Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic
OVAIS ABBAS

OVAIS ABBAS

Cyber Security
KARACHI

Summary

To pursue a career in a reputable Organization, offering professional environment and opportunity for career development where I can use my knowledge and skills, contributing towards the corporate objectives of the organization.

Overview

10
10
years of professional experience
9
9
years of post-secondary education
7
7
Certifications

Work History

AM IT Security BPS-17

NICVD Hospital
Karachi
02.2023 - Current


  • Deployment and implementation of IT management and security products
  • Assist in design and delivery of security solutions and services into different companies
  • Recognizes Deploy and configuration of different types of security solutions for various clients (Kaspersky, Patch Management (Manage Engine),Solarwind, Metasploit, Nessus, Brupsuit)
  • Deployment of FIM, DLP, EDR, AV, PAM, Data classification, IT management (ManageEngine) projects

  • Work on NIST Fram work policies, controls, domains and standards
  • Works on IT risk and security initiatives/issues for one or more IT functional area (e.g., applications, systems, network and/or Web) across the enterprise
  • May participate in security planning and analyst activities
  • Monitors compliance with security policies, standards, guidelines and procedures
  • Assists in the development of processes and procedures for the information security governance program, including control document reviews, participant assessment preparation, meeting coordination, assessment finding mediation, assisting control owner with remediation plan development, tracking findings through remediation, progress monitoring, reporting, and escalation
  • Analyzes security analysis reports for security vulnerabilities and recommends feasible and appropriate options
  • Develops plans to achieve security requirements and address identified risks
  • Captures, maintains, and monitors information security risk
  • Checks existing accounts and data access permission requests against documented authorizations
  • Assists in the data classification process
  • Performs security monitoring and reporting, analyzes security alerts and escalates security alerts to local support teams
  • Identifies and resolves root causes of security-related problems
  • Responds to security incidents, conducts forensic investigations and targets reviews of suspect areas
  • Works with teams to resolve issues that are uncovered by various internal and third-party monitoring tools
  • Assists in the development and delivery of IT risk & security awareness and compliance training programs
  • Proven ability to develop and implement creative solutions to complex problems.

Team Lead

Access Group
Karachi
10.2021 - 02.2023


  • Worked on File integrity monitoring(FIM) Tripwire.
  • Worked on Thalis two factor authentication-2FA.
  • Worked on Thycotic/Centrify Privilege Access Management (PAM).
  • Worked on Ivanti Patch Management project.
  • OT Security.
  • Deployment of Logpoint SIEM
  • Worked on Data Leak Prevention (DLP), Data classification.

Tech Specialist

Risk Associates, National Bank, TPS
Karachi
07.2019 - 09.2021

· Deployment and implementation of IT management and security products for several organization.

· Assist in design and delivery of security solutions and services into different companies.

· Recognizes Deploy and configuration of different types of security solutions for various clients (Blackberry, Manage Engine, E-safe, Titania, NNT, Cimtrak, PaloAlto, Solarwind).

· Deployment of FIM, DLP, EPP, EDR, AV, Nipper, PAM, Data classification, IT management (ManageEngine) projects

· Managed certification and compliance with the Payment Card Industry (PCI) Data Security Standard (DSS) for numerous companies.

· Managed the team to identify the security risks relating to PCI DSS. Provided guidance on PCI DSS requirements. Enabled and assisted internal business units to build and maintain PCI certified systems and infrastructure

· Managed certification and compliance with Payment Application (PA) Data Security Standard (DSS) for numerous companies.

· Work on ISO27001 policies, controls, domains and standards.

· Prepared RFP response for various companies

· Prepared Project plan, scope of work, Proof of concept guide, Technical Proposal documents for different organization.

· Works on IT risk and security initiatives/issues for one or more IT functional area (e.g., applications, systems, network and/or Web) across the enterprise.

· Develops security solutions for low to medium complex assignments. · Works on multiple projects as a team member and leads systems related security components.

· May participate in security planning and analyst activities

· Develops, refines, and implements enterprise-wide security policies, procedures, and standards to meet compliance responsibilities.

· Supports service-level agreements (SLAs) to ensure that security controls are managed and maintained.

· Monitors compliance with security policies, standards, guidelines and procedures.

· Assists in the development of processes and procedures for the information security governance program, including control document reviews, participant assessment preparation, meeting coordination, assessment finding mediation, assisting control owner with remediation plan development, tracking findings through remediation, progress monitoring, reporting, and escalation

· Analyzes security analysis reports for security vulnerabilities and recommends feasible and appropriate options.

· Develops plans to achieve security requirements and address identified risks.

· Captures, maintains, and monitors information security risk.

