Application Security and Saudi PDPL, done properly.
I lead application security at Cyberia, a Saudi telecom. I publish weekly on secure coding, API security, and Saudi PDPL. I'm building GRC Core for teams that live under NCA ECC, CCC, and PDPL.
What I'm writing
What I've delivered at Cyberia
Reduction in application vulnerabilities across the tracked estate.
Reduction in application audit findings across three cycles.
To deliver Phase 1 of the regulatory compliance program.
Three areas of practice
Application Security
Secure SDLC, OWASP, secure design reviews. NCA ECC and CCC.
Compliance & Privacy
Saudi PDPL, consent management, data mapping, audit readiness.
Building
GRC Core, in development. Multi-tenant GRC for teams under NCA and PDPL.
GRC Core
A multi-tenant GRC platform designed for the shape of Saudi regulation. Controls modeled against NCA ECC, CCC, and PDPL instead of retrofit from generic frameworks.
Built by someone who has run these audits, not read about them.
