Sherif Abouelwafa
Cybersecurity Advisor
****************@*****.*** +20-122******* Cairo, Egypt
EDUCATION
Master of Business Administration June 2010
University of Massachusetts, United States of America.
M.Sc. in Computer Science June 2004
University of Massachusetts, United States of America.
B.Sc. in Computer Science and Automatic Control June 1984
Faculty of Engineering – Ain Shams University, Cairo, Egypt.
CERTIFICATIONS
Certified in the Governance of Enterprise IT (CGEIT) June 2011
Information Systems Audit and Control Association (ISACA)
Certified Information Security Manager (CISM) Dec 2009
Information Systems Audit and Control Association (ISACA)
SUMMARY
Cybersecurity and IT Governance Advisor strengthening enterprise security postures. Developing resilient cybersecurity strategies that align with business goals, designing advanced cybersecurity architectures and solutions based on the best practices, latest industry trends and technologies, and conducting risk identification, assessment, and mitigation.
Possesses broad technical and business Knowledge, gained through experience with multinational corporations and industry leaders, across diverse business sectors, including Information Technology, Banking, Oil & Gas, Petrochemicals, Telecommunications, Manufacturing, Construction, Logistics, Healthcare, Government, and other large-scale enterprises.
Managing the development and implementation of IT governance frameworks, including information security organizational structures, roles and responsibilities, policies and procedures, incident response plans, business continuity strategies, KPIs and KRIs.
Planning and leading the development and execution of risk-based Information Systems Audit Plans that are aligned with organizational strategy and business objectives.
Directing the development and implementation of IT strategies, design of distributed and scalable information system architectures that enhance the efficiency and effectiveness of IT services and processes.
Holds an M.Sc. in Computer Science, Master of Business Administration from the University of Massachusetts – USA, and Certified Information Security Manager (CISM) and Certified in Governance of Enterprise IT (CGEIT) certifications.
Cybersecurity Instructor delivering professional training program for CISM, CGEIT, CISSP, CRISC, CISA certifications and Cybersecurity, IT GRC and IT Risk Courses / Workshops.
CORE COMPETENCIES
•Information Security Strategy
•Enterprise Security Architecture
•IT Governance, Risk and Compliance
•Cybersecurity Maturity Assessment
•IT Risk Management
•Business Continuity
•Disaster Recovery Plan
•Incident Response
•IS Audit
•Security Policies and Procedures
•Security Operations
•Project Management
TECHNICAL SKILLS AND FRAMEWORKS
•ISO 27001
•ISO 22301
•NIST
•PCI-DSS
•COBIT
•GDPR
•SAMA
•NCA
•NDMO
EXPERIENCE
Cybersecurity Advisor Feb 2023 – Present
Zinad IT – Dubai, United Arab of Emirates
Managing the development of cybersecurity strategies, designing cybersecurity architecture and solutions, conducting risk identification, assessment, and mitigation strategies for Banks and large enterprises.
Leading the development of IT governance framework, information security organization structure, roles and responsibilities, policies and procedures, incident response plan and business continuity, KPIs and KRIs based on best practices and international standards and regulations (ISO 27001, ISO22301, PCI-DSS, NIST, GDPR and Sarbanes-Oxley) and Saudi regulations (SAMA, NCA, NDMO) and Egyptian regulations (Central Bank of Egypt, Egyptian Financial Regulatory Authority).
Plan, direct and lead the development and implementation of Risk-based IS Audit Plan.
Projects
Jeddah Chamber of Commerce - Kingdom of Saudi Arabia
Makkah Region development Authority - Kingdom of Saudi Arabia
DP Wolrd - Kingdom of Saudi Arabia
Alinma Bank - Kingdom of Saudi Arabia
Cybersecurity and IT GRC Instructor (Part Time) Feb 2023 – Present
CAMPUS Education Institution
The courses are the following :
Certified in Governance of Enterprise IT (CGEIT)
Certified Information Security Manager (CISM)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Systems Auditor (CISA)
Cybersecurity, IT GRC and IT Risk Courses / Workshops
Senior Corporate IT Governance Manager Jan 2015 – Jan 2023
Orascom Construction Industries Corporate, Egypt
Head of IT Governance, Reporting to the VP of IT & HR at Orascom Construction Industries Corporate
Managing the developing and implementation of Cybersecurity Strategy, cybersecurity architecture and solutions, IT Governance, Information Security controls, policies and procedures.
Implementing Risk Management including security reviews, risk analysis, risk assessment, evaluation, selection and implementation of Security technologies.
Plan, direct and lead the development and implementation of Risk-Based IS Audit Plan.
