Application Security and Saudi PDPL, done properly.

I lead application security at Cyberia, a Saudi telecom. I publish weekly on secure coding, API security, and Saudi PDPL. I'm building GRC Core for teams that live under NCA ECC, CCC, and PDPL.

20+ years in application securityWriting weekly on AppSec & Saudi PDPLRiyadh, Saudi Arabia

What I'm writing

What I've delivered at Cyberia

90%

Reduction in application vulnerabilities across the tracked estate.

~95%

Reduction in application audit findings across three cycles.

1.5 mo

To deliver Phase 1 of the regulatory compliance program.

Three areas of practice

Application Security

Secure SDLC, OWASP, secure design reviews. NCA ECC and CCC.

Compliance & Privacy

Saudi PDPL, consent management, data mapping, audit readiness.

Building

GRC Core, in development. Multi-tenant GRC for teams under NCA and PDPL.

IN DEVELOPMENT

GRC Core

A multi-tenant GRC platform designed for the shape of Saudi regulation. Controls modeled against NCA ECC, CCC, and PDPL instead of retrofit from generic frameworks.

Built by someone who has run these audits, not read about them.

Consulting, speaking, or a note about the writing.