Technology audit coverage
Engagements across cloud infrastructure, change and release management, digital workplace, security monitoring, and business continuity and disaster recovery.
I audit the controls organisations bet on. I spent fifteen years building them first.
Today I lead IT and Information Security Internal Audit at Emirates Post Group (7X). Before that, I ran security programs in the UAE banking and financial sector: SIEM and SOC, PCI DSS, ISO 27001, UAE IA. I know where controls bend under pressure because I built them under pressure. That makes my findings sharper and my fixes workable.
A control is only as good as the proof that it operated. I start with what can be shown, trace how the process actually runs against how it was designed, and write observations that a control owner can act on the same week. Most control failures are not new; they are familiar gaps in a new system.
Lead audit delivery for 7X and its subsidiary EDC across cloud infrastructure, ITSM, Microsoft 365, security monitoring and resilience. Report on control posture to the Audit Committee and track remediation to closure.
Ran the security program for a Huawei Cloud hosted environment: UAE IA and ISO 27001 alignment, SIEM operations, incident management, PCI DSS compliance and security awareness.
Wrote the bank's first security policy set, deployed QRadar SIEM and Guardium, led PCI DSS to first time certification, managed the MSSP SOC and supported Central Bank examinations and ISO 27001 surveillance audits.
Implemented ISO 27001 ISMS for organisations in the UAE and Pakistan, designed SOC capability and performed penetration testing and code review for finance and government clients.
Engagements across cloud infrastructure, change and release management, digital workplace, security monitoring, and business continuity and disaster recovery.
Building a risk assessed universe of auditable technology areas that drives the annual plan instead of last year's habits.
Standardised observation writing, AI assisted engagement workflows and Power Query tracking dashboards, designed so any team member produces consistent work.
First policy framework, SIEM, database activity monitoring, DLP and PAM, and first time PCI DSS certification at a UAE bank.
AI changes how fast we can test controls. It does not change what assurance means. Three shifts every audit function now faces, and what stays human.
Read articleBSc Computer Science
I am glad to hear from audit and security leaders, regulators, conference organisers and anyone working on making assurance more useful. Email is the fastest way to reach me: asimminhas@gmail.com.