M. A. Ghafoor

Senior GRC Consultant/Lead Auditor

Overview

Confidently able to handle implementation, Compliance, and Governance /Internal Audits, Certification Audits, and training of ISMS (ISO 27001), (Local CS Frameworks, SAMA CSF, NCA CS controls) and other international standards like PCI-DSS, NIST, COBIT, GDPR, and other standards.

I have more than 20 years in Telecom, operations, and project management.I have served strategically in the leading Pakistan telecom industry players, including multinational organizations.

Relevant Experience
        • Led the independent I.T. controls and security assessments to provide maturity and benchmarking against international standards.
        • Implemented ISO 27001 in various organizations within KSA.
        • Implemented Regulatory Frameworks (NCA, SAMA & and NDMO) for various organizations.
        • Performed Compliance assessments against the Regulatory Requirements (SAMA CSF & NCA)
        • Managed NCA AND SAMA CSF and implementation projects for many organizations, including but not limited to NIC, SAR, IPA, NEOM, Amlak Intl, etc.

 

Certifications

          • ISO 27001: Senior Lead Implementer
          • ISO 27001: Lead Auditor
          • CISM: Certified Information Security Manager
          • CISA: Certified Information Systems Auditor.
          • ITIL: ITIL 4 Foundation