
Sanjay Saha, CISA
System Controller, Data Centre (IT Dept.)

Connect with Sanjay Saha, CISA to Send Message
Connect
Connect with Sanjay Saha, CISA to Send Message
ConnectTimeline
About me
IT Security and Compliance at SBAC Bank Ltd
Education

Shahjalal University of Science and Technology
1998 - 2001Bachelor of Science (B.Sc.) Physics 3.52
Jahangirnagar University, Savar, Dhaka.
2017 - 2018Master of Science (MSc) Computer Science 4 out of 4
Shahjalal University of Science and Technology
-Master of Business Administration (MBA) Finance 3.91
Shahjalal University of Science and Technology
2002 -Master of Science (M.Sc.) Physics 3.81
Experience

Standard Chartered
Apr 2006 - Feb 2010System Controller, Data Centre (IT Dept.)• To run the EOD (End-of-Day) procedures of SCB core banking software eBBS and other surrounding systems like eMortgage, eCAPS, eGLEX, OPICS etc. • Coordinate with the Hong Kong Data-Center & the Support Team of India for any abnormalities in EOD. • To take backup of Data and Applications of windows server using Brightstor ARCserve, Database server (DB2) using TSM server, ATM system, AS/400 system etc, in DLT/ LTO tapes.• To restore backups in DR (Disaster Recovery) sites as per schedule and requirement.• To monitor Computer Network for LAN and WAN environment such as ATMs, POS, Servers, and Communication equipments (VSAT, Radio Link, Fiber Link) using various monitoring tools.• Update regularly Data Centre Inventory such as Computers, Servers, and Tapes etc both in production and DR sites and prepare various types of MIS reports.• Operational improvement & process amplification. Show less

BASIC Bank Ltd
Feb 2010 - Jan 2023• Conduct IT audit by Identifying, assessing, evaluating and monitoring internal and external information security risks and security issues of information assets.• Assess implemented appropriate administrative, physical and technical controls to ensure availability, integrity and confidentiality of information assets.• Assess and audit ICT Security and Risk related policy and frameworks like ICT Security policy, ICT Risk Management Framework, Incident Management, Password policy, Backup & Restore policy, VAPT policy, BCP & DRP, Change Management, Patch management, Configuration management etc., as per regulatory guidelines and international standards.• Conduct VAPT to detect different system flaws using standard tools like Nmap, OpenVAS, nessus, Metasploit etc. using Kali Linux and windows platform.• Assess vulnerability management, penetration testing, incidents, scans, patching status, secure baselines, penetration test results, phishing, and social engineering tests and attacks.• Develop IS Audit Framework for audit reporting and monitoring.• Prepare IS Audit plan and develop tools & materials for IS audit.• Prepare audit report for submission to the management.• Information Systems Audit specially on Windows, Linux and Unix and other different distributions.• Auditing in Data Center and Disaster Recovery site.• Conduct follow up audit to assess how well responsible managers/functions had implemented the recommendations made in the previous conducted comprehensive audit.• Define ICT security requirements and measure compliance, based on Bank's policies/procedures, applicable laws, regulations and best practices.• Assess end point security antivirus management and operation. Show less • Administration and Maintain AIX, Linux and windows system.• Administration and Maintain IBM V7K and DS4700 Storage. • Maintain of LPAR & VIOS and Virtualization by VMWare and Hyper-V.• Apply OS patches and upgrades administrative tools.• Maintain access control as per rules and necessity of AIX, Linux and windows system and monitor system audit regularly.• Take Data and Applications backups and restore backups in DR sites.• Perform export, import, analyze, RMAN backup etc. in Oracle database.• Monitoring of Data Center environment, Temperature, Humidity, water leakage, light, fire suppression system, UPS, Dehumidifiers etc and taking necessary steps if needed.• Communicate and work with vendors for different servers of datacenter. Show less
Assistant Manager, ICT Division
Dec 2015 - Jan 2023Officer, ICT
Feb 2010 - Dec 2015

