Summary
Overview
Work History
Skills
Timeline
Generic

Muhammad Farooq Khan

Chicago,IL

Summary

I am an experienced information & cybersecurity leadership professional, a program manager, and risk advisor with about 16 years of experience working with both local and international businesses. I am skilled at developing successful cybersecurity programs from scratch to maturity that deliver measurable results against business objectives. Areas of my focus include: Information Security & Privacy Compliance Management Technical Vulnerability Management Vendor Risk Management (Third Party Risk Management) Security & Privacy Awareness Program Management Incident Response Management

Overview

16
16
years of professional experience

Work History

Manager Information Security & Compliance

Zones LLC
Chicago, IL
06.2017 - Current

Key Achievements:

  • Information Security & Privacy Information Management Systems (ISMS & PIMS) for ISO 27001 & 27701, SOC 2, and PCI-DSS certifications
  • Established a technical vulnerability management program to identify, report, and help in remediation of security vulnerabilities on an ongoing basis
  • Established and led a Business Information Security program that provides advisory services to leaders from Sales, Marketing, Legal, HR & Operations
  • Set up and led a global Security Operations Center (SOC)
  • Established & led a "Third Party Risk Management (TPRM)" program to facilitate responses to RFQ/RFP, Vendor onboarding, external audits & contractual compliance
  • Established a privacy working group to address various global and state regulations (GDPR, CCPA/CPRA notably)

General responsibilities:

  • Developing a cybersecurity strategy to address business security, contractual, legal, and regulatory requirements
  • Developing and implementing a threat prevention, detection, response, and incident recovery program
  • Evaluating and identifying potential cyber threats and vulnerabilities, and work with internal teams to mitigate risks appropriately
  • Developing and ensuring implementation of organizational policies, procedures, and standards that align with industry standards and regulations
  • Overseeing the security operations center (SOC), including reviews of the runbook, creation of playbooks, and incident response coordination
  • Working closely with the Legal team to review customer and service provider contracts, agreements, and interpret technical jargon for them to provide accurate legal response to the risk situations
  • Becoming a single authoritative point of contact for internal and external customers and auditors for providing appropriate risk responses
  • Establish credibility as a trusted advisor to stakeholders including executives, peers, and employees.

Program Manager

InfoSec Consulting, EnPointe Technologies, Ovex / PCM Inc
08.2013 - 06.2017
  • As the Program Manager Information Security, I lead a team of experienced consultants and specialists to deliver professional services in following areas:
  • Vulnerability Assessment & Penetration Testing (Web application & Infrastructure)
  • Vendor solutions (Firewall, SIEM, End-point-protection, web gateway, Email messaging security etc.)
  • Compliance based on ISO 27001:2013, FedRAMP (NIST 800-53 Rev4)
  • FedRAMP for Collab9, a subsidiary of EnPointe Inc.

Senior Consultant Information Security

INFOGISTIC Pvt Ltd
10.2012 - 08.2013
  • Completed several vulnerability assessment and penetration testing assignments for network infrastructure & web applications
  • Developed information security policies and procedures for the implementation of an effective ISMS based on the requirements of ISO/IEC 27001
  • Deliver professional trainings for CISSP, CISA, CISM and Ethical Hacking and Penetration Testing (Hands-on) 3-5 days training with extensive lab exercises

Asst Manager Network Security

Warid Telecom
05.2011 - 10.2012
  • Monitored systems for indications of threats, security breaches or intrusions.
  • Provided technical support related to security product installation and use.
  • Maintained documentation of security and disaster recovery policies and procedures.
  • Investigated information security breaches to identify vulnerabilities and evaluate damage.
  • Directed vulnerability assessments or analysis of information security systems.

Team Lead Risk Management & Policy Compliance

Mobilink GSM
11.2009 - 05.2011
  • Documented and reported on key risks and recommended mitigation strategies.
  • Developed and documented risk management systems.
  • Monitored risk assessments and assessed validity using industry-specific methods.

Sr. Information Security Consultant/Engineer

Netsol Technologies Ltd
09.2007 - 10.2009
  • Performed network, application, system and mobile penetration testing across company's product suite.
  • Delivered recommendations for enhancements to IT security environments to prevent successful attacks.
  • Communicated findings and strategy to stakeholders, technical staff and executive leadership.

Skills

  • Certified Information System Security Professional (CISSP # 305273)
  • Certified in Risk and Information Systems Control (CRISC # 2130550)
  • Certified Information Systems Auditor (CISA # 12102504)
  • Certified Information Security Manager (CISM # 1220365)
  • SANS GIAC Certified Penetration Tester - 2008 through 2021 (GPEN # 1013)

Timeline

Manager Information Security & Compliance

Zones LLC
06.2017 - Current

Program Manager

InfoSec Consulting, EnPointe Technologies, Ovex / PCM Inc
08.2013 - 06.2017

Senior Consultant Information Security

INFOGISTIC Pvt Ltd
10.2012 - 08.2013

Asst Manager Network Security

Warid Telecom
05.2011 - 10.2012

Team Lead Risk Management & Policy Compliance

Mobilink GSM
11.2009 - 05.2011

Sr. Information Security Consultant/Engineer

Netsol Technologies Ltd
09.2007 - 10.2009
Muhammad Farooq Khan