Hassam Malik

Hassam Malik

Cybersecurity Awareness Program Manager @ City Of Hamilton

About

Qualified Information Security professional with solid experience in implementation and troubleshooting on various Information Security projects. Strong working knowledge of Security tools and technology, Cloud Security, Security Testing Frameworks, Compliance Standards. Ability to clearly understand problems and find positive solutions through use of troubleshooting, problem solving, teaming and communication skills. Skills include: • Implementing controls for critical information assets such as, asset inventory and classification access control mechanisms. • Network and systems security management including Antivirus management, incident management, patch management. • Development of information security policies, standards and procedures. • Information security principles and tools such as Nessus, Nmap, Wireshark, • Metasploit, Kali/BackTrack suite. • Abreast with current and emerging security threats / attacks such as malware, DoS and DDoS, botnets, spam, spyware, sniffing, spoofing, phishing, pharming, Trojans, worms and viruses.

Country

Canada

City

Greater Toronto Area

Industry

Computer & Network Security

Skill

Troubleshooting, Operations, Operating Systems, Documentation, Security Awareness, Active Directory, Healthcare Information Technology (HIT), OpenID Connect, M&A Due Diligence, Proofpoint, Reporting & Analysis, SAML 2.0, Cybersecurity Incident Management, OWASP ZAP, Employee Training, RSA Security, FedRAMP, Microsoft Power BI, Microsoft Intune, Security Metrics

Experience

City Of Hamilton

Cybersecurity Awareness Program Manager

City Of Hamilton

LinkedIn
2025-10 - Present · 1 yr

Led enterprise-wide cybersecurity awareness programs, designing and delivering targeted campaigns, phishing simulations, and training initiatives that improved employee resilience to social engineering attacks. Developed and executed a comprehensive Cybersecurity Awareness Month (October) program, including campaign themes, executive communications, training events, and engaging multimedia content under aggressive timelines. Created budget estimates, resource plans, and cost justifications for security awareness initiatives, ensuring alignment with organizational goals and leadership expectations. Measured and reported program effectiveness using KPIs, phishing metrics, and employee feedback, providing actionable insights and regular updates to senior stakeholders.

Corus Media Holdings Inc.

Cyber Security Operations Specialist

Corus Media Holdings Inc.

2024-5 - 2025-4 · 1 yr

Toronto, ON

▪ Led cloud security enhancements, implementing GCP Service Perimeter, Cloud Armor, and enforcing perimeter controls, alongside Google Workspace Security configurations and firewall policies to prevent data breaches. ▪ Conducted endpoint protection and vulnerability management using FireEye Hx, FireEye ETP, Varonis, and Rapid7, while supporting security policies aligned with NERC CIP, ISO 27001/2, PCI DSS, and NIST standards. ▪ Handled internal ticket resolution via Web Help Desk, created cyber risk dashboards for senior management, and delivered actionable insights through security assessments ▪ Supported SDLC, vendor management, and project management processes, and contributed to cloud migration efforts to enhance organizational agility and security. ▪ Assisted the threat-hunting team by testing new threats, evaluating potential impacts, and supporting early identification of emerging threats.

Financial Services Regulatory Authority of Ontario (FSRA)

Cyber Security Specialist

Financial Services Regulatory Authority of Ontario (FSRA)

LinkedIn
2023-1 - 2024-3 · 1 yr 3 mos

Toronto

• Providing leadership advise, project management, vendor management, and risk-based expert advice to technical & business teams to manage information security risks across FSRA. • Primary on-call person when responding to any high-severity cyber threat alert, and leading any cyber incident response. • Performing in-depth risk analysis for new applications/solutions/systems/services/vendors. • Providing proactive risk mitigation advice while considering cyber security best practices, corporate guidelines and directives, latest threat landscape, and operational sustainability. • Engaging in predictive threat intelligence while ensuring that strategies, designs, and plans take into account the future threat landscape. • Leading and managing multiple projects for establishing new cyber security capabilities while balancing various aspects of the projects such as - budget, stakeholder, change and vendor management, communications and reporting. • In-depth knowledge of cyber security domains, latest industry trends and best practices (i.e., NIST, CIS Top 18, OWASP Top 10, PCI DSS, ISO 27001), common vulnerabilities, threats and attacks targeting people and technology. • Proficient in risk management concepts and methods used for managing and governing cyber security risks. • Strong knowledge and hands-on experience with operating and fine-tuning cyber threat detection and response solutions such as - vulnerability scanners, SIEM platforms (e.g. Rapid7), EDR platforms (e.g. Crowdstrike), DLP tools, Cyber threat intel platforms (e.g. Recorded future), user behavior analytics, Honeypots. • Performing threat hunting to uncover IOA's and Indicators of Compromise. • Proactive and strong knowledge of cloud security for IaaS, PaaS, and SaaS. • Ability to analyze and synthesize information, perform log correlation and analytics, generate KRIs and KPIs, prepare executive reports supported by facts and data. • Ability to automate operational tasks to achieve efficiency.

Devflovv

Information Security Analyst

Devflovv

LinkedIn
2021-3 - 2022-12 · 1 yr 10 mos

Deployed enterprise SSO and MFA with Okta, Azure AD, and OneLogin. Conducted web application penetration testing (Burp Suite, OWASP ZAP). Created Power BI dashboards for threat visibility and IAM governance. Integrated SailPoint with SIEM and EDR tools for identity-based alerting. Led vulnerability management and client remediation support. Delivered KnowBe4-based phishing simulations and security training. Tracked and analyzed KPIs, including intrusion attempts and MTTR (Mean Time to Detect/Resolve), improving overall security response metrics.

TELUS

Security Analyst

TELUS

LinkedIn
2020-2 - 2021-1 · 1 yr

Conducted IAM assessments and security testing (Nessus, Qualys). Ensured PHIPA compliance in healthcare IT solutions. Integrated security into SDLC with SAST/DAST testing methodologies. Monitored IDS/IPS and optimized firewall rule sets. Responded to Tier 2 incidents and performed cloud security reviews.

TC Technology

Information Technology Security Consultant

TC Technology

2018-3 - 2019-11 · 1 yr 9 mos

Dubai, United Arab Emirates

• Worked directly with clients to understand their security requirements and compile SIA/PIA • Worked with other teams to evaluate the contractual scope of works towards the client and establish a workflow to accomplish the goals • Participated in security baselines creation for existing and new clients and working with various teams to assure that the minimum set baselines were met. • Black Hat Testing of all publicly available servers, perimeter Firewalls and Intrusion Detection Systems. • White Hat Testing of all internal servers and member services like DNS, SQL, IIS and Application Servers. • Monitored and analyzed network traffic data using Wireshark to establish baselines and document anomalies. Appropriate actions were taken to minimise network downtime and security breaches resulting in an improvement of network services of 40%. • Established and documented process for event detection from monitoring devices and associated technology

TC Technology

Information Technology Security Analyst

TC Technology

2018-3 - 2019-11 · 1 yr 9 mos

Conducted black-box/white-box testing across DNS, SQL, IIS, and cloud environments. Used Splunk and Wireshark for network visibility and intrusion detection. Enhanced service uptime by 40% through proactive threat detection.

Hassam Malik's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.