Ahmed Aleisawi

Ahmed Aleisawi

Acting Head of Cybersecurity @ NEOM

About

Chief Information Security Officer with 20+ years building and leading cyber programs for sovereign-scale and multi-entity organizations across government, finance, telecom, and standards.At NEOM, I lead enterprise cyber strategy across 18 departments, 15 sectors, 8 subsidiaries, and 7 joint ventures—overseeing six divisions with a multi-million budget to protect multi billion investment and deliver NCA-compliant GRC, OT/ICS resilience, Zero Trust, and integrated incident response/BCP for 12,000+ users.Previously, I established the SIDF cyber function with a Board-approved 3-year strategy and achieved zero breaches through secure remote operations during COVID-19. At MOFA, I implemented a cyber program for 150+ international missions with improved NCA-ECC and ISO 27001 compliance. I founded SASO’s Cybersecurity Directorate during the Shamoon outbreak and strengthened national telecom infrastructure at STC.I advise Boards and executive leadership on risk appetite, investment prioritization, and measurable outcomes—aligning cyber with business strategy and regulatory mandates. Passionate about building high-performing teams, securing OT/ICS environments, and enabling digital transformation at sovereign scale.

Country

Saudi Arabia

City

Riyadh

Industry

Computer & Network Security

Skill

Corporate Governance, Cybersecurity Strategy & Roadmap, M&A & Subsidiary Integration, High-Performing Team Leadership, Board & Executive Reporting, Accelerate Talent Development, Enterprise Mindset, Personal Leadership, Team Leadership, Information Security Management, Project Management, Executive Leadership, Strategic Planning, Business Continuity, ISO 27001, Risk Management, Business Strategy, Operational Excellence, Cybersecurity, Management Consulting

Experience

NEOM

Acting Head of Cybersecurity

NEOM

LinkedIn
2024-11 - Present · 1 yr 11 mos

Neom

✪ Challenge: Scale cyber across a rapidly expanding, multi-entity ecosystem with OT/ICS, JV complexity, and stringent NCA mandates. ✪ Action: Established strategy; built 6-division cyber function; enterprise GRC; IR/BCP; third-party risk; OT/ICS security architecture; Zero Trust foundations; budget governance and execution management. ✪ Result: Coverage across 18 departments, 15 sectors, 8 subsidiaries, 7 JVs; resilience for 12,000+ users; uplifted compliance and risk visibility; matured incident/crisis readiness. ✪ Scope: Led 50+ practitioners; multi-region operations; board and EXCOM engagement.

NEOM

Head of Cybersecurity GRC

NEOM

LinkedIn
2022-10 - 2024-11 · 2 yrs 2 mos

Saudi Arabia

✪ Established NCA-aligned enterprise GRC framework, policies, risk registers, and compliance model across multiple business units. ✪ Implemented supplier risk management and oversight for critical partners; integrated governance into project delivery and OT programs. ✪ Introduced performance KPIs and dashboards for audit readiness and executive reporting.

Masar Alnumou Finance

Independent Member of the Board Level Credit and Risk Committee

Masar Alnumou Finance

LinkedIn
2025-2 - Present · 1 yr 8 mos

Riyadh, Saudi Arabia

Provide strategic oversight and independent guidance to the Board on the institution's risk appetite, policies, and overall risk management framework, with a focus on cyber and technical risks.

Masar Alnumou Finance

Chairman of the Credit and Risk Committee

Masar Alnumou Finance

LinkedIn
2024-2 - 2025-2 · 1 yr 1 mo

Riyadh, Saudi Arabia

Provide strategic oversight and independent guidance to the Board on the institution's risk appetite, policies, and overall risk management framework, with a focus on cyber and technical risks.

Masar Alnumou Finance

Independent Member of the Board Level Credit and Risk Committee

Masar Alnumou Finance

LinkedIn
2022-8 - 2024-2 · 1 yr 7 mos

Riyadh, Saudi Arabia

Provide strategic oversight and independent guidance to the Board on the institution's risk appetite, policies, and overall risk management framework, with a focus on cyber and technical risks.

Tawuniya

Head of Cyber Security Governance, Risk Management, and Compliance

Tawuniya

LinkedIn
2022-2 - 2022-10 · 9 mos

Riyadh, Saudi Arabia

✪ Challenge: Establish a modern, standards-aligned GRC function to meet regulatory mandates and reduce enterprise cyber risk while uplifting awareness, vulnerability closure, and compliance. ✪ Action: - Built and formalized the cybersecurity governance framework; drafted/updated policies and procedures aligned to laws, regulations, and best practices. - Defined risk appetite; established the enterprise risk register; conducted risk assessments with clear RACI for remediation and incident response. - Implemented awareness and education programs; delivered security training across stakeholder groups. - Stood up vulnerability management lifecycle; oversaw remediation and closure; ran VAPT/red teaming, configuration and source code reviews, and social engineering exercises. - Selected/implemented governance tools for assessment and automation; integrated with Strategy and Architecture to ensure compliant design. - Updated compliance frameworks and ensured adherence to standards and regulatory bodies (e.g., ISO 27001/NCA ECC). ✪ Result: - Centralized GRC with clear policies, risk ownership, and executive visibility. - Improved audit readiness and regulatory alignment; accelerated vulnerability closure and raised security awareness across the business. - Reduced time-to-detect/respond through defined processes and tool-enabled assessments; strengthened control coverage across IT and product platforms.