· Checks existing accounts and data access permission requests against documented authorizations.

· Assists in the data classification process.

· Performs security monitoring and reporting, analyzes security alerts and escalates security alerts to local support teams.

· Identifies and resolves root causes of security-related problems.

· Responds to security incidents, conducts forensic investigations and targets reviews of suspect areas.

· Works with teams to resolve issues that are uncovered by various internal and third-party monitoring tools.

· Assists in the development and delivery of IT risk & security awareness and compliance training programs.

· Collaborates on projects to ensure that security issues are addressed throughout the project life cycle.

· Informs stakeholders about compliance and security-related issues and activities affecting the assigned area or project.


Data Center Engineer OG-II

United Bank Limited UBL
Karachi
05.2015 - 05.2019

· Deploy and Implementation of Orion Platform 2015.1.2 i.e., Solarwind Network Performance Monitor 11.5.2, Orion Server and Application Monitor 6.2.1, Network Configuration Manager 7.4, Network Traffic Analyzer 4.1.0

· Administrate LANCOPE LAN monitoring tool.

· Actively monitoring of Core Devices & provide first level support as well as inform to concerns

· Developed efficient procedures for testing, monitoring, reporting and evaluates equipment to ensure no downtime for teams.

· Health check of power and cooling infrastructure of mission critical site.

· Contribute with product managers and other business leaders to coordinate projects, manage capacity and optimize performance, reliability and efficiency.

· Maximize performance; creating / updating documentation of Operating procedures, incident, back-up, and recovery procedures

· Plan and execute data center engineering activities in emergency situations.

· Manage all maintenance contractors, vendors, suppliers and contract renewals relevant to Data Center.

· Operate and Manage both routine and emergency service on a variety of state-of-the-art critical systems such as: UPS, power distribution equipment, LT panels, HVAC (CRAC units), fire detection/suppression; monitoring systems; etc.

· Facilitate technology architecture support for various platform including SAN, NAS, LAN, WAN, Backup & DR-Site.

· Provide first level support for branches, core links, LAN and live & test servers

· Administration of the enterprise infrastructure monitoring application (APC ISX Central, DCE 7.5); proactive review of operational logs to identify service issues.

· Maintaining an enterprise Tier-III data center with specific experience in large footprint environment, banking/business continuity solutions of financial institution

Technology Consultant

Ciphertronix
Karachi
02.2013 - 05.2015
  • Installation & configuration of Windows & Linux based servers
  • Install and configure Asterisk, Elastix & Trixbox Based System
  • Installation, Commissioning & Troubleshooting IP Phone, Quintums
  • Installation, Commissioning & Troubleshooting perform on FXS Gateway
  • Configured and maintained existing Linux servers and backups
  • Lookup Network monitoring tools ntop, Cacti, NMS, Nagious, voip monitoring tool etc
  • Interact with vendor for time-to-time issues
  • Lookup Network issues related to the severs & VoIP Telephony, FXS Gateways, Linux & Computer
  • Ability to adapt to any environment and gain the required knowledge in short time
  • To address critical issues in the areas of System by reporting to upper management

Projects:

  • Working in NIB Bank Head Office and provide VoIP services to approximately 1000 users at a time
  • Configure Cisco, Grand stream & VoIP FXS Gateways & IP Phones
  • Lookup all issues related to Asterisk server
  • Lookup all telephonic and VoIP Telephony issues
  • Attended calls related to customer queries and complaints, offered solutions

Education

Master of Science - MSCS Network And Information

Muhammad Ali Jinnah University
Karachi, Pakistan
01.2015 - 12.2019

Bachelor of Science - Telecommunications

Indus University
Karachi, Pakistan
01.2009 - 12.2012

Skills

File Integrity Monitoring

undefined

Certification

Certified Information Security Manager

Timeline

AM IT Security BPS-17

NICVD Hospital
02.2023 - Current

Certified Information Security Manager

03-2022

Team Lead

Access Group
10.2021 - 02.2023

Privilege Access Management

08-2021

ISO 27001 Training

01-2021

File Integrity Monitoring

11-2020

Data Leak Protection

11-2020

Cylance Security Professional EDR/EPP

11-2020

Paloalto System Engineer

01-2020

Tech Specialist

Risk Associates, National Bank, TPS
07.2019 - 09.2021

Data Center Engineer OG-II

United Bank Limited UBL
05.2015 - 05.2019

Master of Science - MSCS Network And Information

Muhammad Ali Jinnah University
01.2015 - 12.2019

Technology Consultant

Ciphertronix
02.2013 - 05.2015

Bachelor of Science - Telecommunications

Indus University
01.2009 - 12.2012
OVAIS ABBASCyber Security