a
abdelghanem

Abdel G

@abdelghanem

Will create ISO 27001 security policies, risk assessments and GRC documentation

Canada
Arabic
About me
I am an Information Security Officer in a government security role with a strong background in cybersecurity analysis and cloud security engineering. I bring technical expertise in Nikto, Wireshark, and Kali Linux, complemented by several industry-standard certifications. My experience spans public sector security, business analysis, and software development, including backend development in Java and Azure-based system provisioning. I offer both security/GRC documentation services and software development and testing support.... Read more

Skills

a
abdelghanem
Abdel G
Offline • 
Average response time: 1 hour

See my services

Programming & Tech
I will create iso 27001 security policies and risk assessment documents
Legal Documents & Review
I will write your privacy policy, terms of service, and nda

Portfolio

Work experience

Government_of Canada

Information Security Officer

Government of Canada • Full-time

Jan 2025 - Present1 yr 7 mos

Conduct Business Impact Analyses (BIAs) and Threat Risk Assessments (TRAs), including vulnerability scanning and penetration testing, to identify security risks and support audit and compliance initiatives. Manage the end-to-end vulnerability lifecycle using Tenable by documenting findings, coordinating remediation with infrastructure teams, and producing security posture reports using Python. Design and enforce IAM policies and security controls across Azure multi-subscription environments while monitoring policy compliance, identifying configuration exceptions, and supporting the organization's overall cloud security posture.

University_of Alberta

Business Analyst

University of Alberta • Part-time

Sep 2024 - Dec 20243 mos

Investigated security-related issues using tools such as Tenable, Nikto, and Wireshark to identify vulnerabilities across enterprise systems and document remediation recommendations. Supported risk assessments and incident response activities by working closely with infrastructure teams to track remediation efforts, communicate findings to stakeholders, and improve the organization's security posture.