Senior Corporate Application Manager Jan 2010 - Dec 2014
Orascom Construction Industries Corporate/ Orascom Fertilizer Corporate (Fertiglobe Now), USA, UAE, Egypt
Managing the development of IS Strategy, Designing Information System Architecture for the Corporate and subsidiaries :
oOrascom Fertilizer Corporate, USA, UAE
oEgyptian Fertilizer Company - Egypt
oSorfert Fertilizer - Algeria
Leading the Development and implementation of Information Security controls, policies and procedures.
Managing and implementing IT projects at the corporate and subsidiaries as ORACLE ERP, SAP ERP, Maximo EAM, Hyperion Enterprise Performance Management, HR Projects, Inventory and others.
Following up contracts and projects developments, ensuring support for the operational systems and applications.
Corporate Application Manager Jan 2005 - Dec 2009
Orascom Construction Industries Corporate, Egypt
Managing the Development of IS Strategy, Designing Information System Architecture for the Corporate and subsidiaries :
oOrascom cement (Lafarge Now)
oEgyptian Cement Company
Leading the Development and implementation of Information Security controls, policies and procedures based on International standards
Managing and implementing IT projects at the corporate and subsidiaries as ORACLE ERP, SAP ERP, Maximo EAM, Hyperion Enterprise Performance Management, HR Projects, Inventory and others.
Following up contracts and projects developments, ensuring support for the operational systems and applications.
IT Operation Manager Nov 2002 - Dec 2004
Orascom Construction Industries Corporate, Egypt
Managing the Development of IS Strategy, Designing Information Systems Architecture for the Corporate and subsidiaries.
Leading the Development Information Security Strategy and Architecture and implementation of IS controls, policies and procedures based on International standards
Managing and implementing IT projects at the corporate and subsidiaries as ORACLE ERP, SAP ERP, Maximo EAM, Hyperion Enterprise Performance Management, HR Projects, Inventory, Infrastructure, Network, Security & IP telephony and others.
Following up contracts and projects developments, system and network administration, ensuring support for the operational systems and applications.
Deputy IT Group Manager June 2000 – Oct 2002
AMIRAL Management Corporation (Dubai Ports - Sokhna now), Egypt
Managing the development of IS Strategy, Designing the Information System Architecture for the Corporate.
Managing and implementing Corporate IT projects as Oracle Financials project and Security/System Management project for establishing the Network Infrastructure for the Corporate, as well implementing Internet, Mail and security system for the corporate.
Developing Cybersecurity Strategy and Information Security Architecture, and implementing Information Security controls, policies and procedures based on International standards.
Following up contracts and projects developments, system and network administration and ensuring support for the operational applications.
Project Manager/Senior System Analyst June 1994 - May 2000
UNISYS – AGE, Dubai,U.A.E
Managing and implementing Banking Projects
oNational Bank of Dubai – United Arab of Emirates
oEmirates Bank International Limited - United Arab of Emirates
oInvestBank - United Arab of Emirates
Leading a team for the analysis, design and implementation of Banking Applications, Oracle ERP and providing technical support for the applications.
Project Manager/Analyst June 1991 - May 1994
DIGITAL – NATCOM, Kingdom of Saudi Arabia
Software Engineer Nov 1990 - May 1991
BECHTEL– Egypt
Software Engineer June 1989 - Oct 1990
Kuwait Electrical Wiring & Accessories Co (MK Middle East), Kuwait
Software Engineer Sept 1986 – May 1989
Amria Spinning and Weaving Co., Egypt
Telecommunication Engineer Mar 1985 – Aug 1986
Gulf of Suez Petroleum Co. (GUPCO), Egypt
COURSES
Introduction to Deep Learning for Computer Vision- Michigan State University
Certified in Risk and Information Systems Control (CRISC)
Application Security in DevSecOps
ISO 27001:2022 Compliance
Static Application Testing
Dynamic Application Testing
MITRE ATT&CK Framework
Penetration Testing for Cybersecurity Professional
Threat Modeling for Cybersecurity Professional
DevSecOps Foundations
OWASP Top 10
Cloud Concepts, Architecture and Design
Six Sigma Foundations
Penetration Test
Microsoft Security, Compliance, and Identity Fundamentals
Threat Modeling
Design Thinking –Stanford University
Building an ISO 27001 Compliant Cybersecurity Program
Implementing the NIST Risk Management Framework
Digital Business Model Framework
Agile Software Development : Scrum Framework
Cloud Architecture Design
Six Sigma Foundations
The Open Group Architecture Framework (TOGAF)
Certified Information Systems Security Professional (CISSP)
Certified in the Governance of Enterprise IT (CGEIT)
Balanced Scorecard
Certified Information Systems Manager (CISM)
Information Technology Infrastructure Library Foundation (ITIL)
Professional Management Professionals (PMP)
Certified Information Systems Auditor (CISA)