About
Cybersecurity professional with experience in governance, risk, and compliance, incident response, penetration testing, and security operations. Strong background in regulatory compliance, SIEM, IAM, digital forensics, and cybersecurity awareness initiatives.
Experience
-
Senior Cybersecurity SpecialistVectramind · Riyadh, Saudi ArabiaFeb 2026 – Present
- Establishing a cybersecurity framework in accordance with CST and NCA regulations. - Managing XDR and anti-malware solutions. - Integrating logs from different systems/applications with the SIEM and implementing log parsing rules for these systems/applications. - Managing the company's PAM solution, integrating it with different systems/applications and ensuring that it is operating based on security best practices and compliance requirements. - Conducting penetration tests on the company's systems/applications. - Conducting cybersecurity risk assessments across the company's assets. - Managing cybersecurity audits conducted on the company by potential clients and regulatory bodies. - Conducting regular cybersecurity awareness campaigns.
-
Cybersecurity SpecialistPerfect Presentation (2P) · Riyadh, Saudi ArabiaOct 2022 – Oct 2025
- Conducting compliance assessment/auditing for clients with known security best practices, frameworks (NCA ECC, NCA CSCC, NCA DCC, NCA OSMACC, NCA CCC, SDAIA PDPL, CST CRF, ISO 27001), and baselines, as well as risk assessments. - Managing cybersecurity audits conducted on the company by potential clients and regulatory bodies. - Developing cybersecurity policies and procedures that ensure the protection of IT assets, data governance/protection, effective risk management, and regulatory compliance. - Developing cybersecurity policies and procedures that ensure the protection of IT assets, data governance/protection, effective risk management, and regulatory compliance. - Working with cross-functional teams to address/mitigate existing cybersecurity risks, ensuring that mitigation strategies appropriately implemented. - Identity and Access Management (IAM) solution implementation and management. - Configuration and deployment of a phishing simulation web application and using it to conduct awareness phishing campaigns and conducting awareness sessions based on campaign results. - SIEM administration, Incident response, and digital forensics. - Managing approvals for user requests and change management processes to ensure compliance with cybersecurity policies and standards. - Overseeing penetration testing activities and reviewing penetration testing reports.
-
Tuwaiq Cybersecurity TraineeSaudi Federation for Cybersecurity, Programming and Drones · Dammam, Saudi ArabiaOct 2021 – Feb 2022
Completed in-depth training on Linux+, Network+, eJPT, eCPPT, eCDFP, and eCIR.
-
IT InternNaizak Global Engineering Systems · Khobar, Saudi ArabiaJul 2019 – Sep 2019
Provided IT help desk support.
Education
-
Bachelor of ScienceKing Fahd University of Petroleum and MineralsComputer Engineering
Skills
Tools / apps / platforms
Courses & certifications
- Identity and Access Management (IAM/IAG/IGA) · 2025
- Tenable.sc Specialist · 2023