Iyad Abou Hawili

Iyad Abou Hawili Email and Phone Number

Cyber Security Solutions Architect @ SARA-IT (Security Advisory Research Audit)
Iyad Abou Hawili's Location
North York, Ontario, Canada, Canada
Iyad Abou Hawili's Contact Details

Iyad Abou Hawili work email

Iyad Abou Hawili personal email

n/a
About Iyad Abou Hawili

Extensive expertise in cybersecurity, excelling in modeling architecture designs. Strong leadership in managing projects, teams, and vendor relationships with a robust certification portfolio demonstrating deep knowledge in cybersecurity in different domains.

Iyad Abou Hawili's Current Company Details
SARA-IT (Security Advisory Research Audit)

Sara-It (Security Advisory Research Audit)

View
Cyber Security Solutions Architect
Iyad Abou Hawili Work Experience Details
  • Sara-It (Security Advisory Research Audit)
    Director, Information Security Architecture
    Sara-It (Security Advisory Research Audit) Apr 2013 - Present
    Montreal, Ca
  • Cae
    Cyber Security Solution Architect
    Cae Sep 2019 - Apr 2024
    Montréal, Québec, Ca
    • Prepare security requirements as part Preliminary and Detailed solution architecture and present security controls in the Architecture Review Board and Change Management Board.• Developed IAM strategy, gap analysis, solution selection, and Proof of Concept.• Developed a holistic, agile, security roadmap for internet gateway moving it from one maturity level to another.• Lead the evaluation, selection, design and the implementation new security tools and evaluation of security controls of business solutions.• Support other teams across in remediation of security anomalies gaps and issues.• Prepared Privacy/Consent/Cookies security requirements and helped in solution deployment.
  • Air Canada
    Information Security Architect Specialist
    Air Canada Jul 2018 - Sep 2019
    Saint Laurent In Montreal, Quebec, Ca
    • Prepared Mobile, Web, and API Security Requirements, and assessed mobile/web through security code reviews, penetration testing.• Guided developers in application design and code review sessions to identify security risks.• Worked closely with (Solution Architects, Application Architects and Developers) to help identify and appropriately remedy software security and infrastructure vulnerabilities• Helped in creating security standards for application deployment on both private and public clouds and oversee the implementation of appropriate applications as per defined standards and frameworks• Prepared Security User Stories and prepared Penetration testing scope.• Prepared AWS Cloud Security and Resources security requirements (Serverless, appsync, GraphQL, etc…).• Led Security Advisory Board and evaluated technological changes that include Network changes, system changes, AWS configuration, etc..• Worked on Cloud security, Software Security, IAM, MFA, Internet App, API, etc…• Prepared maturity models for Privileged Accounts, IAM, MFA, etc..
  • Bmo Financial Group
    Information Security Manager
    Bmo Financial Group Apr 2017 - Jul 2018
    Toronto, On, Ca
    • Designed a new overall DLP strategy for BMO. Introduced Business driven approach to DLP/Rules design and implementation. Introduced resolution for 75% of the DLP use cases. Improved end-to-end cycle of Event handling.• Provided support for the Governance of the Bank information security initiative (DLP, CDN/Akami, FW, Proxy, and Cloud).• Designed and Managed Exception process to Information security policy using Archer.• Added functionalities and re-structured CDN - Akamai policies.• Prepared Rule base optimization of all FW metrics. Reviewed FW governance policies, and optimized FW Rule change process.• Managed a group of eight people, and led Forum meetings attended by C-level staff.
  • Icici Bank
    Information Security Manager
    Icici Bank Oct 2015 - Apr 2017
    Mumbai , Maharashtra, In
    • Conducted FFIEC and OSFI cyber security self-assessment and followed up on controls implementation.• Served as a focal point for advisory on Information Security topics and others to meet and maintain compliance with internal audit, and regulators (OSFI, FFIEC, GLBA, PIPEDA and PCI).• Assessed Service provider’s Security for all outsourced activities by conducting Service, Information Security, and Vendor’s Continuity Risk Assessment.• Evaluated Service Provider’s reports such as: SOC1, SOC2 Type I and II, and VAPT.• Provided support for implementation and monitoring of the Bank information security initiative (APT, IDS/IPS, Proxy, URL filtering, DMARC, Mobile Device Management -MDM, DLP, DDoS, etc.…).• Conducted vulnerability scans and penetration tests (internal and external) and advised IT team on remediation of vulnerabilities.• Prepared scope of Work (services), and evaluated DDoS service providers’ proposals.• Communicated bank’s information security stance, including compliance issues, risk and incidents to senior management.• Delivered cyber security training to the bank employees.• Prepared BOD committee’s presentations, and supporting documents.
  • Qatar General Electricity & Water Corporation (Kahramaa)
    Information Security Officer
    Qatar General Electricity & Water Corporation (Kahramaa) Dec 2005 - Jan 2013
    Doha, Qa
    • Conduct research and analysis that will contributed to the planning, design, development, implementation and support of the Risk Management and Cyber Security programs.• Provide specialized advice on Cyber Security issues affecting the organization such as: (1) Identify potential exposures, (2) Conduct reviews to ensure that undesirable effects are detected, corrected and/or mitigated, (3) Provide consultation assessed high-profile projects for Cyber Security Risks, identify potential exposures, and present recommendations that are practical, realistic, and achievable.• Implemented risk management framework (CRAMM) and other information security frameworks, principles, methodologies, standards and practices.• Conduct research to aid in the threat risk assessment / privacy impact assessment of company operations, projects, and IT systems and Information Assets.• Review on regular basis enterprise IT controls and procedures, and recommend measures to eliminate or mitigate risks and weaknesses.• Provide consultation to internal stakeholders and project managers, consistently determined to ensure that adherence to security/risk management policies and procedures is built into project deliverables.
  • Ogero
    Senior System Engineer
    Ogero Jan 1998 - May 2005
    Beirut, Lb
    • Prepared project documents (e.g., business case, feasibility study, detailed budget submission, briefing notes, executive summaries) and utilizing project management tools for planning and implementing complex projects and/or packages.• Managed 3rd party security solution providers, conducted / supported IT investigations and breaches (forensics, log analysis), worked with law enforcement and/or regulatory bodies, supervised and coached internal business and technical team members• Provided advise on emerging architectures, technologies or products such as government services reference models, business intelligence/data warehousing, e-service, quality assurance tools, and enterprise content management. • Executed projects in Business Intelligence/Data warehousing modeling, and implementation, e-service design, Content Management and archiving.• Supervised staff and contracted resources, reported work assignment progress against budget and assessed performance on a project basis,• Participated in security committee and developed procedures and policies for e-mail usage, internet usage, user creation/deletion, security controls, and disaster recovery,• Deployed URL filtering -Websense- as an attack countermeasure on Web browsing to minimize security threats,• Configured Switches and Routers, Windows Servers, Unix Solaris, Security threat and attack resolution, • Managed project in all stages (Business case, Planning, …., Commissioning) of complex business strategy and information management projects, costing resources and critical path identification in large, diversified environment, and experienced in using MS Project software.
  • Khatib & Alami
    Systems Admininstrator
    Khatib & Alami 1996 - 1998
    Downtown, Singapore, Sg