Saudi Industrial Development Fund - SIDF

HEAD OF CYBER SECURITY (CISO)

Saudi Industrial Development Fund - SIDF

LinkedIn
2020-2 - 2022-2 · 2 yrs 1 mo

Riyadh, Saudi Arabia

✪ Challenge: Stand up a modern cybersecurity function aligned to National Requirements (NCA), improve governance and compliance, and reduce enterprise risk while enabling SIDF’s strategic objectives. ✪ Action: - Built the CISO function and operating model; delivered a Board‑level 3‑year cyber strategy and roadmap. - Established governance with policies, standards, procedures, and a Steering Committee; formalized exec/BoD reporting. - Performed enterprise governance assessments across identity, access, data privacy, and physical security; stood up risk management with functional/technical risk assessments and a centralized register. - Implemented a structured Compliance program with a detailed gap‑closure plan; managed NCA liaison and regulatory communications. - Launched a comprehensive awareness program supported by an automated platform. - Deployed an Incident Management framework to strengthen detection, response, and resilience. ✪ Result: - Board‑approved strategy operationalized; clearer risk appetite and governance across business units. - Uplifted NCA compliance posture and improved regulator reputation; accelerated closure of control gaps. - Increased cyber awareness and accountability enterprise‑wide; faster incident handling and improved resilience.

Ministry of Foreign Affairs, Saudi Arabia

Head of Cyber Security Governance and Business Resiliency

Ministry of Foreign Affairs, Saudi Arabia

LinkedIn
2017-1 - 2020-2 · 3 yrs 2 mos

Riyadh, Saudi Arabia

✪ Challenge: Build a comprehensive cyber program for HQ and globally distributed missions, unify governance and reporting, and strengthen business resiliency under ministerial oversight. ✪ Action: - Established end‑to‑end cybersecurity program covering Governance, Risk Management, Compliance, Strategy, and Operations. - Formed and operationalized a Cybersecurity Steering Committee chaired by the Minister; implemented a single compliance/communication dashboard. - Developed the enterprise cybersecurity strategy and multi‑year roadmap; recruited and led a high‑caliber cyber team. - Ran compliance and risk assessments across missions and HQ; standardized processes and reporting. Implemented state‑of‑the‑art protection technologies; designed and deployed a secure network architecture for MOFA. - Built Business Continuity and Disaster Recovery capabilities for missions and HQ, including resilient infrastructure and communications. - Launched an awareness and training program that earned international recognition. ✪ Result: - Unified governance and executive visibility; improved compliance posture across HQ and missions. - Strengthened infrastructure security and reduced operational risk with modern controls and secure architecture. - Increased organizational resilience with tested BC/DR; elevated cyber culture through award‑winning awareness initiatives.

SASO, Saudi Standards Metrology and Quality Organization

Head of Cyber Security and Communications

SASO, Saudi Standards Metrology and Quality Organization

LinkedIn
2015-10 - 2017-3 · 1 yr 6 mos

Saudi Arabia

✪ Challenge: Create a formal cybersecurity function, harden infrastructure against rising nation‑state malware (e.g., Shamoon), and uplift resilience and governance. ✪ Action: - Founded the Cybersecurity Directorate; established GRC framework, policies (ISO 27001‑aligned), and program roadmap; ran multiple VAPT cycles. - Designed the cybersecurity and communications strategy; upgraded network/security architecture (Next‑Gen Firewall, Email/Internet Security Gateway, segmentation). - Implemented DR/IR plans and trained IT teams; standardized documentation, playbooks, and change management. - Drove awareness and executive reporting; improved user experience and secure-by-design practices across projects. ✪ Result: - Strengthened security posture and resilience; closed design weaknesses and prevented Shamoon impact through advanced protection and hardening. - Institutionalized governance with clear processes, controls, and repeatable testing. - Improved operational continuity via tested BCP/DR and trained response teams.

