概要

Gaining experience from multiple domains of IT helped me understand the Information Systems more efficiently and as a part of Information Security team I performed numerous Information Systems audits during my job. Moreover, the blend of knowledge that I gained through the network security and penetration testing trainings helped me in performing the tasks related to network penetration testing effectively.

项目

ISO27001 Lead Auditor
ISO 27001 Implementation

工作经历

公司标识
IT Security Engineer
Fatima Group
Jan 2018 - 代表 | Lahore, Pakistan

IT Security Engineer

公司标识
InfoSec Engineer
Systems Limited
May 2017 - Dec 2017 | Lahore, Pakistan

Working as InfoSec Engineer on the following projects:
Implementation of ISO 20000 (ITSMS)
Conducting regular activities for ISO 27001 and 9001 standard conformance
Optimisation of IBM QRadar SIEM solution according to the new and upcoming threats

公司标识
Sr. Information Security Officer
MTBC
Jan 2017 - May 2017 | Rawalpindi, Pakistan

Providing technical support for audits, certification and other compliance efforts including HIPAA/HITECH, PCI-DSS, ISO27001 etc. Below are some highlights of my work:
• Implemented multiple controls of ISO 27001: 2013 that ensured:
o Segregation of production, development and testing environment by assigning role-based rights
o Classification of data by redefining the asset management procedures
o Capacity planning by regularly observing the network performance monitoring tools and company strategies
o Preventing unauthorized access on Information System assets by providing access only on required basis
• Performed internal network penetration testing and proposed remediations to encounter network attacks like MITM, SNMP enumeration, firewall evasion etc.
• Suggested strong access control procedures for all of the information resources by performing multiple Information Systems audits
• Highlighted the critical assets and risk areas by performing qualitative risk assessment biannually
• Performed testing of Disaster Recovery Plan by successfully achieving the desired RTO and RPO on recovery site
• Performed vulnerability assessment of all the critical assets of MTBC on weekly basis

公司标识
Information Security Officer
Mtbc
Jan 2016 - Jan 2017 | Rawalpindi, Pakistan

Documented, designed, deployed and maintained security systems to protect company assets and information while being compliant with applicable federal, state and commercial security standards. Following are my major accomplishments working as ISO:
• Performed daily log analysis for URLs, incoming/outgoing emails and VPN
• Analyzed the security aspects of change management forms
• Worked on Solarwinds Log and Event Manager for monitoring of security events on critical assets
• Documented and designed access control procedures during the transition of hard copy forms to electronic portal
• Performed multiple audits including audits of access control procedures, change management processes etc.
• Served as official contact point for information security and privacy incidents

公司标识
Jr. System Analyst
Mtbc
Jan 2015 - Dec 2015 | Rawalpindi, Pakistan

Clients’ requirement elicitation and proposal of business friendly solution(s) with least development cost. Following are some of my major projects:
• Proposed complete flow of Access Control Automation for critical assets of company
• Proposed the workflow for login page of all web/mobile applications to minimize the effect of security threats
• Analyzed all the application changes from security perspective
• Analysis and design of major mobile applications (i.e. MTBC PHR, MTBC iCheckin, MTBC iDictate etc.)

学历

National University of Science and Technology
哲学硕士, MS (Networks & Telecom)‎
Data Communication and Computer Networking
Completed
2014
COMSATS Institute of Information Technology
学士, 理工学士, Telecommunication Engineering‎
Computer Networks, Wireless Communication, Wireless Networks,
CGPA 2.84/4
2012
Federal Board
中级/A级, 理学院(工程预科), Pre-Engineering‎
maths physics chemistry
所占比重 76.4%
2007
Federal Board
大学入学/0级, 科学, Matriculation‎
maths physics chemistry
所占比重 81.4%
2005

技能

中级 BCMS
中级 Business Continuity Planning
中级 Disaster Recovery
中级 Enterprise Network Security
中级 ISMS Implementation
中级 ISO 20000
中级 ISO 27001
中级 IT Auditors
中级 ITIL Implementation
中级 Penetration Testing
中级 Risk Assessment
中级 Vulnerability Assessment

语言

熟练 旁遮普语
熟练 乌尔都语
熟练 英语