asim@minhas:~$ whoami
STATUS: ASSURED
Portrait of Muhammad Asim Minhas
// IT Audit · Information Security · Assurance · Dubai, UAE

Muhammad Asim Minhas

> assurance_for("cloud")

I audit the controls organisations bet on. I spent fifteen years building them first.

Today I lead IT and Information Security Internal Audit at Emirates Post Group (7X). Before that, I ran security programs in the UAE banking and financial sector: SIEM and SOC, PCI DSS, ISO 27001, UAE IA. I know where controls bend under pressure because I built them under pressure. That makes my findings sharper and my fixes workable.

Manager Internal Audit - IT and Information Security · Emirates Post Group (7X)
linkedin ↗
years_in_assurance20+Years in security and assurance
certifications3Global certifications
organisations_uae5Organisations across the UAE
frameworks_applied7Control frameworks applied
$ tail now.log · updated October 2026

What I am up to

now.log
[build]PG Query Studio, a personal tool that connects to PostgreSQL, keeps the schema at hand and helps build queries visually and with AI.
[explore]Workflow automation with n8n, and where it can take the repetitive work out of assurance.
[write]Short pieces on audit, security and AI. Latest: Shadow AI: The Data Leak Nobody Approved.
$ cat approach.md

Evidence before opinion

A control is only as good as the proof that it operated. I start with what can be shown, trace how the process actually runs against how it was designed, and write observations that a control owner can act on the same week. Most control failures are not new; they are familiar gaps in a new system.

  • Risk based IT and security audit, from planning to reporting
  • Cloud, identity and Microsoft 365 control assurance
  • Change, release and service management controls
  • Security monitoring, incident response and resilience
  • Third party and vendor risk
  • Repeatable, AI assisted audit workflows a whole team can reuse
ISO 27001PCI DSSNIST CSFCOBITUAE IACIS BenchmarksITIL
$ git log --career --oneline · 20 years across the UAE

Career

  1. 2024 → now

    Manager Internal Audit - IT and Information Security

    7X, Emirates Post Group · Dubai

    Lead risk based IT and information security internal audit, providing independent assurance on technology and security controls.

  2. 2021 → 2024

    Manager, Information Technology and Security

    Mensa Technologies · Dubai

    Ran the security program for a Huawei Cloud hosted environment: UAE IA and ISO 27001 alignment, SIEM operations, incident management, PCI DSS compliance and security awareness.

  3. 2009 → 2021

    System Administrator to Assistant Manager, Information Security

    Commercial Bank International · Dubai

    Wrote the bank's first security policy set, deployed QRadar SIEM and Guardium, led PCI DSS to first time certification, managed the MSSP SOC and supported Central Bank examinations and ISO 27001 surveillance audits.

  4. 2005 → 2009

    Security Engineer

    Getronics Middle East · IT Butler e‑Services

    Implemented ISO 27001 ISMS for organisations in the UAE and Pakistan, designed SOC capability and performed penetration testing and code review for finance and government clients.

$ ls ./expertise

What I bring

ASSURANCE

IT and security audit

Risk based assurance over cloud, identity, change and service management, security operations and resilience.

SECURITY

Security program leadership

Fifteen years building security programs: policy frameworks, SIEM and SOC, DLP and PAM, and PCI DSS and ISO 27001 certification.

GOVERNANCE

Frameworks and compliance

Practical alignment to ISO 27001, PCI DSS, NIST CSF, COBIT and UAE Information Assurance standards.

PRACTICE

Modern audit methods

A strong interest in data analytics, automation and responsible use of AI to make assurance faster and more consistent.

$ ls -t ./articles | head -2

Writing

view_all_articles →
$ ./run ai-readiness-check

Is your audit function AI ready?

QUICK CHECK · 6 QUESTIONS · 2 MINUTES

AI readiness check for internal audit

Answer six questions and get a live readiness score with practical priorities. Private: nothing is stored or sent.

start_check →
$ verify --credentials

Certifications

CISSP badge
CISSPCertified Information Systems Security Professional · ISC2
✓ verified on Credly
CISM badge
CISMCertified Information Security Manager · ISACA
✓ verified on Credly
CISA badge
CISACertified Information Systems Auditor · ISACA
✓ verified on Credly

BSc Computer Science

$ ping asim

Let's talk

I am glad to hear from audit and security leaders, regulators, conference organisers and anyone working on making assurance more useful. Email is the fastest way to reach me: .

This is a personal website. Views expressed here are my own and do not represent my employer.

profile current as of October 2026Dubai, UAEcolour of the week: Cyan