Khwaja Naveed Rasheed Cybersecurity GRC · AI Security

About

The record

I am a cybersecurity governance executive with more than twenty years building security, risk and AI governance functions for large enterprises across insurance, banking, petrochemicals, energy and telecom. I currently serve as Director of Cybersecurity GRC at Tawuniya in Riyadh, where I own the enterprise cybersecurity governance, risk and AI security agenda and act as the company's interface to its regulators.

The work is consistent across every organisation I have joined: convert regulatory obligation into something assessed and defensible. That means a control library somebody can audit, a risk register the business actually uses, third-party assurance that survives contact with procurement, and — increasingly — an AI governance capability built from nothing in an organisation that has already deployed the models.

I write for the same reason. Three books published on Amazon in 2026, all of them aimed at the practitioner who has to produce the file an auditor will read rather than the reader who wants a survey of the field.

Experience

  1. 2023 — Present

    Director, Cybersecurity GRC

    Tawuniya · Riyadh, Saudi Arabia

    Own the enterprise second-line Cybersecurity GRC and AI Security functions end to end for one of the Kingdom’s largest listed insurers: framework, standards, risk, third-party assurance and regulator engagement.

    • Established the enterprise’s first AI governance capability — an AI TRiSM Framework and AI Security Standard across nine control domains, enforced by a five-gate assurance model.
    • Secured an independently assessed regulatory posture and directed the Insurance Authority’s consolidated self-assessment return.
    • Released 30+ cybersecurity standards and rebuilt the Cybersecurity Operating Model.
    • Cleared enterprise Generative AI for production across three cloud platforms with data-residency and vendor governance set as preconditions of go-live.
  2. 2022 — 2023

    Manager, Cybersecurity GRC

    Bupa Arabia · Jeddah, Saudi Arabia

    Matured the GRC function for a leading Saudi health insurer and advised on aligning security and privacy with an aggressive digital growth strategy.

    • Authored a three-year cybersecurity and privacy strategy carrying 40+ initiatives, and secured executive funding for it.
    • Designed and deployed an enterprise Third-Party Risk Management programme.
    • Implemented a GRC platform automating policy management, control testing and compliance tracking.
  3. 2021 — 2022

    Cybersecurity Architect

    Saudi National Bank · Jeddah, Saudi Arabia

    Key security authority through one of the region’s largest banking mergers, harmonising security and control frameworks across the combined entity.

    • Directed 100+ risk assessments across legacy and integrated systems.
    • Established Zero Trust and defence-in-depth as the merged bank’s architectural baseline.
  4. 2019 — 2021

    Cybersecurity Risk Analyst

    Samba Bank · Riyadh, Saudi Arabia

    Matured the bank’s information security risk programme and executive risk reporting.

    • Rebuilt the risk programme on ISO/IEC 27005 and OCTAVE Allegro.
    • Automated risk and privacy oversight in RSA Archer and built the CISO GRC dashboard.
  5. 2018 — 2019

    Team Lead, Global Cybersecurity Governance

    SABIC · Jubail, Saudi Arabia

    Led global governance for a multinational petrochemicals group across five regions.

    • Lifted measurable global security compliance 20% on SABSA and NIST CSF.
    • Redesigned enterprise GRC key performance indicators for group leadership.
  6. 2016 — 2018

    Senior Cybersecurity Architect

    Saudi Electricity Company · Jeddah, Saudi Arabia

    Senior security authority for the national utility, governing IT and OT environments.

    • Set architecture and control standards for critical national infrastructure.
    • Embedded security requirements into major capital infrastructure projects.

Earlier career. Gulf International Bank · Sui Southern Gas Company · Siemens / Scientechnic · Shell · Supernet — progressive security, risk and infrastructure roles across banking, energy and telecom.

Certifications & education

Security leadership

  • CISSP, (ISC)²
  • CISM, ISACA

Risk & audit

  • CRISC, ISACA
  • CISA, ISACA
  • ISO/IEC 27005 Senior Lead Risk Manager

Privacy & governance

  • CDPSE, ISACA
  • ISO/IEC 27001 Lead Implementer

Programme delivery

  • PMP, PMI
  • PMI-RMP, PMI
  • MSc Cyber Security Wrexham Glyndŵr University, United Kingdom 2021 — 2023
  • BSc Computer Science University of Karachi, Pakistan 2001 — 2005
  • AI Governance Saïd Business School, University of Oxford 2026
  • AI Governance & ISO 42001 Readiness BSI, five-course specialisation 2026
  • Managing AI Projects with Microsoft Microsoft Professional Certificate 2026

Frameworks & standards

Saudi & regional

  • NCA ECC-2:2024
  • NCA DCC · TCC · CCC · CSCC · OTCC
  • NCA AICG-1:2026
  • SAMA CSF
  • Insurance Authority CSF
  • IA Cybersecurity SAT 2026
  • SDAIA AI Ethics
  • PDPL
  • NDMO
  • CCHI

AI governance & security

  • AI TRiSM
  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • ISO/IEC 22989
  • NIST AI RMF
  • EU AI Act
  • MITRE ATLAS
  • OWASP LLM Top 10 (2025)

Governance & risk

  • ISO/IEC 27001:2022
  • ISO/IEC 27005
  • NIST CSF
  • NIST RMF
  • COBIT
  • SABSA
  • OCTAVE Allegro
  • STRIDE
  • Three Lines of Defense
  • Zero Trust
  • ISO 22301
  • GDPR