概要

Information Security Specialist with 8 years of professional experience in the field of information security and Information Technology with multiple industry leading certifications

Responsible for protecting computers and networks against security breaches and cyber-attacks incident handling, alert tracking, cyber security case management.

Certifications

ISO/IEC 27001 ISMS Lead Auditor


CCNA Cyber Ops 210-250 SECFND & 210-255 SECOPS


CCNA Security 210-260 IINS (CCNA) Security


Cisco Certified Network Associate (CCNA) Routing and Switching


Kaspersky Endpoint Security Associate


Kaspersky Lab Certified Professional


Fortinet NSE 1 Network Security Associate


Fortinet NSE 2 Network Security Associate


IBM QRadar SIEM Foundation


Splunk 7.x Fundamentals Part 1 (eLearning)



Trainings
CISSP Review (ISC)²


Certified Ethical Hacker (CEH) - Trillium


Nexpose Vulnerability Assessment -Trillium


CISSP Security - IT master Charles Strut University


Phishing Countermeasures - IT master Charles Strut University


Burp Suite, Web Hacking Tool -Udemy


Effective Security Operation Using IBM QRADAR-Ebryx


FortiGate Essentials 6.2 – Fortinet


Autopsy Digital Forensics Platform – Autopsy


CNSS Certified Network Security Specialist - ICSI, UK


Siem Fundamentals - Elastic


Anomaly Detection for Cyber Security – Elastic


Siem Administration with QRadar – Pluralsight


Incident Detection and Investigation with QRadar– Pluralsight


Foundations of Operationalizing MITRE ATT&CK-AttackIQ


项目

Kaspersky antivirus Deployment at The Bank of Punjab
Qradar Siem Deployment at The Bank of Punjab

工作经历

公司标识
Information Security Specialist
Punjab Information Technology Board
Jan 2020 - 代表 | Lahore, Pakistan

The primary responsibility is to analyze systems for vulnerabilities suggest best security solutions, and handling cyber-attacks in an efficient and effective manner.
Duties:
 Update the Network design for emerging threats to ensure cyber security.
 Coordinate with IT for Incident Response and handling.
 Manage risk Assessment and vulnerability scanning of Infrastructure (OS, Systems, Sever, and Networks etc.)
 Risk Assessment of new IT and business initiatives.
 Network Security Monitoring and assessment using various tools.
 Contribute in Information Security SOPs/Guidelines development and maintenance.
 Manage logical and physical access controls reviews and prepare reports for higher management.
 Design and conduct targeted Information Security Awareness Trainings.
 Design and ensure the implementation of ACL and Security Baseline.
 Security Reviews for network and IT infrastructure.
 Policy Definition for End point, firewall, web gateway, Domain controller etc.
 Coordinate and perform Vulnerability scanning and penetration testing of network/systems.
 Incident logging, reporting /management.
 Awareness training of the employees on information security standards, policies and best practices.
 Conduct penetration testing, simulating an attack on the system to find exploitable weaknesses.
 Perform static/dynamic mobile application testing, and penetration testing of web applications to identify vulnerabilities and security defects.
 Perform Internal Audits.

公司标识
IT Security Engineer
Fatima Fertilizer Company Limited (FFCL)
Apr 2019 - Jan 2020 | Lahore, Pakistan

The primary responsibility is to design, implement, protect and support the company’s overall information security infrastructure.
Duties:
 Perform Internal Audits and Co-ordinate external audits
 Monitor for potential compromise, intrusion, significant event, or threat to the security posture of the company.
 Triage alerts and reports received from various sources and perform incident response in real time as needed
 Work closely with internal team members as well as external partners to identify and resolve information security issues
 Continuously monitor and tune SIEM and related systems to increase detection rates, reduce false positives, and improve response time
 Engage in threat hunting and proactive security operations
 Evaluate, deploy, and maintain security tools, technology, and systems
 Perform security assessments on new and existing systems, processes, and technology
 Develop, update, and maintain standard operating procedures and other technical documentation.
 Define policies for email security, endpoint protection, application whitelisting, and other systems and network enforcement points
 Collaborate to define security standards and develop secure procedures
 Work closely with multiple groups and business units globally to provide guidance and support
 Perform regular security and vulnerability reviews and participate in periodic security and compliance audits
 Monitor and respond to \'phishing\' emails and \'pharming\' activity
 Training, Awareness and developing cyber security skills of Fatima-group employees

公司标识
information security officer
The Bank of Punjab (BOP)
May 2016 - May 2019 | Lahore, Pakistan

