Delivering SAMA CSF/MVC/CTI, NCA ECC/DCC, and ITGC assessments for financial, government, and defense-sector clients including Aramco Digital, American Express, and IMCTC
I am an IT and Information Security Senior Consultant at ECOVIS Saudi Arabia (ECOVIS AL SABTI), based in Riyadh, Saudi Arabia. I deliver risk-based compliance engagements for some of Saudi Arabia's most high-profile organizations, including Aramco Digital, American Express (AESA), Saudi Public Security, and IMCTC. Spanning SAMA CSF/MVC/CTI, NCA ECC/DCC, and ITGC frameworks.
My work includes producing Risk & Control Matrices (RCMs), leading audit walkthroughs, identifying risk owners, coordinating stakeholder meetings, and authoring 40+ bilingual cybersecurity policy and procedure documents. I specialize in translating complex regulatory requirements into actionable compliance roadmaps that organizations can actually follow.
I combine deep GRC expertise with a strong technical foundation in software development, penetration testing, and AI-assisted tooling, including a live GRC Automation Platform I built to accelerate policy drafting and control mapping. My academic background combines computer science with cybersecurity specialization and criminal justice, providing a comprehensive perspective on digital security challenges.
Live GRC automation, SOC simulations, penetration testing labs, and hands-on security challenges — built on real frameworks used in production environments.
Conducting risk-based compliance engagements for major Saudi entities across financial, telecom, and energy sectors.
Conducting risk-based compliance engagements for major Saudi entities across financial, telecom, and energy sectors.
Delivered end-to-end GRC engagements for high-profile financial, government, and military clients across Saudi Arabia.
Cybersecurity Specialization · Criminal Justice Minor · GPA: 3.1/4.0
My research focuses on the intersection of cybersecurity, digital forensics, and criminal justice, aiming to develop more effective methods for investigating and preventing cybercrime.
Benchmarks the NIST post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) against classical algorithms on an Apple M2 Pro, and calculates the cost of post-quantum message sizes on industrial protocols such as DNP3 and Modbus. It finds that on capable hardware the main obstacles are bandwidth and embedded firmware trust anchors, not computation, and maps a migration roadmap onto NCA and SAMA frameworks. All results are reproducible from the included data and scripts.
Read MoreReviews how post-quantum cryptography changes digital forensics and examines the implications for digital evidence under Saudi Arabia's Law of Evidence (2022) and Anti-Cyber Crime Law. Includes a small reproducible experiment showing that ML-KEM secret keys remain recoverable from process memory during use but not after secure erasure, illustrating why live forensics matters in the post-quantum era.
Read MoreReviews how ransomware operations use cryptocurrency for payment and laundering, the blockchain-tracing techniques used to investigate them, and the resulting criminal-justice challenges. Grounded in public cases such as the 2021 Colonial Pipeline seizure and in published on-chain data, with a regional section on Saudi Arabia and the GCC.
Read MoreA selection of personal and professional projects demonstrating my technical skills and practical application of cybersecurity and GRC knowledge.
Built an AI-assisted platform to automate policy drafting, control mapping, and compliance gap analysis workflows — integrating compliance logic for SAMA, NCA ECC/DCC, ISO 27001, and NIST CSF frameworks. Significantly reduces manual documentation effort for GRC engagements.
Developed an educational platform with 20+ interactive cybersecurity simulations covering SOC analyst training, penetration testing labs, and vulnerability assessment techniques. Includes compliance framework guides for NIST CSF, ISO 27001, CIS Controls, and OWASP. Built with Django backend, React frontend, and Docker deployment.
Full-stack AI-powered job application platform using Django, React, and PostgreSQL with intelligent job matching achieving 90%+ accuracy using BERT-based NLP models. Deployed with Docker, SSL/TLS encryption, automated CI/CD pipeline, 85%+ test coverage, JWT authentication, and OWASP Top 10 mitigations.
Developed a comprehensive digital forensic toolkit that automates the collection and analysis of volatile and non-volatile data from compromised systems. Incorporates chain-of-custody documentation to ensure evidence admissibility in legal proceedings.
Professional certifications and technical skills that complement my academic qualifications and practical experience.
Google (via Coursera)
Comprehensive cybersecurity program covering security fundamentals, risk management, network security, Linux/SQL, incident detection and response, and Python automation.
Completed: April 17, 2025
CompTIA
Industry-standard certification covering network security, compliance, threats, vulnerabilities, access control, and cryptography.
In Progress
EC-Council
Certification covering penetration testing methodologies, attack vectors, hacking tools, and ethical hacking techniques.
In Progress
Google (via Coursera)
Mastery of cybersecurity fundamentals, security frameworks, and core security concepts.
Completed: April 17, 2025
Google (via Coursera)
Proficiency in Linux operating system and SQL database security techniques.
Completed: April 17, 2025
Google (via Coursera)
Skills in security incident detection, analysis, and effective response procedures.
Completed: April 17, 2025
Google (via Coursera)
Proficiency in developing Python scripts for security automation and analysis.
Completed: April 17, 2025
Technical Skills
SAMA CSF / MVC / CTI, NCA ECC / DCC / CCC, ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, CST CRF
Technical Skills
Splunk, QRadar (SIEM), Metasploit, Burp Suite, Wireshark, Nmap, OWASP Top 10, MITRE ATT&CK
Technical Skills
Python, JavaScript/TypeScript, Django, React, Docker, Kubernetes, AWS, PostgreSQL, REST APIs