stc

Head of Information Security Governance, Risk Management & Compliance (GRC)

stc

LinkedIn
2014-4 - 2015-10 · 1 yr 7 mos

Al-Riyadh Governorate, Saudi Arabia

In my past role as Governance, Risk & Compliance Manager I implemented security awareness programs and instituted compliance metrics for decreasing enterprise risks and network security threats. For the resolution of network technologies security issues, I interacted with the network design department. I configured routers, switches, firewalls, etc. to execute network security procedures. I created a security culture within STC’s network and ensured adherence to STC’s quality standards for network security as per international security standards such as ISO 27001, eTOM, ITU, etc. I defined and met KPI’s for key team members to meet job protocols. Following are highlights of the key achievements that I attained: ✪ Integrated framework with corporate strategy and procurement to transfer risk mitigation accountability on vendors, mitigating the impact of risk. ✪ Overcame company’s cybersecurity incidents and infrastructure compromises by executing cyber security incident management framework, team training, and engaging a 3rd party for cybersecurity intelligence. Implemented an Enterprise Risk Management Framework based on ISO31000 which helped STC to identify and manage risks in its telecommunication technologies. ✪ Implemented Cybersecurity Governance based on ISO27001, this has helped tremendously in improving STC’s telecom security and ensuring secure implementations from its telecom vendors. ✪ Conducted Vulnerability and Penetration Testing on all STC telecom technologies (PS Core, Converged Core, Transport Network, Wireless Network, Mobile Network, Landline Network, and Value-Added Services). ✪ Implemented Minimum Baseline Security Standard for all the telecom technologies procured from the vendors (Alcatel-Lucent, Nokia, CISCO, ERICSSON, Huawei … etc). ✪ Established a program with STC’s telecom vendors based on a partnership to improve the security of their deliverables and operations according to STC cybersecurity policies and VAPT assessments.

International Systems Engineering - ISE

Head of Information Security Shared Services

International Systems Engineering - ISE

LinkedIn
2013-3 - 2014-4 · 1 yr 2 mos

Al-Riyadh Governorate, Saudi Arabia

In my past role as Shared Security Services Manager I developed and supervised shared security services activities and present analysis, recommendations, and escalation points to Head of Information Security and Assurance. For meeting information security and assurance service goals I retained specialised capabilities and created succession plans. I ensured ISE’s readiness and awareness of latest information security and business continuity solutions/techniques as well as with IT infrastructure, projects, and client accounts to review information security designs with the engagement of research and development. I identified and notified quality manager regarding quality related training needs to ensure the delivery of exceptional service. I ensured the comprehensive delivery of functional operations in accordance with policies and procedures by leading and guiding direct reports. Following are highlights of my key achievements that I attained: ✪ Maintained efficient operational excellence across ISE by supported in developing policies and processes for information security as per business requirements. ✪ Ensured full adherence to ISE business management system, including legal and regulatory requirement mandate through policies as described in the BMM. ✪ Obtained required signature/approval on related policy and process as part of business management system.

BAE Systems Saudi Arabia

Head Of Information Security

BAE Systems Saudi Arabia

LinkedIn
2012-6 - 2013-3 · 10 mos

Riyadh

In my past role as Information Security Manager I oversaw reports of information security incidents and ensured rapid resolution. To eliminate any chance of incident or vulnerability, I ensured proper protection and corrective measures. I governed overall aspects of development documentation, along with presentation of information security education, awareness, and training activities. I accomplished tasks assigned with the co-ordination of information security professionals work. Following are highlights of my key achievements that I attained: ✪ Managed information security and compliance and transformed whole IT to comply with BAE Global policies and standards with especial care on supply chain and 3rd party security. ✪ Oversaw and realised the successful implementation of security features for detection of malicious code, viruses, intruders (hackers), and local threats/vulnerabilities.

Confidential

ISMS and Security Compliance Manager

Confidential

2011-2 - 2012-5 · 1 yr 4 mos

Saudi Arabia

Responsible of: • Leadership and strategic direction for Information Security Management System and Security Audit and Compliance according to the strategic plans. • Liaison with and offers strategic direction to functions related to ISMS and Security Audit and Compliance plus senior and middle managers throughout IT and Communication Department as necessary, on information security matters. • Leads the design, implementation, operation and maintenance of the Information Security Management System based on the ISO/IEC 27000 series standards, including certification against ISO/IEC 27001 where applicable. • Leads the preparation and the implementation of necessary information security policies, standards, procedures and guidelines, in conjunction with the Security Committee. • Leads the design and operation of related compliance monitoring and improvement activities to ensure compliance both with internal security policies etc. and applicable laws and regulations. • Leads suitable information security awareness, training and educational activities. • Leads information security risk assessments and controls selection activities. • Leads activities relating to contingency planning, business continuity management and IT disaster recovery in conjunction with relevant functions and third parties.

Education

King Saud University

King Saud University

LinkedIn

Computer Science & Information

2000 - 2005 · 5 yrs

Ahmed Aleisawi's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.