me↗Get in touch ↗

Muhammad Eissa / Abu Dhabi, UAE

Regulatory IT audit.
Cybersecurity assurance.

I lead regulatory IT audit and cybersecurity assurance across healthcare, banking, and financial services. My 11+ years span ADHICS V2 audits, banking assurance, national financial supervision, and hands-on SOC leadership.

PDF · 31 August 2026

11+

Years across audit and cybersecurity

14+

Financial institution assessments and audits

400+

Incident-response cases led

01 / SELECTED WORK

Experience. Made tangible.

02 / EXPERIENCE

A career across controls and operations.

Download the full CV ↓
May 2026 — Present

ADHICS Auditor

Emirates Classification Society (TASNEEF) · Abu Dhabi, UAE

Conduct ADHICS V2 audits across Abu Dhabi, Al Ain, and Al Dhafra, covering governance and technical controls at the applicable Basic, Transitional, and Advanced tiers. Lead scoping, walkthroughs, evidence validation, control testing, closing meetings, and reporting. Advise CIOs, CISOs, and compliance officers on regulatory exposure and prioritized remediation.

Responsibilities & achievements
  • Audit healthcare entities across Abu Dhabi, Al Ain, and Al Dhafra against ADHICS V2, covering Section A governance and Section B technical control requirements at the applicable Basic, Transitional, and Advanced tiers.
  • Run engagements end to end: scoping and entity classification, audit planning, documentation review, physical and virtual walkthroughs, evidence validation, control testing, closing meetings, and report issuance.
  • Assess controls spanning IT governance, risk management, asset and access management, health information and EMR security, third-party and cloud-hosted services, backup and recovery, incident management, and business continuity.
  • Advise CIOs, CISOs, and compliance officers on remediation, translating control deficiencies into regulatory exposure and prioritized corrective action plans.
May 2025 — Jan 2026

Head of Information Security Compliance & Assurance

ADIB (Abu Dhabi Islamic Bank) · Abu Dhabi, UAE · Contract engagement

Led enterprise compliance governance aligned to CBUAE ISR, ISO 27001, PCI DSS, and NIST standards. Provided independent second-line assurance and maintained the Information Security Assurance Framework. Reduced audit findings by 30% and improved risk-reporting timeliness by 40%.

Responsibilities & achievements
  • Led enterprise-wide information security compliance governance aligned to CBUAE ISR, ISO 27001, PCI DSS, and NIST standards.
  • Reduced audit findings by 30% and improved risk-reporting timeliness by 40% across the assurance function.
  • Acted as second line of defense, providing independent assurance over security controls and risk treatment decisions.
  • Coordinated internal and external security audits and gap analyses, managing the findings lifecycle and corrective action plans through to closure.
  • Maintained the Information Security Assurance Framework covering all critical systems and business units.
  • Reviewed implemented security configurations across enterprise platforms, identifying gaps and driving corrective action with platform owners.
May 2024 — Apr 2025

Security Operations Center (SOC) Manager

Klivvr · Cairo, Egypt

Led 400+ incident response cases and a team of up to seven L1–L3 specialists. Rebuilt response playbooks to cut incident resolution time by 30% and reduced MTTR by 35% through SOC strategy and SLA governance. Tuned Sentinel, Splunk, and SOAR with threat intelligence to reduce false positives by 30%.

Responsibilities & achievements
  • Led 400+ incident response cases, cutting incident resolution time by 30% through rebuilt response playbooks.
  • Reduced MTTR by 35% by defining SOC strategy, operating model, and SLA governance.
  • Managed and mentored a team of up to 7 SOC specialists across L1–L3, setting shift models, performance KPIs, and escalation paths.
  • Deployed and tuned Microsoft Sentinel, Splunk, and SOAR platforms, integrating threat intelligence to reduce false positives by 30%.
Mar 2020 — Nov 2023

IT Risk & Cybersecurity Auditor (GRC)

Central Bank of Egypt · Cairo, Egypt

Led 14+ IT risk assessments and audits of financial institutions against CBE regulations, PCI DSS, and ISO 27001. Designed a national cybersecurity audit toolkit that improved audit efficiency by approximately 30%. Assessed third-party risk and issued executive reports guiding remediation and regulatory decisions.

Responsibilities & achievements
  • Led 14+ IT risk assessments and audits of Egypt’s top financial institutions against CBE regulations, PCI DSS, and ISO 27001.
  • Designed a standardized national cybersecurity audit program and toolkit for financial institution reviews, improving audit efficiency by approximately 30%.
  • Developed and enforced policies aligning national IT operations with NIST, ISO 27001, and PCI DSS.
  • Assessed IT infrastructure, security architecture, and control effectiveness, identifying vulnerabilities and prioritizing remediation based on regulatory risk.
  • Conducted third-party vendor risk assessments to secure the national financial supply chain.
  • Issued executive audit reports influencing remediation priorities and regulatory decisions.
Mar 2017 — Dec 2019

Senior Cybersecurity Analyst

Liquid C2 MENA (formerly SecureMisr) · Cairo, Egypt

Delivered enterprise SIEM deployments, log integrations, and MITRE ATT&CK-aligned detection use cases, improving event detection by 50% and reducing false positives by 35%. Led threat hunting and incident investigations, and established a cybersecurity services line that increased revenue by 20%.

