cat experience.md

A timeline of roles across banking security, governance, data protection, consulting and teaching.

Full-Time#

Founder, RogSec Technology Solutions#

2025 – present

Why launch RogSec? After more than five years in the banking industry, holding roles spanning end-to-end security from infrastructure to governance (infrastructure security, business continuity, disaster recovery, data privacy, information security), I founded RogSec to serve a broader range of clients and gain experience across different sectors and projects.

I develop and oversee the company’s strategic vision, build and maintain relationships with customers and partners, and identify growth opportunities. I lead the creation and execution of marketing, sales, and operational strategies, represent the company publicly to communicate our values and mission, and ensure we operate within legal and ethical guidelines.

Senior Regional Personal Data Protection Officer, GCC · Arab Bank#

2025 – 2025

Why the shift to a DPO role? A step toward a more specialized position to deepen my expertise in data privacy. With a regional scope, I worked across the laws and regulations of multiple countries in the Arabian Gulf and wider Middle East, broadening my understanding of regional privacy and compliance challenges.

I supported Data Controllers across the GCC in meeting their obligations under the Personal Data Protection Law by monitoring internal compliance, advising stakeholders on privacy governance and policies, and maintaining and validating data registers and processing-activity records. I oversaw privacy impact assessments and automated decision-making registers, identified and helped manage privacy risks, reviewed contractual privacy clauses, and assessed new or updated products and services for PDPL and compliance implications.

Information Security Section Head & Data Protection Guardian, Al Baraka Islamic Bank#

2024 – 2025

Why the shift to an IS role? This role marked a career shift from infrastructure security to governance, expanding my expertise into information security, business continuity, and data privacy. It broadened my understanding of security responsibilities beyond my earlier infrastructure-focused duties.

I oversaw management communications and quarterly community meetings, developed and enforced security strategies and hardening guidelines aligned with PCI-DSS, CIS, NIST, and ISO 27001, and managed the vulnerability program and continuous monitoring to detect and remediate incidents. As Data Protection Guardian, I ensured compliance with data protection regulations, conducted BIAs, PIAs, and risk assessments, and managed access controls. I also developed cybersecurity policies and frameworks, coordinated vulnerability and patch management with IT, supported business continuity planning, and assisted with environmental monitoring and incident response.

Network Support & Security Supervisor, The BENEFIT Company#

2020 – 2024

Why start in network support and security? Starting in infrastructure let me understand which assets are most critical to an organization and how to manage them from a cybersecurity perspective. That gave me a solid foundation for future moves, particularly a transition into governance.

I conducted network assessments and enforced regulatory and security standards (PCI-TSP, PCI-DSS, NIST, ISO 27001) while managing security tools (firewalls, routers, switches, WAF, LTM) and integrating devices with SIEM for anomaly detection. I performed firewall and access reviews, remediated VAPT, ACL, and configuration issues, evaluated new cybersecurity technologies, and led network and datacenter migrations and connectivity projects, including MPLS and BGP links with local and global partners.

Cameraman, Bahrain Television#

2017 – 2018

The story behind my first job. While pursuing my bachelor’s degree, I wanted to diversify my professional experience by entering the media industry, a field I’ve long been passionate about. Driven by an interest in filmmaking, I seized the opportunity to work in video production to gain hands-on technical experience ahead of graduation.

I worked on the production of live events and TV shows, keeping the filming running smoothly, meeting the technical specifications, and capturing good footage. I edited footage to support the storytelling, worked with teams from different departments, and handled the recording process from live continuity through to post-production, following broadcast standards.

Part-Time#

Instructor, Bahrain Polytechnic#

2024 – 2024

Why another teaching role? To expand my teaching experience and give back to the sector. This role carried greater responsibility than my previous teaching position: I delivered the full course material, supervised exam sessions, and graded exams and assessments as a full instructor.

I developed a lab curriculum for IT6003 Networks and Data Communications aligned with industry standards, designed hands-on exercises, provided individualized feedback to improve students’ technical skills, and collaborated with colleagues to ensure consistent lab content and assessment.

Instructor, University of Bahrain#

2022 – 2024

Why a teaching role? During my master’s studies at the University of Bahrain, I worked as an instructor delivering lab sessions. I pursued this to gain experience presenting technical content and to expand my teaching techniques, which later helped me prepare and deliver reports to senior management in my information security role.

I led interactive lab sessions for ITCE352, ITCE353, and ITNE231, delivering hands-on exercises that built practical networking skills, assessed lab reports with constructive feedback, and maintained fair, accurate grading.

Training#

Information Security Trainee, Bahrain Islamic Bank#

2020 – 2020

I led the development of the Bahrain Threat Sharing Platform, establishing a centralized hub for effective intelligence exchange among key stakeholders. I implemented network vulnerability management practices, running regular assessments and remediating the risks they turned up, deployed VPN connections for secure remote access, and conducted firewall audits to ensure policy compliance, identify weaknesses, and implement critical security enhancements.