Iyad Abou Hawili Skills

Smart Cards Information Security Windows Server Digital Rights Management Amazon Web Services Active Directory Infrastructure Multi Factor Authentication Cyber Defense Microsoft Azure Security Architecture Design Computer Security Office 365 Security Nist Secure Sdlc Cloud Security Dlp Virtualization Identity And Access Management Web Application Security Operations Management U.s. Federal Information Security Management Act Network Security Risk Management Mobile Application Security Federated Identity Management Aws Glba Web Application Firewall Information Security Management Maturity Models Vapt Information Security Governance Network Architecture Iso 27001 Payment Card Industry Data Security Standard Cryptography Ffiec Servers Akamai Pki Pipeda

Iyad Abou Hawili Education Details

  • Royal Holloway, University Of London
    Royal Holloway, University Of London
    Information Secuirty
  • Heriot-Watt University
    Heriot-Watt University
    General
  • Lebanese American University
    Lebanese American University
    Computer

Frequently Asked Questions about Iyad Abou Hawili

What company does Iyad Abou Hawili work for?

Iyad Abou Hawili works for Sara-It (Security Advisory Research Audit)

What is Iyad Abou Hawili's role at the current company?

Iyad Abou Hawili's current role is Cyber Security Solutions Architect.

What is Iyad Abou Hawili's email address?

Iyad Abou Hawili's email address is iy****@****cae.com

What schools did Iyad Abou Hawili attend?

Iyad Abou Hawili attended Royal Holloway, University Of London, Heriot-Watt University, Lebanese American University.

What skills is Iyad Abou Hawili known for?

Iyad Abou Hawili has skills like Smart Cards, Information Security, Windows Server, Digital Rights Management, Amazon Web Services, Active Directory, Infrastructure, Multi Factor Authentication, Cyber Defense, Microsoft Azure, Security Architecture Design, Computer Security.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.