
Muhammad Waqas
Information Security Manager
Compétences

Voir mes services

Portfolio
Expérience professionnelle
Information Governance Lead
Language Empire • Temps plein
Nov 2023 - Present • 2 yrs 9 mos
Responsible for developing, implementing and continually improving the organisation’s information governance and cybersecurity framework in alignment with ISO 27001, GDPR and Cyber Essentials. Led the transition of the Information Security Management System from ISO 27001:2013 to ISO 27001:2022. This included reviewing the ISMS scope, updating the risk assessment and treatment methodology, revising the Statement of Applicability, developing policies and procedures, assessing control implementation and preparing the organisation for certification audits. Developed and implemented policies covering information security, risk management, access control, asset management, data protection, cloud security, network security, system hardening, vulnerability management, threat intelligence, incident response, disaster recovery and business continuity. Worked with control owners and relevant stakeholders to implement security requirements, collect compliance evidence and ensure that organisational information and associated assets were appropriately protected. Organised and conducted incident-response, disaster-recovery and business-continuity exercises to evaluate organisational preparedness and improve cyber resilience. Conducted internal ISMS audits to identify control gaps and improvement opportunities, documented findings, supported corrective actions and represented management during external certification activities. Led GDPR and data-protection improvement work by identifying compliance gaps, developing GDPR and data-retention policies, establishing data-subject access procedures and integrating privacy requirements into operational processes. Managed information-security, data-protection, quality and GDPR responses for client tenders and supplier-assurance questionnaires.
Information Security Officer
Arc Inventador • Temps plein
Jan 2019 - Oct 2023 • 4 yrs 9 mos
Developed and implemented the organization’s Information Security Management System in accordance with ISO 27001 and the NIST Cybersecurity Framework. Implemented security controls to protect the confidentiality, integrity and availability of information systems, networks and organisational assets. Conducted internal ISMS audits and coordinated the external certification audit.