
Shahid M.
vCISO and Cybersecurity Consultant, ISO 27001, SOC 2 and GRC Expert
Skills

Bekijk mijn diensten


Portfolio
Werkervaring
Head of Information Security
Idenfo • Fulltime
Apr 2022 - Present • 4 yrs 5 mos
Architected and govern the enterprise-wide information security program across GDPR, PDPA, PDPL, SAMA-CSF, NCA-ECC, PECA, SBP and SECP requirements for operations in 15+ countries. Built the ISMS from ground-zero to ISO/IEC 27001 certification in 12 months (zero non-conformities); led SOC 2 Type II readiness for Fortune 500 customers; deployed zero-trust/UAM architecture (75% insider-risk reduction) and WAZUH SIEM (95% faster threat detection, MTTD 48h to 2h); ran enterprise risk assessments (150+ risks, 85% risk-exposure reduction over 24 months).
Executive - Information Security (NOMC)
Zong 4G • Fulltime
Jan 2020 - Apr 2022 • 2 yrs 3 mos
Enforced PTA-regulated security policy across a telecom network serving 50M+ subscribers. Ran enterprise vulnerability management across 10,000+ devices (35% reduction in critical unpatched vulns in 6 months), VAPT on mobile apps, web portals and network infrastructure (200+ high-severity findings remediated pre-production), and a phishing-simulation program that cut susceptibility 25% in year one.
Information Security Officer
Khushhali Microfinance Bank Limited • Fulltime
Oct 2019 - Jan 2020 • 3 mos
Strengthened the ISMS for an SBP-regulated microfinance institution; ran risk assessments and internal audits under RMF/SBP guidelines; supported ISO/IEC 27001 governance and PCI-DSS alignment for payment card operations; supported SOC incident investigations and forensic evidence collection.