The primary responsibility is to design, implement, protect and support the company’s overall information security infrastructure.
Duties:
 Configure and troubleshoot security infrastructure devices and solutions to protect systems and information infrastructure, including firewalls and data encryption program
 Identify and define system security requirements for the bop infrastructure.
 Design new system security architecture and develop detailed network security designs or upgrade existing ones
 Prepare and document standard operating procedures and protocols
 Ensure that the company knows as much as possible, as quickly as possible about security incidents
 Work with security team to perform Vulnerability Assessments and uncover network vulnerabilities.
 Write comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancement using tools (Winaudit, MBSA, NMAP, Advance IP Scanner, SIEM Qradar, Nexpose, Nessus, Rat, skybox and Nipper).
 Coordinate with Assets custodians and owners to Fix detected vulnerabilities to maintain a high-security standard.
 Monitor computer networks for security issues, attacks, intrusions and unusual, unauthorized or illegal activity
 Investigate security breaches and other cyber security incidents.
 Document security breaches and assess the damage they cause.
 Monitor and respond to \'phishing\' emails and \'pharming\' activity
 Maintain an information security risk register, risk tracker and assist with internal and external audits relating to information security
 Perform POC, Evaluate security products and Research security enhancements and make recommendations to management how to increase security posture and minimize security Risk.
 Perform Security Audits of network and infrastructure to highlight gaps
 Conduct cyber security awareness trainings of BOP employees

公司标识
Network Support Executive
TkXel
Feb 2015 - Feb 2016 | Lahore, Pakistan

Responsible for supporting the company\'s employees at all levels as part of a helpdesk team. Ensuring that all hardware and software is configured and installed correctly.
Duties:
 Responsible for networking, design, installation and maintenance services.
 Installation and maintenance of Pfsense Firewall, ESX, Citrix Xen SERVER, VMware.
 Supporting users over the telephone, Skype and by email.
 Maintain the company\'s network infrastructure.
 Networking and providing support for Windows, Macintosh and Linux issues.
 Configuration and testing of any new hardware and software.
 Management of the daily data backup and retrieval scheme.
 Installing and operating Linux/Windows desktop and server operating systems.
 TCP/IP networking and hardware maintenance and repair.
 Training new employees. Assistance with training of staff and compiling procedural documentation.
 Assisting the network manager with support requests.
 Applying patches in accordance with company procedures.

公司标识
Technical Support Engineer
Mobilink GSM (PMCL)
Sep 2014 - Feb 2015 | Lahore, Pakistan

公司标识
Network and System Support Engineer
Cog-Soul Soft
Oct 2013 - Sep 2014 | Lahore, Pakistan

公司标识
Network and System Support Engineer
Express News
Mar 2013 - Sep 2013 | Lahore, Pakistan

公司标识
Intern SoftwareEngineer
Infogistic (Pvt.) Ltd.
Jan 2012 - Mar 2013 | Lahore, Pakistan

学历

COMSATS Institute of Information Technology
学士, , Bachelors of Engineering‎
Computer Science
所占比重 71%
2012
Fazaia inter college Lahore cantt
中级/A级, , F.Sc Pre-Engineering‎
所占比重 58%
2007
paf inter college munir road lahore
大学入学/0级, , Matric in Computer Science‎
所占比重 68%
2004

技能

初学者 Amin Management
初学者 ATS Knowledge
初学者 Automation Languages Command
初学者 British Accents
熟练 Cyber Defense
熟练 Cyber Security
初学者 Embedded Programming
初学者 Erlang
初学者 Establishing Strategic Partnerships
初学者 Evaluating Risk
初学者 Event Marketing Strategies
初学者 Executive Presentation Skills
初学者 Export Development
初学者 Forth
初学者 Go-to-Market Strategy
初学者 Government
初学者 Government Contract Negotiations
熟练 Green Hills Integrity
初学者 h Operations Management
初学者 Handling Assignments
初学者 Haskell
初学者 Heavy Machinery Knowledge
初学者 High Networth Individuals
初学者 High Rise Buildings Knowledge
初学者 HTML and XHTML
初学者 Import Operations Handling
初学者 Individuals / Consumers
初学者 Institutional Selling
初学者 International Business Exposure
初学者 Internet Services
初学者 Inventory Planning
熟练 iOS
初学者 J2EE
初学者 JavaScript
初学者 Jquery
初学者 JScript.
初学者 JSP
初学者 Knowledge of FMCG
初学者 Labor Laws
初学者 Lead in
初学者 Less than 1 month
初学者 Less than Rs. 1,000
熟练 Linux System
初学者 Lisp
初学者 Live Demo
初学者 Lua
熟练 Mac OSX
初学者 Managing Midsize Teams - 5 to 20 People
初学者 Marketo
初学者 Microsoft SQL

语言

熟练 旁遮普语
熟练 乌尔都语
中级 英语