SBAC Bank PLC.
Dec 2022 - nowExecutive Officer•Development and update ICT Security and Risk related policy and frameworks like ICT Security policy, ICT Risk Management Framework, Incident Management, Password policy, Backup & Restore policy, VAPT policy, BCP & DRP, Change Management, Patch management, Configuration management etc., as per regulatory guidelines and international standards.•Identify, assess, evaluate, treatment and communicate internal and external information security risks and security issues of information assets as per ICT risk management framework.•Design and implement appropriate administrative, physical and technical controls in consultation with process owners to ensure availability, integrity and confidentiality of information assets.•Work with internal/external auditors and outside consultants as appropriate on required security assessments and audits.•Prepare compliance report for different regulatory and others like Bangladesh Bank, ICT Ministry, BGD e-GOV CIRT , BIBM etc.•Train, guide and act as an internal resource on Information Security functions to other departments. Manage the security awareness training programs and strategies to address awareness and training for all stakeholders.•Define ICT security requirements and measure compliance, based on Bank’s policies/procedures, applicable laws, regulations and best practices.•Network Security monitoring via different monitoring tools such as SIEM, IPS, IDS.•Conduct VAPT to detect different system flaws using standard tools.•Prepare action plans for Network Security related emergencies and alarms.•To implement IS security related standards like ISO 27001/2, PCI-DSS etc. Show less
Licenses & Certifications

Oracle Database SQL Certified Expert
OracleSept 2013
IBM Tivoli Storage Manager 6.3 Implementation And Administration
IBMMar 2014
Certified in Cybersecurity
ISC2
ISO/IEC 27001:2022 LA (ISMS)
BSIOct 2023- View certificate

Certified Information Systems Auditor® (CISA)
ISACAApr 2016 
Certified Ethical Hacker (CEH)
EC-CouncilJun 2021
Foundation Course on Banking
BASIC Bank LtdOct 2013
Languages
- enEnglish
- beBengali
Recommendations

Michael ruane
RetiredBallina, County Mayo, Ireland
Ibrahim alsharari
Engineer - Supply chain management - Logistics - Safety and Health - Process Optimizationالسعودية
Kenyarda scott
Deputy DirectorUnited States
Yang xiang
Founder of BanBai APPJiangsu, China
Adib havaldar, p.eng.
Design EngineerWaterloo, Ontario, Canada
Vel murugan v
Owner-Sri Ramakrishna Cottage IndustriesBengaluru, Karnataka, India
Avinash thiagarajan
Senior Solution Engineer || Product Consultant || Presales Engineer || B2B SaaS || ITSM || ESM Ticke...Chennai, Tamil Nadu, India
Sumit verma
Senior Associate Technical Support | Global IT Manage | GreystarSahibzada Ajit Singh Nagar, Punjab, India
Giuseppe malara
Project Manager presso Syskoplan ReplyRome, Latium, Italy
Deryck clarke
French hornist, Arts Education Advocate, Director of Educational Program, The Harlem Chamber PlayersRichmond County, Georgia, United States
Hanan safwat
Assistant Director, Accounts Payable at the American University in CairoEgypt
Chhamta shukla
Hospital/Healthcare Administration | DPSRUDelhi, India
Musharrat a.
Content Writer || Project Manager || CopywriterDhaka, Bangladesh
Marci skolnick
Show Caller, Tour Manager, Stage Manager, Event Manager, Collaborator. Helping you tell your best st...Las Vegas, Nevada, United States
Kaniz fatema
Student Counselor at Australian International School, DhakaDhaka, Dhaka, Bangladesh
Gislaine righi
R & S Coordinator / HR & T & D Coordinator / Coach / DISC / Speaker / HR Business PartnerSão Paulo, São Paulo, Brazil
Sali abdulnour, p.eng, pmp®
Certified Professional Engineer | Skilled in Project Management and Business Development | Proven su...Greater Montreal Metropolitan Area
Tom weirich
Standards Lab Technician at Stoneridge ElectronicsMansfield, Ohio, United States
Michael yang
Investment Manager at Chemchina Petrochemical CorporationChina
Santiago spago
Data Analyst | SQL | Python | Power BI | Looker Studio | Political Science | International RelationsBuenos Aires, Buenos Aires Province, Argentina
...