Cyber Risk Assessment
Assess critical applications, infrastructure, vendors, and business processes by identifying risks, impacts, control gaps, and practical treatment actions.
Riyadh, Saudi Arabia | CRISC - CRTP - ECSA - CEH - RHCSA
I help organizations identify cyber risk, manage vulnerabilities, review secure architecture, and align IT/OT projects with regulatory requirements, security standards, and business objectives.
Professional profile
I am a Senior Cyber Security GRC Specialist with strong experience in comprehensive risk assessments, vulnerability management, regulatory compliance, third-party risk, security audits, and secure architecture reviews for new and ongoing technology projects.
My background combines governance and hands-on technical security across Linux, Windows, Active Directory, web application security, network security, WAF implementation, vulnerability assessment, penetration testing, business continuity, disaster recovery, and operational technology environments.
Expertise
Core strengths across GRC, technical security, compliance, architecture, and enterprise risk visibility.
Assess critical applications, infrastructure, vendors, and business processes by identifying risks, impacts, control gaps, and practical treatment actions.
Review new projects, system designs, infrastructure changes, application features, and OT systems before deployment to ensure security alignment.
Support scanning governance, finding assignment, risk prioritization, remediation tracking, and vulnerability reporting across enterprise environments.
Facilitate security compliance, evidence review, audit readiness, control mapping, and alignment with internal policies and external regulatory expectations.
Evaluate vendor security posture, contracts, compliance evidence, remote access, criticality, data exposure, resilience, and risk treatment actions.
Implement and enforce controls in IT and OT environments where resilience, availability, segmentation, change control, and compliance are critical.
Develop KRIs and Power BI reporting to translate technical findings into clear management insight and decision-ready security dashboards.
Apply technical experience in application security, WAF, Linux, Windows, Active Directory, network controls, firewall review, and secure configurations.
Career summary
A timeline built from your updated CV, focused on the strongest cybersecurity and GRC messages.
Selected impact
Numbers and accomplishments that communicate seniority and credibility without exposing sensitive information.
Credentials
Certifications and education that support both governance leadership and technical review capability.
Research focus
Controls for secure AI systems in regulated organizations, including governance, risk assessment, data protection, model security, monitoring, and accountability.
Technical and regulatory analysis of incidents affecting critical services, with practical lessons for resilience, incident response, and governance.
Approaches for aligning operational technology security with risk appetite, regulatory expectations, change control, and business continuity needs.
Contact
Available for professional inquiries, research collaboration, cybersecurity GRC discussions, and consulting-related conversations.