Muhammad Eissa / Abu Dhabi, UAE
Regulatory IT audit.
Cybersecurity assurance.
I lead regulatory IT audit and cybersecurity assurance across healthcare, banking, and financial services. My 11+ years span ADHICS V2 audits, banking assurance, national financial supervision, and hands-on SOC leadership.
PDF · 31 August 2026
11+Years across audit and cybersecurity
14+Financial institution assessments and audits
400+Incident-response cases led
01 / SELECTED WORK
Experience. Made tangible.
BANKING / ASSURANCE
Independent assurance, audit findings management, and clearer risk reporting across a banking environment.
30% reduction in audit findings.
Read case study ↗SECURITY OPERATIONS / LEADERSHIP
SOC strategy, response playbooks, and team development grounded in operational incident handling.
400+ incident-response cases led.
Read case study ↗DETECTION ENGINEERING / SIEM
End-to-end SIEM deployments and detection use cases for enterprise security operations.
50% improvement in event detection.
Read case study ↗May 2026 — Present
ADHICS Auditor
Emirates Classification Society (TASNEEF) · Abu Dhabi, UAE
Conduct ADHICS V2 audits across Abu Dhabi, Al Ain, and Al Dhafra, covering governance and technical controls at the applicable Basic, Transitional, and Advanced tiers. Lead scoping, walkthroughs, evidence validation, control testing, closing meetings, and reporting. Advise CIOs, CISOs, and compliance officers on regulatory exposure and prioritized remediation.
Responsibilities & achievements
- Audit healthcare entities across Abu Dhabi, Al Ain, and Al Dhafra against ADHICS V2, covering Section A governance and Section B technical control requirements at the applicable Basic, Transitional, and Advanced tiers.
- Run engagements end to end: scoping and entity classification, audit planning, documentation review, physical and virtual walkthroughs, evidence validation, control testing, closing meetings, and report issuance.
- Assess controls spanning IT governance, risk management, asset and access management, health information and EMR security, third-party and cloud-hosted services, backup and recovery, incident management, and business continuity.
- Advise CIOs, CISOs, and compliance officers on remediation, translating control deficiencies into regulatory exposure and prioritized corrective action plans.
May 2025 — Jan 2026
Head of Information Security Compliance & Assurance
ADIB (Abu Dhabi Islamic Bank) · Abu Dhabi, UAE · Contract engagement
Led enterprise compliance governance aligned to CBUAE ISR, ISO 27001, PCI DSS, and NIST standards. Provided independent second-line assurance and maintained the Information Security Assurance Framework. Reduced audit findings by 30% and improved risk-reporting timeliness by 40%.
Responsibilities & achievements
- Led enterprise-wide information security compliance governance aligned to CBUAE ISR, ISO 27001, PCI DSS, and NIST standards.
- Reduced audit findings by 30% and improved risk-reporting timeliness by 40% across the assurance function.
- Acted as second line of defense, providing independent assurance over security controls and risk treatment decisions.
- Coordinated internal and external security audits and gap analyses, managing the findings lifecycle and corrective action plans through to closure.
- Maintained the Information Security Assurance Framework covering all critical systems and business units.
- Reviewed implemented security configurations across enterprise platforms, identifying gaps and driving corrective action with platform owners.
May 2024 — Apr 2025
Security Operations Center (SOC) Manager
Klivvr · Cairo, Egypt
Led 400+ incident response cases and a team of up to seven L1–L3 specialists. Rebuilt response playbooks to cut incident resolution time by 30% and reduced MTTR by 35% through SOC strategy and SLA governance. Tuned Sentinel, Splunk, and SOAR with threat intelligence to reduce false positives by 30%.
Responsibilities & achievements
- Led 400+ incident response cases, cutting incident resolution time by 30% through rebuilt response playbooks.
- Reduced MTTR by 35% by defining SOC strategy, operating model, and SLA governance.
- Managed and mentored a team of up to 7 SOC specialists across L1–L3, setting shift models, performance KPIs, and escalation paths.
- Deployed and tuned Microsoft Sentinel, Splunk, and SOAR platforms, integrating threat intelligence to reduce false positives by 30%.
Mar 2020 — Nov 2023
IT Risk & Cybersecurity Auditor (GRC)
Central Bank of Egypt · Cairo, Egypt
Led 14+ IT risk assessments and audits of financial institutions against CBE regulations, PCI DSS, and ISO 27001. Designed a national cybersecurity audit toolkit that improved audit efficiency by approximately 30%. Assessed third-party risk and issued executive reports guiding remediation and regulatory decisions.
Responsibilities & achievements
- Led 14+ IT risk assessments and audits of Egypt’s top financial institutions against CBE regulations, PCI DSS, and ISO 27001.
- Designed a standardized national cybersecurity audit program and toolkit for financial institution reviews, improving audit efficiency by approximately 30%.
- Developed and enforced policies aligning national IT operations with NIST, ISO 27001, and PCI DSS.
- Assessed IT infrastructure, security architecture, and control effectiveness, identifying vulnerabilities and prioritizing remediation based on regulatory risk.
- Conducted third-party vendor risk assessments to secure the national financial supply chain.
- Issued executive audit reports influencing remediation priorities and regulatory decisions.
