Riyadh, Saudi Arabia · MSc · CISSP · CISM · ISO 27001 LI · ITIL
Mohamed S. Murad
Senior IT Leader Infrastructure · Cloud · Security · Service Excellence
Twenty+ years building and running the enterprise technology that a SAMA-regulated lender and MENA's largest fitness operator depend on — translating business strategy into infrastructure, cloud and governance that hold up under audit, and proving it in availability, recovery time and cost.
01 — About
An IT executive built on operations, not slideware.
I lead enterprise IT infrastructure for Leejam Sports Company (Fitness Time), the largest operator of sports and fitness centres in MENA — 230+ branches across Saudi Arabia and the UAE, more than 500,000 active members, and the technology estate that keeps all of it running. Over twenty years I have built and operated that layer across four sectors — financial services, sports and leisure, real estate and industrial manufacturing — each with its own regulator, scale and failure modes.
The work has a consistent shape: take a business objective, translate it into infrastructure and governance that survives an audit, then prove the outcome in numbers — availability, recovery time, risk reduction, cost avoided. That has meant standing up cybersecurity and cloud functions from nothing, governing an eight-figure budget, and reporting to the executive table in the language of the business rather than the language of the stack.
I am now focused on Head of IT Infrastructure, IT Director, VP and C-suite technology roles in organisations where the digital agenda is central to Saudi Vision 2030 — and where scale, regulation and pace all have to be handled at once.
02 — Experience
Two decades of infrastructure that had to work.
Roles led with outcome, not remit. Figures below are drawn from departmental performance and annual reporting.
-
IT Infrastructure & Security Manager
Leejam Sports Company (Fitness Time)
Largest operator of sports and fitness centres in MENA. 230+ branches across KSA and UAE · 500k+ active members · 5k+ employees.
- Migrated on-premises data-centre workloads to a resilient multi-cloud platform serving all member web and mobile channels — application response time down ~73% (1.3s → 350ms), availability up from 99.5% to 99.9%, and annual infrastructure run-cost cut from ~SAR 1.2M to ~SAR 675K.
- Built the Network Operations Centre and enterprise observability capability from scratch to 100% monitoring coverage and 99.99% availability on critical revenue systems, halving Mean Time to Repair.
- Rebuilt disaster recovery on cloud active-active replication: RTO reduced by over 90% to a validated ≤6-hour target, RPO to near-zero data loss, and DR test cycles from five days to four hours.
- Govern an eight-figure annual infrastructure budget and lead 15+ engineers across infrastructure, cloud, network, security and end-user support — having established the dedicated Cybersecurity and Cloud functions from the ground up.
-
Infrastructure & Security Manager
Dar Al Tamleek
Leading Saudi mortgage and home-finance institution, regulated by the Saudi Central Bank (SAMA).
- Led a Kingdom-wide network and security transformation — next-generation firewalls, SDWAN, ZTNA, NAC, PAM, EDR, NDR, DLP with data classification, SIEM, secure mail gateway and sandboxing — advancing maturity across all six SAMA Cybersecurity Framework domains and delivering successful regulatory audits.
- Architected and operated multi-site high-availability infrastructure (primary data centre plus DR site) on Dell VXRail, VMware vSphere clustering, SAN storage and RecoverPoint replication; authored the IT Disaster Recovery Plan and executed live DR activations during genuine business interruptions, restoring full service inside committed recovery windows every time.
- Served as technical lead on both the Cybersecurity Committee and the Business Continuity Management Committee, owning DR strategy, site readiness and the continuity plan for all technology assets — alongside vendor negotiation across multi-year agreements and an enterprise-wide security awareness programme.
-
Systems Administrator
Dar Al Tamleek
- Architected and built the company's entire infrastructure from day one — servers, storage, Active Directory, LAN/WAN, the primary data centre and the DR site — establishing the foundation the business scaled on for the next fifteen years.
- Deployed clustered Microsoft Exchange (DAG) and SQL Server for high availability on mission-critical systems, with firewalls, IPS, VPN, proxy and endpoint protection across the estate.
- Delivered 30+ systems tied to business growth including IP-PBX, VoIP, videoconferencing and backup/recovery, achieving up to 85% cost savings through procurement strategy.
-
Systems Administrator
Al-Sorayai Trading & Industrial Group
- Modernised the legacy network and established WAN connectivity linking the data centre to multiple factories and divisions across the Kingdom.
- Administered Active Directory, DNS, DHCP, mail server and corporate intranet supporting fast-growing manufacturing operations, and drove upgrades for performance, reliability and scalability.
-
Technical Support Engineer
AQAR Holding Co. / SIMTIX Co.
- Built the company's IT infrastructure from scratch — domain, Active Directory, servers and network — and owned ongoing support across hardware, software and connectivity.
