Summary
Overview
Work History
Education
Skills
Accomplishments
Personal Information
References
Training
Technology Expertise
Projects And Experiences
Timeline
Generic

Adeel Ahmad Makhdum

Altona,Australia

Summary

A professional career comprises more than 18 years of work experience, primarily in ICT operations, Information Security, risk and threat modeling, GRC and Compliance, Security Operations, and Network Infrastructure. This experience includes leading positions, supervising multiple teams simultaneously, and collaborating with various business groups, including Network Operators, ISPs, and banking/financial institutions, with core expertise in IT GRC, Risk Management, Information Security, Compliance, SOC, and Network Operations.

Overview

21
21
years of professional experience

Work History

IS Security Advisor (Risk and Compliance Team)

GHD
11.2022 - Current
  • Work on ISO-27001, Cyber essentials and GDPR compliance and participate in compliance and audit activities tasks.
  • Manage the risk management lifecycle and provide the appropriate control to improve the risk profile of GHD.
  • Product and project risk evaluation with adequate controls as per the security and risk resilience of the organisation.
  • Initial response to daily security checks and information requests. Triage issues unable to be addressed by the analyst.
  • Aids in maintaining security documentation and reference materials.
  • Co-ordinating document reviews by stakeholders.
  • Assist in coordinating the response to information security incidents.
  • Coordinate and respond to customer security questionnaires and provide security leadership in certain procurement projects.
  • Contribute to the development of information Security policies, procedures, standards, and guidelines based on knowledge of best practices and compliance requirements.
  • Conduct security research in keeping abreast of latest security issues.

IT Risk and Security Analyst

Illion
10.2021 - 11.2022
  • Independently leading the PCI -DSS level-1 compliance program and look after all the compliance activities.
  • Work on ISO-27001, Cyber essentials and GDPR compliance and perform the leadership role in all the compliance tasks.
  • Initial response to daily security checks and information requests. Triage issues unable to be addressed by the analyst.
  • Aids in maintaining security documentation and reference materials.
  • Perform monitoring and maintenance of the DTS and Tender link overall IT security posture. Aid in identifying control deficiencies, recommending possible control improvements and implementation of new controls.
  • Work with engineers on vulnerability management, user access reviews, anti-virus management, IDS/IPS oversight, and SIEM log analysis.
  • Co-ordinating document reviews by stakeholders.
  • Assist in coordinating the response to information security incidents.
  • Coordinate and respond to customer security questionnaires.
  • Contribute to the development of information Security policies, procedures, standards and guidelines based on knowledge of best practices and compliance requirements.
  • Collaborate with the NOC teams to manage security vulnerabilities.

Lecturer/ Advisor (Information Security)

White Cliffe
, New Zealand
05.2019 - 01.2021
  • To provide one on one support to students in order to deliver curriculum content on an as required basis, enabling students to complete their formal qualification.
  • Student interactions are structured for the benefits of and engage the needs of the learners by ensuring an inclusive learning environment with minimal barriers to learning.
  • Providing workshops to learners to apply knowledge and skills in a range of relevant contexts.
  • Provide continued support for students to achieve goals by providing professional student management practices, including regular contact and follow ups.
  • Ensure assessments are facilitated in a fair and transparent way and learners are provided with useful feedback.
  • Assist other Institute staff to maintain excellence in the day-to-day delivery of all aspects of a student's course including assisting with the maintenance and effective operation of the Institute Intranet, Network and related resources as required.
  • Continue and maintain Professional Development in relation to product and skills-based knowledge based on latest developments and trends in the IT sector.

Information Security Consultant

JDS Limited
10.2017 - 04.2019
  • Provide service to fulfill PCI-DSS compliance obligations.
  • SOC Management and information security incident management.
  • Threat modelling and Risk Management.
  • Through this platform I was mainly attached with Roosh Technologies ltd.
  • Response to customer Security Assessments and provide consultancy to perform periodic security audits.
  • Conduct the supplier security audits time to time and assist the higher management for future service providers in light of standards set.
  • Work closely with DPO to preserve the data privacy as per the international and National laws i.e GDPR etc.
  • Provide Technical Expert Consultancy for the enhancement and revamping of Network Infrastructure Architecture of certain clients based on their future technological requirement.
  • Network monitoring preparation of periodic reports by using different NMS systems including NetSIEM and Accelops for different clients.
  • Worked on Cisco Meraki products including Access Point and Switches.
  • Provided Monitoring and Technical support to manage Cisco ASA and Firepower firewall suits.
  • Providing L-2 & 3 support services for managed network clients and consumer clients having different WAN services.
  • Response to different RFQ and prepare Network Architecture Design solutions for implementation of different applications.
  • Network Administration and Network Development including LAN, WAN and Wireless Network for different Clients.

