Khalid Bin Ahmed
Sr. GRC Engineer, vCISO @ Workstreet
About
"Most organizations have a compliance program. Very few have a security program. There's a difference." Most organizations are investing in cybersecurity tools. Very few are investing in cybersecurity thinking. I work at the intersection of cybersecurity, governance, and risk helping business leaders across KSA, GCC, EMEA, and the US build security programs that are practical, scalable, and aligned with how their business actually operates. Over the past 8+ years, I've worked across consulting, advisory, and enterprise environments supporting organizations with: • Cybersecurity governance and strategy • GRC program design and implementation • Third-party and vendor risk management • Regulatory compliance across ISO 27001, SOC 2, CMMC, PCI DSS, NCA ECC, SAMA, and more But one thing became clear working across all of these organizations: Compliance does not automatically mean security. A passed audit does not mean your business is protected. A filled framework does not mean your risks are managed. Real security requires thinking not just ticking boxes. My focus today is helping organizations build governance programs that actually reduce risk especially as AI systems, cloud platforms, and complex vendor ecosystems continue to expand the modern attack surface. As an ISO 27001:2022 Lead Auditor and ISO 42001 (AI Management Systems) Auditor, I also help organizations navigate the governance challenges that come with AI adoption one of the least understood risk areas for most leadership teams today. I share insights on: • Cybersecurity risk explained in business language • Practical GRC implementation and lessons from the field • AI governance and emerging regulations • Third-party risk and vendor security • Real lessons from working with organizations across multiple industries and regions If you are a founder, CISO, security leader, or executive trying to understand cybersecurity beyond the compliance checklist you are in the right place. Let's make cybersecurity, risk, and governance simple. 📩 Open to conversations on: Cybersecurity governance | GRC | vCISO advisory | AI risk | NCA ECC & SAMA | Security leadership
-
Saudi Arabia
Information Technology & Services
Leadership, IT Audit, Governance, Risk Management, and Compliance (GRC), Artificial Intelligence (AI), Third Party Risk Management (TPRM), Risk Management, IT Security Policies & Procedures, Stakeholder Engagement, SOC 2, CMMC, U.S. Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS), General Data Protection Regulation (GDPR), Vanta, ISO42001, Internet of Things (IoT), Project Management, compliance, Soc 2 Type 2, ISO 27001 Lead Auditor
Experience

Sr. GRC Engineer, vCISO
In this role, I lead governance, risk, and compliance initiatives for clients across KSA, GCC, EMEA, and the US, supporting organizations in building practical security programs that strengthen resilience while meeting regulatory and certification requirements. I work closely with leadership teams to establish governance structures, implement risk management practices, and prepare organizations for frameworks such as ISO 27001:2022, ISO 42001, SOC 2, CMMC, PCI DSS, GDPR, and relevant regional regulations. My responsibilities include: • Leading end-to-end policy development, control implementation, and governance framework design • Conducting enterprise risk assessments, Business Impact Analysis (BIA), and residual risk evaluations • Managing Third-Party Risk Management (TPRM) processes including vendor security assessments and remediation tracking • Supporting organizations through certification readiness and external audits • Developing compliance dashboards and board-level security metrics to improve risk visibility for executive leadership • Overseeing vulnerability remediation tracking and risk treatment planning • Conducting Tabletop Exercises for Incident Response and Disaster Recovery plans to validate operational readiness • Supporting compliance initiatives aligned with Cyber Essentials, HIPAA, HITRUST, TISAX, and emerging regulations such as DORA where applicable • Integrating security and compliance tech stacks with GRC platforms such as Vanta to automate evidence collection and improve continuous monitoring Beyond frameworks and tooling, my role as a vCISO focuses on helping organizations make informed security decisions by balancing regulatory expectations, operational realities, and long-term business resilience. I also support client teams by developing standard operating procedures (SOPs), governance workflows, and security program structures that enable organizations to maintain compliance in a scalable and sustainable way.

