Summary
Overview
Work History
Education
Skills
Certification
Additional Information
Hobbies and Interests
Languages
Timeline
Generic
FARNAZALSADAT GHAVAMI

FARNAZALSADAT GHAVAMI

Tehran,Iran,

Summary

Senior security expert with more than 13 years’ experience in varied organizations in financial and banking industry. Experienced in security areas such as analyzing, designing, planning, implementing and auditing. Capable of balancing between security controls and business needs. Successful in implementing and fine tuning security tools. Enthusiastic about new standards and best practices as well as growing technologies within defense in-depth approach.

Overview

15
15
years of professional experience
1
1
Certification

Work History

Senior Security Engineer

Middleeast Bank
06.2022 - Current
  • Providing cross-departmental guidance and collaboration on cyber security policies and procedures
  • Implementing and maintaining security solutions to consistently robust organization's security architecture
  • Conducting regular internal audits of IT infrastructure, ensuring compliance with industry standards and regulatory requirements

Senior Security Engineer

Negah Bank Co
06.2021 - 06.2022


  • Implemented necessary controls and procedures to protect information system assets from unauthorized access
  • Collaborated with cross-functional teams to align security protocols and policies with business objectives


Information Security Engineer

Karafarin Bank
06.2009 - 06.2021
  • Providing guidance on information security governance including policies, processes, controls, roles and responsibilities
  • Developed comprehensive information security policies and procedures ensuring compliance with industry standards and regulations
  • Contributed to the design and implementation of incident response plan within Security Operation Center (SOC)
  • Conducted vulnerability assessments to identify potential risks within the organization''s infrastructure
  • Enhanced network security by implementing intrusion detection and prevention systems and web application firewalls
  • Coordinated with third-party security information and event management (SIEM) providers to maintain protections and predict threats
  • Implemented and maintained security monitoring tools to ensure the availability of security within an organization

Education

Master of IT Engineering- Computer Networks -

Qazvin Azad University
Qazvin, Iran
09.2012

Bachelor of IT Engineering -

Parand Azad University
Tehran, Iran
09.2008

Skills

  • Network Security: WALLIX (privileged Access Manager), Fortiweb and Profense (Web Application Firewall), Juniper (Intrusion Detection and Prevention System)
  • Network Forensic: Wireshark, TCPdump, OmniPeek
  • Vulnerability Assessment: Tenable Nessus, Nmap, IP360
  • Penetration Testing: BackTrack 5, Samurai
  • Performance Monitoring: HP OpenView, Manage Engine
  • Application Manager: OpenNMS, PRTG, SolarWinds
  • security logging: LogZilla, Manage Engine Event Manager, AlienVault OSSIM, Snare, splunk
  • Hypervisor: VMware ESX
  • Ticketing system: ManageEngine Service Desk
  • Operating Systems: Linux Redhat , Microsoft Windows Server
  • Frameworks & standards: COBIT, ITILL, ISMS (ISO 27001)
  • Programming languages: python (basic level)

Certification

  • Microsoft Network +, KahkeshanNoor Educational Institute, 2009
  • CISCO CCNA, KahkeshanNoor Educational Institute, 2011
  • Payment Card Industry Data Security Standard, Applied Information Development Institute, 2012
  • ITIL version3 Foundation, EXIN institute, Self-study, 2012
  • ISMS/ ISO27001 Internal Auditor, KahkeshanNoor Educational Institute,2012
  • Certified Ethical Hacker (CEH), KahkeshanNoor Educational Institute, 2012
  • Information Security Management Systems (ISMS) Lead Auditor, TUV Nord, 2013
  • ATM Security Best Practice, NISICT, 2013
  • PCI & PA DSS Foundation, NISICT, 2014
  • Preventing Fraud and Financial Abuses, 4th Annual Conference, 2014
  • Certified Information Systems Auditor (CISA), KahkeshanNoor Educational Institute, 2014

Additional Information


  • Efficient time management
  • Willingness to learn
  • Flexibility
  • Team leadership
  • Reliability


Hobbies and Interests

  • Yoga
  • Photography
  • Painting - Watercolor

Languages

Persian
Native or Bilingual
English
Professional Working
German
Limited Working

Timeline

Senior Security Engineer

Middleeast Bank
06.2022 - Current

Senior Security Engineer

Negah Bank Co
06.2021 - 06.2022

Information Security Engineer

Karafarin Bank
06.2009 - 06.2021

Master of IT Engineering- Computer Networks -

Qazvin Azad University

Bachelor of IT Engineering -

Parand Azad University
  • Microsoft Network +, KahkeshanNoor Educational Institute, 2009
  • CISCO CCNA, KahkeshanNoor Educational Institute, 2011
  • Payment Card Industry Data Security Standard, Applied Information Development Institute, 2012
  • ITIL version3 Foundation, EXIN institute, Self-study, 2012
  • ISMS/ ISO27001 Internal Auditor, KahkeshanNoor Educational Institute,2012
  • Certified Ethical Hacker (CEH), KahkeshanNoor Educational Institute, 2012
  • Information Security Management Systems (ISMS) Lead Auditor, TUV Nord, 2013
  • ATM Security Best Practice, NISICT, 2013
  • PCI & PA DSS Foundation, NISICT, 2014
  • Preventing Fraud and Financial Abuses, 4th Annual Conference, 2014
  • Certified Information Systems Auditor (CISA), KahkeshanNoor Educational Institute, 2014
FARNAZALSADAT GHAVAMI