Unit Head (LMU & WMU)

Zarai Taraqiati Bank Limited (ZTBL)
11.2006 - 02.2016
  • Normally unit Head in ZTBL is VP and I got chance to Head two units at a time which comprises the whole department lead by SVP. I am lucky enough to work as Acting SVP as well for certain period.
  • Supervise a team of Network Infrastructure and Security Operations to keep up and running of Telecommunication Media infrastructure and enterprise level Network.
  • Work closely with QSA for annual PCI-DSS compliance audit and supervise the implementation of PCI-Plan calendar.
  • Perform periodic risk analysis, threat identification through by using available methodologies and maintain the risk register.
  • Responsible to conduct weekly vulnerability scan and prepare the mitigation plans.
  • Responsible to carried out system sustainability through automation and Technological development different medium sized network infrastructure projects independently and provide technical assistance to Senior Project Manager for higher projects.
  • Responsible to provide technical interpretation of the monitoring data Prepare the design.
  • Implementation of infrastructure enhancement in line with the infrastructure roadmap and guidelines issued by higher management.
  • Responsible for upholding ZTBL's Business Code of Ethics and for promptly reporting violations of the Code.
  • Supervise a team of engineers and Support offices throughout the country and manage their tasks, deliverables. Being the only senior person Assist Engineers by verifying network solutions and ensuring that appropriate products and services have been selected to satisfy requirements.
  • Provide Top Tier Level -3 support for the Field Services Managers (ZDPM), Network Support Engineer, and staff.
  • Mentor other technical groups and present technical solutions to the higher Management for strategic decisions in lieu with Bank's overall organizational goals.
  • Responsible to implement the change with complete analysis of its impact upon the services. Research and analysis of new technologies and implement the technological standards.

Network/Telecom Admin

CBR (PRAL)
03.2006 - 11.2006
  • Leading and supervising the Wireless and Network Team in North Region.
  • Providing L-2 & 3 support services for managed network clients and consumer clients having different WAN services.
  • Worked on Cisco Pix 515 Firewalls, Cisco 1751,2600 series Router and Switches, Nortel Passport 8600 Core switch.

Sr. Engineer

Cyber Internet Services Limited
09.2004 - 03.2006
  • Leading and supervising the RF team in North Region.
  • Project planning, Scheduling, execution, and monitoring during all the project phases.
  • Providing L-2 & 3 support services for managed network clients and consumer clients having different WAN services.
  • Configuration and implementation of Cisco Routers and Switches.
  • Wireless Network Surveys and establishment of certain PTP and PMP circuits.
  • Used PRTG and MRTG for Network monitoring and preparation of periodic reports for Higher Management.

Education

M.Phil. - Engineering Management

University of Engineering and Technology Taxila
Taxila, Pakistan

M.Sc. - Computer Sciences

Hamdard University Karachi
Karachi, Pakistan

B.Sc. - Electronics

University of Punjab
Lahore, Pakistan

Skills

  • Risk management
  • ISO compliance
  • GDPR compliance
  • Security documentation
  • Incident response
  • Vulnerability management
  • Threat assessment
  • Customer security
  • Policy development
  • Regulatory compliance
  • Security audits
  • Team collaboration
  • Effective communication
  • Problem solving
  • Attention to detail
  • Compliance monitoring
  • Interpersonal communication
  • Staff training
  • Analytical skills
  • Asset protection
  • Emergency response management
  • Security Policies Enforcement
  • Disaster recovery planning
  • Task prioritization
  • Threat management
  • Business continuity planning
  • Teamwork
  • Digital forensics
  • Identity management
  • Problem-solving abilities
  • Access management
  • Security Intelligence Gathering
  • Information security
  • Security policy development
  • Multitasking capacity
  • Multitasking Abilities
  • Disaster recovery

