Security and Governance expert with 15+ years of experience in a Fortune 500 multinational environment (MetLife), specializing in PCI DSS compliance, IT Risk Management, and Infrastructure Security. Certified CISM and PCI ISA, with deep expertise in bridging the gap between technical security controls (Azure, Guardium, WSUS) and regulatory frameworks. Proven track record in leading external audits, driving vulnerability remediation, and managing senior stakeholders globally.
PCI DSS, ISO 27001, IT Risk Management, Third-Party Risk Assessment (TPRM).
Microsoft Azure (AZ-900), Sentinel (SIEM), Defender for Cloud, VMware ESXi.
Vulnerability Management (WSUS, EDR), Database Security (IBM Guardium).
AI use-policy mapping, Model risk considerations, Prompt injection risks.
Internal/External Audit Leadership, Gap Analysis, Evidence Remediation.
root@refat:~/skills# view_details
"Operate as the Regional Subject Matter Expert (SME) for Information Security Governance, orchestrating defense strategies for enterprise-grade infrastructure. Bridging the gap between CISO directives and local execution across Bangladesh and Nepal territories."
Enforced strict IAM policies across Azure (Entra ID) environments, aligning with Global CISO standards and SC-900 principles.
Executed due diligence and security assessments for critical vendors, ensuring strict adherence to Data Privacy and SLA mandates.
Developed and maintained local incident response plans and disaster recovery procedures to ensure business continuity.
Managed security configurations for VMware vSphere, Cisco networking core, and Microsoft 365 tenant hardening.
Stamford University Bangladesh (2014)
GPA: 3.75/4
RUET (2009)
GPA: 3.07/4
Address: Oriental Hoqdale (Flat-A6) 3,4 kamlapur Bazar Road, Motijheel, Dhaka
Visa Status: Requiring Subclass 482 Sponsorship