Cybersecurity / GRC

Building the controls that make good work scale.

I'm Abdulmohsen Alnowayhi, a Computer Science with AI and Cybersecurity graduate turning security requirements, business rules, and messy handoffs into practical systems.

CASE FILE / 2026RIYADH / KSA

The throughline

Make the process clear. Make the control usable. Make the record trusted.

Available for GRC opportunities

01 / Profile

Security is a business enabler.

My work sits between technical delivery, privacy, and the people who make controls real. I'm currently a Sales Specialist at Saudi Liebherr, while staying focused on the cybersecurity and GRC path that shaped my degree and projects.

The projects below show how I operate at a professional level: I map the real process, identify where trust can break, design controls around people and roles, and leave behind a system that saves work instead of adding bureaucracy.

2

Liebherr platforms shaped

200+

participants' data handled

99.8%

attendance accuracy

9k+

automation reach

02 / Capabilities

GRC & compliance

PDPL reviews, risk concepts, policy application, control thinking, and practical documentation.

Privacy by design

Data minimisation and secure handling translated into usable internal products and workflows.

Security operations

Access control, incident escalation, security awareness, and confidential data handling.

03 / Selected work

Projects with a point of view.

Not just what I built—why it mattered, what I controlled, and how it made the organisation more efficient.

01

CURRENT / BUSINESS SYSTEMS

Lead-to-cash control system

Liebherr Saudi Arabia

A production CRM for heavy-equipment deals, designed around how the business actually sells. I helped turn informal authority structures into a traceable digital process that moves a deal from first contact to final payment.

  • Division-level access and segregation of duties
  • Approval queues with margin and pricing governance
  • Document traceability and a visible deal metro
  • Finance controls that make sensitive decisions accountable
Made complex commercial governance auditable and operational

02

CURRENT / SERVICE OPERATIONS

Service operations platform

Liebherr Saudi Arabia

I replaced a single-file calculator with a multi-user service-order workflow. One trusted service record now connects the engineer on site, supervisor review, timekeeper validation, customer signature, and invoice generation.

  • Role-based handoffs for engineers, supervisors, and timekeepers
  • Customer signatures, hour classification, and expense tracking
  • Party-specific invoicing from the same source record
  • Audit history and controlled correction requests
Saved double work by making one signed record drive the entire process

03

SECURE DEVELOPMENT / PDPL

Privacy-first internal communications

Deployed internal application

Designed, built, and deployed a password-gated internal web application for focused company communication. The product deliberately collects no personal data and was reviewed through a Saudi PDPL lens.

  • HTTPS and password-gated access
  • Brute-force lockout protection
  • Minimal data collection and intentionally small attack surface
  • Practical privacy controls that users can actually follow
Completed a PDPL compliance review

04

AUTOMATION / DATA INTEGRITY

Validation-driven quotation tool

Commercial operations

A quotation workflow that makes sensitive commercial details safer to handle. I embedded division-based controls around banking details, contractual clauses, and authorised signatories instead of leaving those checks to memory.

  • Validation before a quotation can move forward
  • Controls for banking and contractual information
  • Authorised-signatory checks by division
  • Reduced avoidable rework and integrity errors
Removed recurring data-integrity errors

05

HUMAN RISK / NCA GRANT

Phishing simulation & awareness platform

Final-year cybersecurity project

A working prototype built to make human-factor risk measurable. The platform combines phishing simulation, awareness activity, and performance tracking so security teams can improve behaviour with evidence rather than assumptions.

  • Human-factor risk assessment
  • Security-awareness campaign structure
  • Performance tracking for learning outcomes
  • Governance-minded approach to security culture
Recognised through the NCA Cybersecurity Pioneer Grant

04 / Experience

An operator's view of risk.

Every role has sharpened the same instinct: protect the information, make the process reliable, and escalate early.

Sales Specialist

Saudi Liebherr Company · Riyadh

May 2026 — Present

Alongside my commercial role, I am helping shape two internal platforms that reflect how the company operates. I translate sales, finance, approvals, service handoffs, document controls, and division boundaries into systems that reduce ambiguity, protect sensitive data, and give leadership a traceable view of work.

Event Operations Specialist

Saudi Equestrian Events Company · Riyadh

Nov 2025 — May 2026

Managed confidential accommodation data for 200+ international participants and coordinated access-control and security deployment across venues.

Small Power Technician Supervisor

Rouad Alsaraya · Freelance

Mar 2026 — May 2026

Supervised compliant small-power operations at AFC Tournament venues, conducting inspections and coordinating contractors.

IT & BOH Supervisor

Blink Experience · Riyadh

Oct 2025 — Nov 2025

Delivered first-line IT support, resolved infrastructure issues, and escalated incidents through documented response procedures.

IT Specialist & Administrator

3points Crowd Management · Riyadh

Jul 2023 — Sep 2023

Ran attendance verification for 1,000+ staff at 99.8% accuracy with zero security breaches, plus WhatsApp API automation reaching 9,000+ individuals.

05 / Contact

Let's make security easier to act on.

Open to conversations about entry-level GRC, compliance, privacy, and security operations opportunities.