Accomplishments

  • Successfully lead the PCI-DSS Level-1 certification activities for Illion., 2022
  • Successful renewal of ISO 27001:2013 Certification., 2022
  • Extensively working on renewal of cyber essentials certificate for UK Office.
  • Preparing and pursuing the GDPR Compliance.
  • Hands on working with different ISM and Cyber security protective security frameworks.
  • Actively leading the Risk identification, Risk Analysis, Evaluation, and mitigation processes.
  • Maintain the Risk register and provide DPIA for certain platform.
  • Directly maintaining the Supplier Security requirements and customer security assessments.
  • Extensively working on vulnerability Management and remediation with different stakeholders.
  • Perform daily compliance check and prepare the weekly and monthly reports for BOD.
  • Created & implemented the Service management standards for Managed Network Services in NSP industry.
  • Created & Published the Bank's Comprehensive IT Governance Framework.
  • Created & Published the Bank's IT DR/BCP Procedure and Incident Management Policy.
  • Created & published the set of Information security Policies in compliance with PCI-DSS and ISO-27001.
  • Created core documentation and oversaw the implementations of PCI-DSS Standard within ZTBL.
  • Lead the Network team to setup Network and Security infrastructure from the scratch for 5550+ branch offices.
  • Currently working on research projects related to Cyber Security and Data Privacy.

Personal Information

Visa Status: SCV-444 (NZ Citizen)

References

References will be provided on request.

Training

  • AWS Cloud Security and Threat Management
  • PCI-DSS Compliance
  • GDPR and NZ, AU privacy acts
  • Threat analysis and Risk Mitigation
  • Program Management in Telco Orgs
  • Project Management Professional (PMTE)
  • Cisco Certified Network Professional (CCNP)
  • PPRA Rules and Management (PPRA Govt of Pakistan)
  • Pursuing CISSP & CRISC

Technology Expertise

  • Qualys VM
  • Crowd strike
  • Solar wind SIEM
  • NNT FIM
  • STRIDE threat management
  • AWS cloud security Management
  • Cisco (Firewalls, Routers, Switches, Wireless Controllers, MLS)
  • Microsoft (Windows Workstation and servers, MS Project, Office and Visio)
  • Fortinet (Firewalls & IDS/IPS, UTMs, FortiAnalyzer)
  • Huawei (Routers 1100, Switches, Wireless AP and controller)

Projects And Experiences

  • Information Security Governance Project, Management and Maintenance of Information Security Governance Framework., Creation of Information Security Policies, Procedures, Guidelines and Standards based on ISO 27001 and PCI-DSS Standards., Compliance with GDPR and Cyber essentials., Providing security consultancy services to key business and technology projects.
  • Country Wide Network Infrastructure Establishment Project, Creation of Technical Architecture Design., Management and Maintenance of ICT Project Management Framework., Providing Network Technical consultancy services to key business and technology projects.
  • Incident Management, Published comprehensive Incident Management Policy and Procedures., Conducting Qualitative and Quantitative Risk Analysis for Incidents.
  • Operational Management, Worked as liaison Officer between customer and Service Provider., Customer account management and Provide lead technical support.

Timeline

IS Security Advisor (Risk and Compliance Team)

GHD
11.2022 - Current

IT Risk and Security Analyst

Illion
10.2021 - 11.2022

Lecturer/ Advisor (Information Security)

White Cliffe
05.2019 - 01.2021

Information Security Consultant

JDS Limited
10.2017 - 04.2019

Unit Head (LMU & WMU)

Zarai Taraqiati Bank Limited (ZTBL)
11.2006 - 02.2016

Network/Telecom Admin

CBR (PRAL)
03.2006 - 11.2006

Sr. Engineer

Cyber Internet Services Limited
09.2004 - 03.2006

M.Phil. - Engineering Management

University of Engineering and Technology Taxila

M.Sc. - Computer Sciences

Hamdard University Karachi

B.Sc. - Electronics

University of Punjab
Adeel Ahmad Makhdum