Cyber Security Officer
Current• Performed necessary tasks to protect information systems assets from unauthorized access or destruction by involving in several GRC initiatives such as DBAM Tool implementation, Beauceron Security (SaaS) implementation and Data masking on customer credit & debit card numbers stored on the Database server.• Implemented ISO 27001 to include new enhancements/changes, which required the development and implementation of new Information Security policies and procedures.• Responsible for governance, risk, and compliance activities within the Information Security team utilizing best practice frameworks such as NIST, ISO 27001 and PCI-DSS.• Monitored the results from risk assessments, penetration testing, and vulnerability scans and ensured treatment plans and remedial actions are being progressed.• Tracked developments and changes in the digital business and threat landscape to ensure that they are adequately addressed in security strategy plans and architecture artifacts. • Implemented Beauceron Security (SaaS) platform for all Bell employees to provide Security education focusing on human side of security. Helped in designing awareness programs through surveys, computer-based training, phishing simulations, and risk scoring.• Performed risk assessment for cybersecurity, information security and business continuity.• Facilitated the Audit process within the team in terms of identification of root cause of audit findings, determine and implement appropriate CAPA / Remediation Plan.• Conducted Infrastructure Audits; IT Audits and internal controls testing (design & operating effectiveness) to verify areas of weaknesses requiring remediation before rewriting policies and undergoing mandatory compliance audits.• Set up ISMS policies and standards, fostering security awareness across the Organization.• Participated in Business Continuity Plan and Disaster Recovery policy drafting.• Involved in DR Drills, BCP Notification Testing.