Mar 2017 — Dec 2019
Senior Cybersecurity Analyst
Liquid C2 MENA (formerly SecureMisr) · Cairo, Egypt
Delivered enterprise SIEM deployments, log integrations, and MITRE ATT&CK-aligned detection use cases, improving event detection by 50% and reducing false positives by 35%. Led threat hunting and incident investigations, and established a cybersecurity services line that increased revenue by 20%.
Responsibilities & achievements
- Delivered end-to-end SIEM deployments (log onboarding, use case development) for enterprise clients, improving event detection by 50% and reducing false positives by 35%.
- Led threat hunting and incident investigations across enterprise environments to mitigate APT activity.
- Established a new professional cybersecurity services line, driving a 20% revenue increase.
- Built log source integrations and detection use cases mapped to the MITRE ATT&CK framework.
Sep 2015 — Feb 2017
Network Security Engineer
Sinai University · North Sinai, Egypt
Designed security infrastructure across three campuses and migrated edge firewalls to next-generation platforms. Extended authenticated access coverage by 60% through NAC and Active Directory integration. Improved data transfer efficiency by 35% with VPNs and WAN optimization.
Responsibilities & achievements
- Designed and implemented security infrastructure across 3 campuses, integrating firewalls, IDS/IPS, and SIEM, and migrating edge firewalls to next-generation platforms.
- Implemented Network Access Control (NAC) integrated with Active Directory, extending authenticated access coverage by 60%.
- Deployed site-to-site VPNs and WAN optimization across branch sites, increasing data transfer efficiency by 35%, and automated device hardening and configuration reviews.
03 / EXPERTISE
Technical depth. Independent perspective.
01Regulatory Audit & Assurance
Regulatory assurance across healthcare, banking, and financial services.
Explore capabilities +
- ADHICS V2: governance & technical controls
- CBUAE ISR, NESA & CBE regulations
- ISO 27001, NIST CSF, PCI DSS & SOC 2
- Privacy requirements & regulatory exposure
02Healthcare Cybersecurity Audit
End-to-end ADHICS V2 audits of healthcare entities across Abu Dhabi, Al Ain, and Al Dhafra.
Explore capabilities +
- Entity classification & risk-based scoping
- Basic, Transitional & Advanced tiers
- Health information & EMR security
- Evidence validation & remediation planning
03IT & Information Security Audit
Risk-based planning, control testing, and findings management across critical systems.
Explore capabilities +
- IT general controls (ITGC)
- Application & core banking audits
- Evidence management & executive reporting
- TeamMate & ACL
04IT Risk & Controls
Risk assessments and assurance that connect control deficiencies to business and regulatory priorities.
Explore capabilities +
- Enterprise & third-party risk assessments
- Control design & effectiveness testing
- Remediation governance & closure
- Executive & board reporting
05Security Operations & Response
Hands-on SOC leadership, detection engineering, and incident response.
Explore capabilities +
- SOC operating models, SLAs & KPIs
- Threat hunting & MITRE ATT&CK
- Incident response & cyber crisis management
- Tabletop exercises & team mentoring
06Technology Assurance
Security reviews grounded in enterprise engineering and operations.
Explore capabilities +
- SIEM/SOAR, EDR/NDR & vulnerability management
- Azure, AWS & GCP security
- Network security & secure-by-design reviews
- Backup, recovery & business continuity
Tools & technical skills +
ADHICS V2CBUAE ISRNESAISO 27001NIST CSFPCI DSSTeamMateACLMicrosoft SentinelSplunkIBM QRadarKQL / SPL / AQLSOAREDR / NDRVulnerability managementFortiGate / Palo Alto / Cisco ASAAzure / AWS / GCPPython / Bash / PowerShellDocker / KubernetesAnsible / TerraformCI/CD securityDigital forensicsSOC leadership & mentoring
04 / ABOUT
Security with a business purpose.
My work connects hands-on security engineering with independent assurance. I help organizations understand control gaps, prioritize remediation, and communicate risk clearly.
As founder of ESLabs Academy, I provide Arabic-language cybersecurity training and mentoring for the MENA security community.
ISACA and ISC2 memberships · ISC2 Exam Development Volunteer · Fast Company Middle East — Cybersecurity Subcommittee.
Languages: Arabic (native) · English (fluent).
05 / CREDENTIALS
Learning that supports practice.
Certifications and training listed in my CV dated 31 August 2026
Governance, risk and audit
CISSPISC2CISAISACACRISCISACAPCIPPCI SSCDecember 2025 – December 2028BCMEBIIT Risk ControlsRisk Rewards Limited Defensive operations
GCIHGIACGMONGIACSC-200MicrosoftCEHEC-CouncilATT&CK FoundationsAttackIQFSEFireEye Systems EngineerHP ATPArcSight Security V1 Architecture and networks
SC-100MicrosoftCCNP SecurityCiscoCCNA CyberOpsCiscoCCNA SecurityCisco EDUCATION
Professional Diploma — Network & Systems Security
Ministry of Communications and IT, Egypt · November 2013 – June 2014
924 academic training hours; CCNA R&S, CCNA Security, and MCSA 2012 academic certifications.
Bachelor of Science — Computer Science
Future Academy · Cairo, Egypt · September 2009 – May 2013
06 / ELEVATED SECURITY LABS
Founder, ESLabs Academy
The education arm of Elevated Security Labs. Arabic-language cybersecurity training and mentoring that connects technical knowledge with practical experience.
Visit ESLabs Academy ↗es_ACADEMY