SH.Shahul Hameed
Curriculum Vitae — Information Security Abu Dhabi · UAE

Shahul
Hameed

Chief Information Security Officer (CISO) · Information Security Leader · Security Architect

Shahul Hameed

20+ years turning cyber risk into board-level certainty — with a zero-breach record.

Download CV PDF · 4 pages

0
Years
Zero
Breaches
0
Visitors / yr
0
Certifications
0
Yrs ISO 27001
01

Profile

I'm an information-security leader and applied-AI builder with 20+ years defending government and enterprise across the UAE. On the security side I own the full program — ISO 27001, NIST CSF and Zero-Trust architecture; a Microsoft Sentinel / Defender XDR / CASB SOC with 24/7 threat detection, incident response and VAPT; GRC and audit readiness — and I've kept one of the region's most-targeted estates breach-free. Today I lead security operations for the Department of Culture & Tourism – Abu Dhabi (DCT), protecting the digital infrastructure behind the emirate's museums, heritage and destination platforms. On the AI side I'm hands-on: I conceptualize, design and ship AI-powered products — LLM agents, MCP-integrated tools and automations — and I govern responsible, secure AI adoption to ISO/IEC 42001 as a certified Lead Auditor and Lead Implementer. I work exactly where information security and AI converge.

02

Experience — Dept. of Culture & Tourism, Abu Dhabi

2023 — Now

01Security Operations Unit Head — Museums Shared Services

Leads enterprise security operations across DCT's Museums Shared Services — the digital backbone of Abu Dhabi's national museums. Built and operationalized the information-security strategy, policy library and incident-response plans aligned to UAE IA, and enforced a Security-by-Design governance model that reviews every system before go-live. Deployed Microsoft Sentinel (SIEM), Defender XDR and Cloud App Security estate-wide, stood up AI governance to ISO/IEC 42001, and runs VAPT and third-party (supply-chain) risk end to end — protecting irreplaceable collections data, digital archives and the visitor-facing platforms behind the estate.

2022 — 23

02IT Security Unit Head — Zayed National Museum

Built the technology and security operating model for a landmark national museum from greenfield, ahead of opening. Defined the dedicated IT and security budget, vendor SLAs and IT-governance model, and localized ISO 27001-aligned controls to safeguard irreplaceable digital archives, collections data and visitor information — embedding a security-aware culture across curators and museum staff before launch.

2021 — 22

03Head of Technical Engineering Section — IT Department

Directed a multi-disciplinary engineering organization spanning Security Operations, hybrid infrastructure, application development and the desktop unit. Ran a 24/7 SOC, an Azure IaaS/PaaS/SaaS hybrid-cloud estate, DevSecOps pipelines and thousands of managed endpoints; owned IT strategic planning and budgets; delivered executive-level technical reporting to the C-suite; and governed BCDR, incident response and vendor SLAs across the enterprise.

2019 — 21

04IT Governance & Compliance Unit Head — Corporate Security

Directed the enterprise Security Governance and Compliance unit as the strategic advisor to executive leadership on cyber risk. Authored the security policy library and incident-response plan, established the cyber-risk and threat-modeling lifecycle, and sustained ISO 27001, GDPR and UAE IA (ADSIC/NESA) compliance through recurring internal and external audits, corrective-action plans and formal reporting to regulators.

2019

05Infrastructure Lead — IT Department

Led enterprise infrastructure operations and a cross-functional engineering team. Delivered new network architectures and systems with zero critical disruption, designed BCDR architectures to strict RTO/RPO objectives, and engineered infrastructure security controls and hardening while negotiating enterprise procurement contracts for maximum ROI.

2011 — 19

06Senior Security Administrator → IT Security Expert → Security Administrator

Eight years progressing as the principal subject-matter expert for enterprise security. Engineered the network-security stack and IAM (firewalls, IDS/IPS) to hold a zero-breach environment on a highly-targeted estate, deployed centralized SIEM and ran end-to-end incident response with threat hunting and forensics, governed vulnerability-management (VAPT) programs, and sustained ISO 27001 / ADSIC compliance with security-awareness training for thousands of employees.

Earlier Career

2007 — 09

07Network Administrator — Abu Dhabi Investment Authority (ADIA)

Engineered high-availability network infrastructure and security firewalls supporting the rigorous operations of one of the world's largest sovereign wealth funds. Notably executed a zero-downtime corporate-headquarters migration that kept financial trading and operations completely uninterrupted.

2005 — 11

08Systems Engineer — Seven Seas Computers (now Noventiq)

Designed and deployed complex enterprise IT architectures for diverse corporate clients. Directed end-to-end project lifecycles encompassing requirements gathering, vendor negotiation, deployment and rigorous security integration across each engagement.

03

Core Competencies

  • C01Security Strategy & Governance
  • C02Enterprise Risk Management
  • C03GRC — ISO 27001, GDPR, UAE IA/NESA
  • C04SOC / SecOps Leadership
  • C05SIEM/SOAR & XDR
  • C06Threat Detection & IR
  • C07Vulnerability Mgmt / VAPT
  • C08AppSec & Secure SDLC · DevSecOps
  • C09Zero Trust Architecture
  • C10Cloud Security (Azure, M365)
  • C11AI Governance (ISO/IEC 42001)
  • C12Incident Response
  • C13Applied AI & LLM App Development
04

Certifications — 15+ total

  • CISSP
  • CCSP
  • CISM
  • CISA
  • COBIT
  • CCSK
  • CCZT
  • TOGAF 9
  • CEH
  • ITIL
  • Security+
  • Azure Security Engineer
  • ISO 42001 Lead Auditor
  • ISO 42001 Lead Implementer
05

Selected Work — apps I've conceptualized, designed, developed & shipped using Artificial Intelligence

UAE Subcontractors

A UAE construction subcontractor directory — verified businesses across every trade, with self-registration, admin activation, lead credits and a sales-agent commission network.

Next.js · Postgres · SaaS
Visit ↗
IndexPulse

AI market-intelligence for NIFTY 50 — news, sentiment & option-Greeks distilled into intraday calls via AI.

AI · LLM · Real-time
Visit ↗
FLARE

Multi-tenant vulnerability-management platform — flaw logging, analysis, remediation SLAs, evidence and auto-generated PDF/Word reports.

AppSec · GRC
Visit ↗
Complyant

GRC & compliance oversight — one control score across ISO 27001/42001, UAE IA, GDPR, PCI, SOC 2 & NIST.

Compliance · Risk
Visit ↗
Cadence

Team work & capacity dashboard — planned vs adhoc load, framed around workload not performance.

Ops · Teams
Visit ↗
Knack

AI job-hunt — scores every listing against your CV profile and tailors a per-role CV.

AI · Careers
Visit ↗
JarFlow

AI personal-finance PWA — upload bills and let AI categorize across the 6-Jars system.

AI · Fintech
Visit ↗
SubScope

UAE construction-opportunity intelligence & compliant outreach for subcontractors.

Intelligence
Visit ↗
MyMetrics

Self-hosted health & habit tracker with an AI coach.

Health · Self-hosted
Visit ↗
06

Contact

Whether it's a security engagement or advisory conversation, a board or speaking invitation, or an AI build you want to scope — I read every message myself. Tell me what you're working on and I'll reply personally.

Prefer email? [email protected]  ·  +971 50 442 4928