Consultant Admin for IT & Security
India
During this engagement, I supported CyberSecureIT with day-to-day IT and security operations, helping establish structured processes to manage assets, users, and internal security practices. My role focused on ensuring operational stability while maintaining basic security governance across the organization. Key responsibilities included: • Managing user onboarding and offboarding processes, including access provisioning and de-provisioning • Implementing IT asset tracking and inventory management to improve visibility and accountability of company resources • Enforcing internal security policies and operational procedures to maintain compliance and system integrity • Coordinating with IT vendors and internal leadership to support infrastructure operations and resolve technical issues • Conducting security awareness activities to promote safe security practices among employees • Managing ticketing systems and troubleshooting day-to-day IT issues across user environments • Tracking security exceptions, remediation activities, and operational follow-ups This role allowed me to support a growing organization by strengthening internal IT governance processes and improving the overall security awareness and operational structure of the team.

IT & Security Manager
Hyderabad, Telangana, India
In this role, I was responsible for managing both cybersecurity and IT operations while leading the organization’s security governance and compliance initiatives. I worked closely with leadership and technical teams to strengthen the company’s security posture, improve operational efficiency, and prepare the organization for international compliance standards. A significant part of my role involved building and implementing security controls aligned with ISO 27001:2022 and SOC 2 Type 2, supporting the organization through certification readiness, internal control implementation, and external audit preparation. My key responsibilities included: • Leading the implementation and ongoing management of ISO 27001:2022 and SOC 2 Type 2 compliance programs • Managing identity and access management processes, including user provisioning, access reviews, and endpoint compliance using Microsoft Intune and Azure AD • Maintaining IT asset inventory, security baselines, and patch management processes to ensure systems remained secure and compliant • Overseeing network and infrastructure security, including VPN access, firewall management (Sophos), and server administration • Managing endpoint protection and threat detection tools such as CrowdStrike Falcon and Microsoft Defender • Conducting vulnerability assessments and remediation tracking to reduce security risks across the environment • Collaborating with vendors and internal teams to support audit readiness, IT governance, and operational security improvements This role provided me with strong hands-on experience across infrastructure security, identity management, and compliance implementation, which later helped shape my transition into more specialized GRC and vCISO advisory roles.

Service Desk Analyst
Hyderabad, Telangana, India
In this role, I supported IT service operations for pharmaceutical clients, focusing on secure user account management and access control processes aligned with healthcare compliance requirements. Key responsibilities included: • Managing user account provisioning and deprovisioning while ensuring adherence to HIPAA compliance requirements • Granting and revoking access to sensitive systems and data based on approved authorization procedures • Supporting identity and access management activities while maintaining strong security and privacy controls • Collaborating with internal IT teams to streamline account lifecycle management and improve operational efficiency This role strengthened my experience in secure access management and compliance-focused IT operations within a regulated healthcare environment.

Technical Support Associate
India
In this role, I provided technical support for telecommunications services supporting Telstra customers, assisting users with connectivity and network-related issues. Responsibilities included: • Troubleshooting Wi-Fi, mobile, and broadband connectivity issues for end users • Diagnosing network and device-related problems to restore services quickly and improve customer experience • Working with cross-functional teams to resolve technical issues and streamline support workflows • Contributing to process improvements that helped reduce response and resolution times This position helped me develop strong network troubleshooting, customer communication, and technical problem-solving skills.

Business Co-Owner
Princess Designer Wear
Hyderabad
During this period, I co-managed a family-owned wholesale and retail clothing business, overseeing operations, vendor relationships, and day-to-day business management. Key contributions included: • Building and maintaining vendor partnerships with textile manufacturers across India to ensure product quality and reliable supply • Managing inventory operations and warehouse coordination to improve stock visibility and order fulfilment • Supporting sales operations, customer engagement, and supplier negotiations • Implementing operational improvements that helped streamline inventory processes and reduce overhead costs This experience provided valuable exposure to business operations, vendor management, and team coordination, which later supported my transition into governance and risk management roles.

Technical Support Engineer
Hyderabad Area, India
In this role, I provided technical support for Dell clients, assisting users with troubleshooting hardware, software, and operating system issues. Responsibilities included: • Diagnosing and resolving operating system and application-related issues for end users • Troubleshooting hardware, network, and system performance problems to minimize downtime • Supporting customers through structured troubleshooting processes to identify root causes and implement solutions • Contributing to improved customer satisfaction through efficient and reliable technical support This role helped build my foundation in IT troubleshooting, endpoint support, and structured problem resolution, which later supported my move into IT security and governance.
Khalid Bin Ahmed's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.

