++ Supervise the development and implementation of plans and goals across 33 ministries and sub-departments.
++ Ensure compliance with regulations(ISO 27001, ISO 9000, NIST, GDPR, HIPAA, HiTrust) and internal policies.
++ Undertake staffing responsibilities (hiring, training, evaluating etc.) across 33 ministries and attached departments.
++ Create reports and submit them to the prime minister of Pakistan.
TecNext Private Limited
Dec 2020 – Aug 2021
Islamabad
eCommerce GRC Lead
++ Oversight and guidance for all Governance, Risk and Compliance (GRC) for Wallan Group KSA eCommerce Services.
++ Develop, maintain, and publish corporate-level information security policies, standards, procedures, and guidelines to obtain and maintain company certifications.
++ Engage in penetration studies, threat analysis, vulnerability assessments, and security audit activities to ensure controls and security are effective. This includes the development & management of regular security awareness training for all employees.
++ Verify relevant third-party attestations and perform risk assessments to validate the necessary safeguards are in place to protect our information assets.
++ Manage and lead quarterly Information Security Management Committee meetings with the Company’s executive leadership.
++ Collaborate with Legal and sales to pragmatically support the sales effort with prospects and customers by championing the security value of eCommerce Services.
++ Provide security leadership and mentoring to all eCommerce Services departments.
Interactive group of Companies
Feb 2020 – Jun 2020
Islamabad
Information Security Analyst
++ Performed risk analyses to identify appropriate security countermeasures.
++ Recommend improvements in security systems and procedures.
++ Encrypted data and erected firewalls to protect confidential information.
++ Monitored use of data files and regulated access to protect secure information.
++ Developed plans to safeguard computer files against modification, destruction or disclosure.
++ Monitored computer virus reports to determine when to update virus protection systems.
++ Conducted security audits to identify vulnerabilities.
++ Reviewed violations of computer security procedures and developed mitigation plans.
++ Devoted special emphasis to punctuality and worked to maintain outstanding attendance record, consistently arriving
to work ready to start immediately.
PPHI Sindh
Apr 2018 – Feb 2020
Larkana
Data Security Specialist
++ Initiates, facilitates, and promotes activities to foster Healthcare Data security awareness within the organization.
++ Manages security incidents and events involving electronic protected health information (ePHI)
++ Ensure that the disaster recovery, business continuity, risk management and access controls needs of the facility are addressed.
++ Ensures that PPHI complies with the World Bank, technical and physical safeguards.
++ Collaborates with organization senior management, Privacy Officer, and Corporate Compliance officer to establish governance for the security program.
++ Is responsible for initial and periodic information security risk assessment/analysis, mitigation and remediation. Responsible for development and implementation of security risk management plan.
++ Working closely with Privacy Officer as needed with breach determination and notification processes under HIPAA and applicable State breach rules and requirements.
++ Serves as information security consultant to all departments for all data security related issues.
Sindh Rural Support Organization
Jun 2017 – Apr 2018
Larkana
MIS Officer
++ Database Design, Implementation and Management
++ Troubleshooting and Network Equipments Management
++ Designed and evaluated WAN and LAN connectivity technologies.
++ Keeping track of Project KPIs
++ Quarterly Bi-annually and Annually Donner reporting
++ Performed network security design and integration duties.
++ Standardized job tasks and trained junior team members on industry best practices and standards
TakeOne Private Limited
Sep 2016 – Aug 2017
Larkana
Master Trainer - IT
++ Compiled IT training and assessment resources based on understanding of technical processes and skills-development needs.
++ Updated training coursework and requirements according to group and technology changes.
++ Cultivated customized curriculum and course content to address organizational technology training mandates.
++ Led syllabus preparation based on detailed breakdowns of technical concepts.
++ Removed malware, ransomware and other threats from laptops and desktop systems.
++Assessed system hardware and software and suggested modifications to reduce lag time and improve overall speed.