web applications development. [WordPress, PHP], C#, Python

کمپنی کا لوگو
Cyber Security Consultant`
ENSO Lab
دسمبر ۲۰۲۲ - جنوری ۱۹۷۰ | Dubai, United Arab Emirates

• ISO 27001 and 27002 (Implementation and Auditing).
• Penetration Testing and Vulnerability Assessment,
• Gap Analysis,
• Governance, Risk and Compliance
• NIST Cybersecurity Framework
• Power Sector Cyber Security Regulations (Pakistan)
• Information System Auditing
• GDPR
• IT Policy and Procedure development and analysis.
• 3rd Party Cyber Security Audit.

تعلیم

National University of Science and Technology
ماسٹرز, ماسٹرز ان سائنس, MS Information Security‎
Information Security and Network Administration, Information Technology, Information Security Awareness and ISO 27, Security Management, Information Security
2016
Sindh Agriculture University
بیچلرز, بیچلرز ان سائنس, BS IT‎
Information Technology
2014

پیشہ ورانہ مہارتیں

ماہر Asset Evaluation
ماہر Automation Languages Command
ماہر Bash
ماہر Bookkeeping Knowledge
ماہر C#
متوسط C++
ماہر CEH
متوسط Checkpoint Security Management
ماہر CISA
متوسط Cisco Firewall Security
متوسط Cisco Information Security Knowledge
ماہر CISSP
متوسط CMMI
ماہر Creative Desing Skills
ماہر Cyber Defense
ماہر Cyber Operations
ماہر Cyber Security
ماہر Data Control
متوسط Delievry Planning
ماہر Digital Forensics
ماہر Dynamic Code Analysis
ماہر EDR
ماہر Ethics & Professionalism
ماہر GRC
متوسط Handling Assignments
ماہر HIPPA
ماہر HITECH
ماہر HTML
ماہر Information Security
ماہر Information Security Engineering
ماہر Information Security Management Frameworks
ماہر Information System Audit
ماہر Information Technology Audit
ماہر Internal Audit Command
ماہر Internal Controls
ماہر ISO 27001 Lead Auditor
ماہر ISO 9001
ماہر ISO27001
ماہر IT Security
ابتدائی Java
ماہر Linux
ماہر Linux System
متوسط Mac OSX
ابتدائی MATLAB Command
ماہر MIS Audit
متوسط MS SQL Server
ماہر MS Visual Studio
متوسط MySQL
ماہر Network Security Auditing
ماہر Networking

زبانیں

ابتدائی سندھی
ماہر پشتو
ماہر اردو
متوسط انگریزی