Cybersecurity engineer with 5+ years' experience, specialising in privileged access management (BeyondTrust Password Safe) and enterprise vulnerability management (Tenable) across hundreds of Windows, Linux, database and network assets, aligned to ISO 27001 and NIST CSF. Also experienced in incident response, SIEM monitoring, Active Directory and penetration testing. Certified BeyondTrust PAM Administrator, Tenable VM, CEH v10 (96.8%). Seeking a PAM, vulnerability management or security engineering role in Saudi Arabia, UAE or remote. Transferable Iqama.

--- CV ---
SYED MOHAMMAD DANIAL
Cybersecurity Engineer | Vulnerability Management | Privileged Access Management
CEH (96.8%) · Certified BeyondTrust PAM Administrator · Tenable Vulnerability Management · CNSS · Azure AI Engineer Associate
Dammam, Saudi Arabia · +966 53 569 3746 · [email protected]
LinkedIn · YouTube (50K+ views)
Transferable Iqama · Legally authorized to work in Saudi Arabia · Available to join immediately

PROFILE
Cybersecurity engineer with 5+ years across security and IT infrastructure, currently running privileged access management and
enterprise vulnerability management for P1/P2 mission-critical healthcare systems at Johns Hopkins Aramco Healthcare. Administers
BeyondTrust Password Safe and Tenable across hundreds of Windows, Linux, database, and network assets, aligned to ISO 27001, NIST
CSF, and Zero Trust least-privilege principles.
Signature results: cut PAM policy-violation detection from up to 24 hours to near real time, and closed standing audit findings by
bringing previously unmanaged databases and Linux servers under privileged access control.

CORE COMPETENCIES
Privileged Access Management: BeyondTrust Password Safe, credential vaulting, automated password rotation, credential injection,
session recording & auditing, just-in-time (JIT) access, least-privilege / Zero Trust enforcement, PAM onboarding & offboarding lifecycle
Vulnerability Management: Tenable (deployment, administration, scan policy design, credentialed scanning), Nessus, risk-based
prioritization, patch validation, remediation tracking, Burp Suite Professional, Metasploit, OWASP ZAP, OWASP Top 10, penetration
testing
Incident Response & Monitoring: End-to-end incident handling, containment & remediation, root cause analysis, post-incident
reporting, SOC coordination, SIEM monitoring & log analysis, real-time alerting design, MITRE ATT&CK-informed analysis, Microsoft
Defender (EDR), Microsoft Purview (DLP)
Identity & Directory Services: Active Directory, Group Policy (GPO), Microsoft Entra ID (Azure AD), identity & access management,
multi-factor authentication
GRC & Compliance: ISO 27001, NIST Cybersecurity Framework, risk assessment & mitigation, audit response & finding closure, security
policy enforcement, ITIL / CAB change management
Infrastructure & Cloud: Windows Server, Linux (Red Hat, Ubuntu), server hardening, patch management, VMware vSphere, Microsoft
Azure, firewalls, routing & switching, SolarWinds, Tripwire (FIM), ServiceNow (CMDB, Request Catalog, CHG/CTASK), SCCM
Development: C#, ASP.NET MVC, MS SQL Server, HTML/CSS/JavaScript, Bootstrap, secure coding practices

PROFESSIONAL EXPERIENCE

PAM Administrator & Vulnerability Management — Cybersecurity Department Jun 2025 – Present
Johns Hopkins Aramco Healthcare (SmplID) Dammam, Saudi Arabia
• Administer and harden the enterprise BeyondTrust Password Safe platform as the central control point for privileged access
across hundreds of Windows/Linux servers, domain controllers, databases, and network devices in P1/P2 critical healthcare
infrastructure enforcing least privilege and full session accountability.
• Own enterprise vulnerability management on Tenable deploying and maintaining the platform, building credentialed scan policies
and scan schedules across Windows, Linux, and network assets, and converting raw scan output into risk-prioritized remediation
targets for system owners.
• Drive remediation to closure by validating patches, tracking fix SLAs with infrastructure teams, and reporting residual risk to
leadership, ensuring findings are actually resolved rather than re-reported cycle after cycle.
• Eliminated a detection blind spot of up to 24 hours caused by a legacy daily-report process for PAM bypass events; engineered
real-time email alerting driven by session-recording and access-log monitoring, cutting policy-violation detection from next-day to
near-instant.
• Neutralized shared-password and standing-credential risk by onboarding Windows, Linux, VMware vSphere, and web-application
assets into PAM with credential vaulting, automated rotation, and credential injection so privileged passwords are never exposed
to end users.
• Closed open audit findings by bringing previously unmanaged databases and Linux servers under PAM, automating asset
reconciliation against CMDB/SCCM, and redesigning the ServiceNow PAM Request Catalog to enforce clean, auditable access
requests.
• Led change management (CHG/CTASK) for high-risk infrastructure work server decommissioning, IP readdressing,
SolarWinds/Tripwire agent deployment securing CAB approvals and preserving operational continuity on production critical
systems.
• Authored a technical assessment of BeyondTrust Password Safe vs. Microsoft LAPS for workstation credential management,
evaluating licensing cost, rotation risk, and operational overhead to equip leadership with a data-driven platform decision.
• Resolved PAM access incidents and firewall connectivity failures by partnering with SOC, Active Directory, Enterprise Architecture,
Compliance, and external vendors restoring secure access paths without weakening controls.
Back Office Executive — IT Operations May 2023 – May 2025
Ibex (SquareTrade Campaign) Karachi, Pakistan
• Delivered L1/L2 support across hardware, software, and access issues for depot supply-chain operations, sustaining 98% system
uptime on business-critical IT services.
• Engineered automation to replace error-prone manual data-entry workflows, cutting operational errors by 30% and lifting cross-
team productivity by 25%.
• Reduced endpoint exposure to known exploits by applying security patches and system updates in line with IT policy, and
supported endpoint compliance audits across the fleet.
Web Application Se
Riyadh, Job Seekers, Administrator, Information Technology And Cybersecurity
واپس جائیں اگلا