FlowCV Logo
Furqan SheikhInformation Security Consultant
[email protected] +966591905064 P.O.Box 79791- Al Khobar 31952 https://www.linkedin.com/in/furqan-sheikh-b3070416

Self-driven and accomplished Information Security Professional, having a strong motivation and extensive 12+ years of experience in conducting security assessments, internal/external security audits, and effectively managing projects within the Oil & Gas industry. Demonstrated expertise in translating strategic plans into practical solutions, monitoring performance to achieve operational goals, and fostering success in challenging environments

Career History
2015 – present
Information Security Consultant, Ejada Systems Limited
2012 – 2015
Security Engineer, Ejada Systems Limited
2011 – 2012
Service & Solution Professional, Gulf Net Solutions
Skills
• Information Security Awareness Training
• Establish Security Policies & Procedures
• Vulnerability and Threat Management
• Security Compliance Audit
• Project Management & Execution
• Application and Security Log Data Analysis
•ISO 27001 Audit
• Technical & Commercial Proposal Writing
Certificates
Certificate of Cloud Security Knowledge v.4
PECB: ISO 27001:2013 Information Security Management System Training
(ISC)²: Certified in Cybersecurity
PMI- Project Management Professional ( Pursuing)
Projects
Name :AGOC IT Professional Technical Consultancy & Support Services

Client: AGOC Saudi Arabia

Role: Information Security Consultant/Project Manager

Task & Responsibilities:

  • Identify and define requirements, scope, and objectives
  • Successfully managed offsite team members, ensuring project tasks were assigned and deadlines were met
  • Monitor project progress, handling any arising issues and ensuring AGOC's SLAs were met
  • Was primary point of contact, providing regular project status updates to all stakeholders
  • Conducted regular meetings with AGOC for status and incident updates
  • Participated with Client for purchase and PoC of various security technologies such as NexGen Data Center Firewall Devices and Microsoft Security & CISCO networking solutions
  • Communicated budgetary quotations to the customer and participated in the bidding process
  • Prepared and submitted commercial and technical proposals to the customer
  • Managed PS from OEM vendor for appliance configuration & deployment
  • Managed the invoicing process to close the project
  • Handled implementation issues with respective internal and external providers
  • Name: Ejada CCC Certification for Aramco (SAC-002)

    Client: Aramco Saudi Arabia

    Role: Information Security Consultant/Lead Auditor

    Task & Responsibilities:

  • Planning of internal audit with internal team for roles and responsibilities.
  • Collecting evidence for control specified in Saudi Aramco (SAC-002)
  • Performed closing the non-conformities found during audit.
  • Reporting audit finding and project progress to management
  • Implemented network and endpoint security controls including antivirus and access controls
  • Guided IT Team to effectively manage incident and patch management processes
  • Ensured external auditor limits advice within the applicable SAC-002 control statements
  • ISO27001 Certification

    Client: Datacenter - Ejada Systems Limited

    Role: Information Security Consultant/Internal Auditor/Implementer

    Task & Responsibilities

  • Executed audit activities, collected evidence based on ISO control objectives
  • Verified network security landscape within the SOA boundaries
  • Ensured controls are implemented as documented in ISO policy and procedure documents
  • Implemented Log-Review procedures for IT & Security teams
  • Deployed SIEM, OS Hardening and MFA technologies to reduce threat vector at the datacenter
  • Implemented forms for Physical and Logical access to Datacenter assets.
  • Participated in final internal audit before arrival of external auditor
  • Network Segregation for Aramco Developers

    Client: Ejada Eastern Province Branch Office

    Role: Information Security Consultant/Implementer

    Task & Responsibilities:

  • Designed and implemented network security controls for effectively segregating Ejada Developers’ Network supporting Aramco development projects as per ARAMCO SACS-002 Third Party Cybersecurity Standard
  • Implemented comprehensive Network Security/Endpoint Security using technologies such as:
  • o Antivirus, 2-Factor Authentication, OS Hardening

    o NexGen Firewall

    o Building separate Active Directory and Group Polices

    o Patch Management using WSUS server for windows systems.

    o Vulnerability Management of entire Network using Nessus Tool

  • SEIM solution to log network and security exceptions on all assets
  • Administrated Active Directory accounts as per Aramco policy
  • Implemented KSA NCA recommendations as applicable to this project
  • Resolve issues with Aramco Network team for VPN connectivity issues
  • Incident Management and share mitigation report with Aramco
  • Facilitated IT security audits by Aramco Team for Cybersecurity compliance
  • Incident Response Management and Response (MIR3)

    Client: Aramco

    Role: Information Security Consultant/Implementer

    Task & Responsibilities:

  • Gathering the requirement from client teams (Exchange, Telephony, SMS)
  • Coordinating with Telephony vendor to integrate client telephony within their application
  • Installing the MIR 3 application in client Environment with Vendor
  • Installed database for client to be used with the application in their environment
  • Troubleshooting issues encountered during the installation of MIR3 application
  • Installing the application for the failover server and testing failover scenarios
  • Onsite support for the project till the signoff.
  • Saudi Aramco Data Protection Framework Implementation Project, Information Security Engineer
  • Creating Risk Assessment Catalogue.
  • Creating information Asset inventory with the proponent.
  • Manage compliance and support ISO 27001.
  • Prepare and maintain information awareness material.
  • Conduct information security awareness programs on regular basis.
  • Conducting internal audits, reporting on areas of risk and preparing conclusion and recommendations for appropriate areas.
  • Creating templates to conduct Audit reviews etc.
  • Following up on audit recommendations to mitigate risk management.
  • Weekly meeting for enhancements in project operations.
  • Education
    2011
    Bachelor of Business and Information Technology, University Of Management and Technology Lahore, Pakistan
    2004
    Higher Secondary Education, Saudi Arabian International School (SAIS)
    2002
    Secondary Education, Saudi Arabian International School (SAIS)