Delivering SAMA CSF/MVC/CTI, NCA ECC/DCC, and ITGC assessments for financial, government, and defense-sector clients including Aramco Digital, American Express, and IMCTC
I am an IT Risk Advisory Consultant at Dr. Mohamed Al-Amri & Co. (BDO), based in Riyadh, Saudi Arabia. I deliver risk-based compliance engagements for some of Saudi Arabia's most high-profile organizations — including Aramco Digital, American Express (AESA), Saudi Public Security, and IMCTC — spanning SAMA CSF/MVC/CTI, NCA ECC/DCC, and ITGC frameworks.
My work includes producing Risk & Control Matrices (RCMs), leading audit walkthroughs, identifying risk owners, coordinating stakeholder meetings, and authoring 40+ bilingual cybersecurity policy and procedure documents. I specialize in translating complex regulatory requirements into actionable compliance roadmaps that organizations can actually follow.
I combine deep GRC expertise with a strong technical foundation in software development, penetration testing, and AI-assisted tooling — including a live GRC Automation Platform I built to accelerate policy drafting and control mapping. My academic background combines computer science with cybersecurity specialization and criminal justice, providing a comprehensive perspective on digital security challenges.
Hands-on training for the next generation of security professionals
Conducting risk-based compliance engagements for major Saudi entities across financial, telecom, and energy sectors.
Delivered end-to-end GRC engagements for high-profile financial, government, and military clients across Saudi Arabia.
Cybersecurity Specialization · Criminal Justice Minor · GPA: 3.1/4.0
My research focuses on the intersection of cybersecurity, digital forensics, and criminal justice, aiming to develop more effective methods for investigating and preventing cybercrime.
This research explores the challenges law enforcement faces when investigating ransomware attacks that utilize cryptocurrency payments. The study proposes a framework for tracking cryptocurrency transactions while maintaining legal compliance with chain-of-custody requirements for digital evidence.
Read MoreThis research examines the practical challenges of implementing post-quantum cryptographic algorithms in critical infrastructure systems. The study analyzes potential security vulnerabilities during transitional periods and proposes a risk mitigation framework.
Read MoreThis research explores how the advent of quantum computing will transform digital evidence collection, preservation, and presentation in court. The paper discusses the legal and technical considerations for ensuring the admissibility of digital evidence in a post-quantum cryptographic environment.
Read MoreA selection of personal and professional projects demonstrating my technical skills and practical application of cybersecurity and GRC knowledge.
Built an AI-assisted platform to automate policy drafting, control mapping, and compliance gap analysis workflows — integrating compliance logic for SAMA, NCA ECC/DCC, ISO 27001, and NIST CSF frameworks. Significantly reduces manual documentation effort for GRC engagements.
Developed an educational platform with 20+ interactive cybersecurity simulations covering SOC analyst training, penetration testing labs, and vulnerability assessment techniques. Includes compliance framework guides for NIST CSF, ISO 27001, CIS Controls, and OWASP. Built with Django backend, React frontend, and Docker deployment.
Full-stack AI-powered job application platform using Django, React, and PostgreSQL with intelligent job matching achieving 90%+ accuracy using BERT-based NLP models. Deployed with Docker, SSL/TLS encryption, automated CI/CD pipeline, 85%+ test coverage, JWT authentication, and OWASP Top 10 mitigations.
Developed a comprehensive digital forensic toolkit that automates the collection and analysis of volatile and non-volatile data from compromised systems. Incorporates chain-of-custody documentation to ensure evidence admissibility in legal proceedings.
Professional certifications and technical skills that complement my academic qualifications and practical experience.
Google (via Coursera)
Comprehensive cybersecurity program covering security fundamentals, risk management, network security, Linux/SQL, incident detection and response, and Python automation.
Completed: April 17, 2025
CompTIA
Industry-standard certification covering network security, compliance, threats, vulnerabilities, access control, and cryptography.
In Progress
EC-Council
Certification covering penetration testing methodologies, attack vectors, hacking tools, and ethical hacking techniques.
In Progress
Google (via Coursera)
Mastery of cybersecurity fundamentals, security frameworks, and core security concepts.
Completed: April 17, 2025
Google (via Coursera)
Proficiency in Linux operating system and SQL database security techniques.
Completed: April 17, 2025
Google (via Coursera)
Skills in security incident detection, analysis, and effective response procedures.
Completed: April 17, 2025
Google (via Coursera)
Proficiency in developing Python scripts for security automation and analysis.
Completed: April 17, 2025
Technical Skills
SAMA CSF / MVC / CTI, NCA ECC / DCC / CCC, ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, CST CRF
Technical Skills
Splunk, QRadar (SIEM), Metasploit, Burp Suite, Wireshark, Nmap, OWASP Top 10, MITRE ATT&CK
Technical Skills
Python, JavaScript/TypeScript, Django, React, Docker, Kubernetes, AWS, PostgreSQL, REST APIs
I'm open to research collaborations, cybersecurity consulting opportunities, and career conversations in GRC, IT risk, and SOC.
azizcsecj@gmail.com
+966 50 *** ****
Riyadh, Saudi Arabia
aziz707.info