Responsibilities & achievements
  • Delivered end-to-end SIEM deployments (log onboarding, use case development) for enterprise clients, improving event detection by 50% and reducing false positives by 35%.
  • Led threat hunting and incident investigations across enterprise environments to mitigate APT activity.
  • Established a new professional cybersecurity services line, driving a 20% revenue increase.
  • Built log source integrations and detection use cases mapped to the MITRE ATT&CK framework.
Sep 2015 — Feb 2017

Network Security Engineer

Sinai University · North Sinai, Egypt

Designed security infrastructure across three campuses and migrated edge firewalls to next-generation platforms. Extended authenticated access coverage by 60% through NAC and Active Directory integration. Improved data transfer efficiency by 35% with VPNs and WAN optimization.

Responsibilities & achievements
  • Designed and implemented security infrastructure across 3 campuses, integrating firewalls, IDS/IPS, and SIEM, and migrating edge firewalls to next-generation platforms.
  • Implemented Network Access Control (NAC) integrated with Active Directory, extending authenticated access coverage by 60%.
  • Deployed site-to-site VPNs and WAN optimization across branch sites, increasing data transfer efficiency by 35%, and automated device hardening and configuration reviews.

03 / EXPERTISE

Technical depth. Independent perspective.

01

Regulatory Audit & Assurance

Regulatory assurance across healthcare, banking, and financial services.

Explore capabilities +
  • ADHICS V2: governance & technical controls
  • CBUAE ISR, NESA & CBE regulations
  • ISO 27001, NIST CSF, PCI DSS & SOC 2
  • Privacy requirements & regulatory exposure
02

Healthcare Cybersecurity Audit

End-to-end ADHICS V2 audits of healthcare entities across Abu Dhabi, Al Ain, and Al Dhafra.

Explore capabilities +
  • Entity classification & risk-based scoping
  • Basic, Transitional & Advanced tiers
  • Health information & EMR security
  • Evidence validation & remediation planning
03

IT & Information Security Audit

Risk-based planning, control testing, and findings management across critical systems.

Explore capabilities +
  • IT general controls (ITGC)
  • Application & core banking audits
  • Evidence management & executive reporting
  • TeamMate & ACL
04

IT Risk & Controls

Risk assessments and assurance that connect control deficiencies to business and regulatory priorities.

Explore capabilities +
  • Enterprise & third-party risk assessments
  • Control design & effectiveness testing
  • Remediation governance & closure
  • Executive & board reporting
05

Security Operations & Response

Hands-on SOC leadership, detection engineering, and incident response.

Explore capabilities +
  • SOC operating models, SLAs & KPIs
  • Threat hunting & MITRE ATT&CK
  • Incident response & cyber crisis management
  • Tabletop exercises & team mentoring
06

Technology Assurance

Security reviews grounded in enterprise engineering and operations.

Explore capabilities +
  • SIEM/SOAR, EDR/NDR & vulnerability management
  • Azure, AWS & GCP security
  • Network security & secure-by-design reviews
  • Backup, recovery & business continuity
Tools & technical skills +
ADHICS V2CBUAE ISRNESAISO 27001NIST CSFPCI DSSTeamMateACLMicrosoft SentinelSplunkIBM QRadarKQL / SPL / AQLSOAREDR / NDRVulnerability managementFortiGate / Palo Alto / Cisco ASAAzure / AWS / GCPPython / Bash / PowerShellDocker / KubernetesAnsible / TerraformCI/CD securityDigital forensicsSOC leadership & mentoring

04 / ABOUT

Security with a business purpose.

My work connects hands-on security engineering with independent assurance. I help organizations understand control gaps, prioritize remediation, and communicate risk clearly.

As founder of ESLabs Academy, I provide Arabic-language cybersecurity training and mentoring for the MENA security community.

ISACA and ISC2 memberships · ISC2 Exam Development Volunteer · Fast Company Middle East — Cybersecurity Subcommittee. Languages: Arabic (native) · English (fluent).

05 / CREDENTIALS

Learning that supports practice.

Certifications and training listed in my CV dated 31 August 2026

Governance, risk and audit

CISSPISC2
CISAISACA
CRISCISACA
PCIPPCI SSCDecember 2025 – December 2028
BCMEBI
IT Risk ControlsRisk Rewards Limited

Defensive operations

GCIHGIAC
GMONGIAC
SC-200Microsoft
CEHEC-Council
ATT&CK FoundationsAttackIQ
FSEFireEye Systems Engineer
HP ATPArcSight Security V1

Architecture and networks

SC-100Microsoft
CCNP SecurityCisco
CCNA CyberOpsCisco
CCNA SecurityCisco

EDUCATION

Professional Diploma — Network & Systems Security

Ministry of Communications and IT, Egypt · November 2013 – June 2014

924 academic training hours; CCNA R&S, CCNA Security, and MCSA 2012 academic certifications.

Bachelor of Science — Computer Science

Future Academy · Cairo, Egypt · September 2009 – May 2013

06 / ELEVATED SECURITY LABS

Founder, ESLabs Academy

The education arm of Elevated Security Labs. Arabic-language cybersecurity training and mentoring that connects technical knowledge with practical experience.

Visit ESLabs Academy ↗

Talk audit, assurance, or cybersecurity education.

Get in touch ↗