IT and security audit
Risk based assurance over cloud, identity, change and service management, security operations and resilience.

> assurance_for("cloud")
I audit the controls organisations bet on. I spent fifteen years building them first.
Today I lead IT and Information Security Internal Audit at Emirates Post Group (7X). Before that, I ran security programs in the UAE banking and financial sector: SIEM and SOC, PCI DSS, ISO 27001, UAE IA. I know where controls bend under pressure because I built them under pressure. That makes my findings sharper and my fixes workable.
A control is only as good as the proof that it operated. I start with what can be shown, trace how the process actually runs against how it was designed, and write observations that a control owner can act on the same week. Most control failures are not new; they are familiar gaps in a new system.
Lead risk based IT and information security internal audit, providing independent assurance on technology and security controls.
Ran the security program for a Huawei Cloud hosted environment: UAE IA and ISO 27001 alignment, SIEM operations, incident management, PCI DSS compliance and security awareness.
Wrote the bank's first security policy set, deployed QRadar SIEM and Guardium, led PCI DSS to first time certification, managed the MSSP SOC and supported Central Bank examinations and ISO 27001 surveillance audits.
Implemented ISO 27001 ISMS for organisations in the UAE and Pakistan, designed SOC capability and performed penetration testing and code review for finance and government clients.
Risk based assurance over cloud, identity, change and service management, security operations and resilience.
Fifteen years building security programs: policy frameworks, SIEM and SOC, DLP and PAM, and PCI DSS and ISO 27001 certification.
Practical alignment to ISO 27001, PCI DSS, NIST CSF, COBIT and UAE Information Assurance standards.
A strong interest in data analytics, automation and responsible use of AI to make assurance faster and more consistent.
Answer six questions and get a live readiness score with practical priorities. Private: nothing is stored or sent.
start_check →BSc Computer Science
I am glad to hear from audit and security leaders, regulators, conference organisers and anyone working on making assurance more useful. Email is the fastest way to reach me: asimminhas@gmail.com.
This is a personal website. Views expressed here are my own and do not represent my employer.