About

I audit the controls organisations bet on. I spent fifteen years building them first.

Today I lead IT and Information Security Internal Audit at Emirates Post Group (7X). Before that, I ran security programs in the UAE banking and financial sector: SIEM and SOC, PCI DSS, ISO 27001, UAE IA. I know where controls bend under pressure because I built them under pressure. That makes my findings sharper and my fixes workable.

Approach

Evidence before opinion

A control is only as good as the proof that it operated. I start with what can be shown, trace how the process actually runs against how it was designed, and write observations that a control owner can act on the same week. Most control failures are not new; they are familiar gaps in a new system.

  • Risk based IT and security audit planning, from audit universe to Audit Committee reporting
  • Cloud, identity and Microsoft 365 control assurance
  • Change, release and service management controls
  • Security monitoring, incident response and resilience
  • Third party and vendor risk
  • Repeatable, AI assisted audit workflows a whole team can reuse
ISO 27001PCI DSSNIST CSF COBITUAE IACIS BenchmarksITIL
20 years across security and assurance in the UAE

Career

  1. 2024 to now

    Manager Internal Audit - IT and Information Security

    7X, Emirates Post Group · Dubai

    Lead audit delivery for 7X and its subsidiary EDC across cloud infrastructure, ITSM, Microsoft 365, security monitoring and resilience. Report on control posture to the Audit Committee and track remediation to closure.

  2. 2021 to 2024

    Manager, Information Technology and Security

    Mensa Technologies · Dubai

    Ran the security program for a Huawei Cloud hosted environment: UAE IA and ISO 27001 alignment, SIEM operations, incident management, PCI DSS compliance and security awareness.

  3. 2009 to 2021

    System Administrator to Assistant Manager, Information Security

    Commercial Bank International · Dubai

    Wrote the bank's first security policy set, deployed QRadar SIEM and Guardium, led PCI DSS to first time certification, managed the MSSP SOC and supported Central Bank examinations and ISO 27001 surveillance audits.

  4. 2005 to 2009

    Security Engineer

    Getronics Middle East · IT Butler e‑Services

    Implemented ISO 27001 ISMS for organisations in the UAE and Pakistan, designed SOC capability and performed penetration testing and code review for finance and government clients.

Selected work

What I have built and assured

Audit

Technology audit coverage

Engagements across cloud infrastructure, change and release management, digital workplace, security monitoring, and business continuity and disaster recovery.

Audit

IT and security audit universe

Building a risk assessed universe of auditable technology areas that drives the annual plan instead of last year's habits.

Practice

Audit workflows built for reuse

Standardised observation writing, AI assisted engagement workflows and Power Query tracking dashboards, designed so any team member produces consistent work.

Security

Banking security foundations

First policy framework, SIEM, database activity monitoring, DLP and PAM, and first time PCI DSS certification at a UAE bank.

Articles

Writing

October 2026 · 7 minute read

Internal Audit in the Age of AI

AI changes how fast we can test controls. It does not change what assurance means. Three shifts every audit function now faces, and what stays human.

Read article
Credentials

Certifications

CISSP badgeCISSPCertified Information Systems Security Professional · ISC2
CISM badgeCISMCertified Information Security Manager · ISACA
CISA badgeCISACertified Information Systems Auditor · ISACA

BSc Computer Science

Contact

Let's talk

I am glad to hear from audit and security leaders, regulators, conference organisers and anyone working on making assurance more useful. Email is the fastest way to reach me: .

Profile current as of October 2026Dubai, UAE