Selected programmes
A representative slice of the delivery portfolio. Where a source gave a range, the conservative end is used.
-
2024 — 2025 · Programme lead
Data Centre to Multi-Cloud Migration
On-premises workloads moved to a resilient AWS/Azure platform with cloud-native security, automated backup and recovery, and headroom for national campaign traffic.
- ~73% faster response
- 99.9% availability
- ~SAR 525K saved p.a.
-
2024 — 2025
Disaster Recovery Rebuild
Cloud-based active-active replication with full risk assessment, redundancy design and a recurring simulation programme — continuity that can be demonstrated, not just documented.
- >90% RTO reduction
- ~0 data loss (RPO)
- 5d → 4h DR test cycle
-
2023 — 2025
NOC, Observability & Incident Management
Built from scratch and consolidated onto a single pane of glass — full-stack APM, distributed tracing with automatic dependency mapping, AI-powered anomaly detection, real user monitoring and integrated on-call.
- 100% coverage
- 99.99% critical availability
- −50% MTTR
-
2024 — 2025 · Enterprise-wide
Enterprise Security Controls Hardening
Firewall policy tightened across head office and every club, AI-driven detection enabled at the WAF and CDN layer, Active Directory RBAC refactored into a role-based model, SSO and MFA rolled out, and the development environment isolated from public exposure.
- +60% proactive threat identification
- +150% suspicious email detection
- Department-level risk-based policy
-
2025 · With engineering
DevSecOps & VAPT in the SDLC
Automated security and compliance gating inside CI/CD — builds blocked on vulnerability detection, findings raised straight into Jira, VAPT embedded across 6+ applications.
- Weeks → hours remediation
- +40% pipeline speed
- Zero critical vulns in prod
-
2025 · Enterprise-wide
Cyber Awareness & Human Risk
Scenario-based modules, simulated phishing and leadership tabletop drills, measured on executive dashboards — content built in-house, avoiding ~SAR 80K in external cost.
- −43% phishing click rate
- 2% → 66% reporting rate
-
2024 — 2026 · 230+ sites
Centralised Endpoint Management
One platform for deployment, patching, remote support and configuration governance, with enforced baselines and full inventory visibility across every corporate device.
- −50% on-site visits
- −81% highly vulnerable systems
- −40% resolution time
-
2016 — 2023 · Dar Al Tamleek
SAMA Cybersecurity Framework Programme
Technical lead on the Cybersecurity Committee of a SAMA-regulated lender — baseline assessment, a multi-year maturity roadmap, ISO 27001-aligned policy and procedure, risk treatment, incident response and audit evidence.
- All 6 framework domains advanced
- Successful SAMA regulatory audits
- ISO 27001-aligned policy set
03 — Core competencies
Where I create leverage.
IT Strategy & Digital Transformation
Multi-year technology roadmaps tied to business outcomes, budget cases and board-level approval — aligned to the Saudi Vision 2030 digital agenda.
Cloud Architecture & Migration
Hybrid and multi-cloud target-state design, phased workload migration, cloud-native security and post-migration cost optimisation.
Enterprise Infrastructure Operations
Data centre, platform services, virtualisation, storage and network operating at national scale across hundreds of sites.
IT Service Management (ITIL)
Service standards, incident and change discipline, ITSM platform rollout and measurable MTTR improvement across the organisation.
Cybersecurity & Governance
Defence-in-depth architecture, SIEM and SOC operations, identity and access, and framework-led programmes — SAMA CSF, ISO 27001, NCA, PDPL.
Business Continuity & Disaster Recovery
DR architecture, RTO/RPO definition, BCP ownership and validated failover exercises — including live activations during real interruptions.
Monitoring, Observability & AIOps
Full-stack observability, NOC establishment, AI-driven anomaly detection and executive dashboards linking IT health to business KPIs.
Budget Ownership & Cost Optimisation
Eight-figure budget governance, TCO modelling and sustained multi-year savings without trading away availability or security posture.
Vendor Management & Negotiation
Contract strategy and commercial negotiation across major technology partners, with accountability for delivery and ROI.
Team Leadership & Capability Building
Building specialised functions from the ground up, developing engineers into owners, and structuring teams around business units.
Regulatory Compliance & Risk
Risk assessment and treatment, policy and control frameworks, audit readiness and evidence — proven in a SAMA-regulated environment.
Automation, AI & DevOps Enablement
Infrastructure as code, CI/CD security gating, workflow automation and AI agent orchestration as a route to autonomous IT operations.
04 — Credentials
Education & certification.
Education
MSc, Internet Systems Development
University of Portsmouth, United Kingdom
BSc (Honours), Computer Science
Sudan University of Science and Technology
Professional certification
CISSP
Certified Information Systems Security Professional
CISM
Certified Information Security Manager, ISACA
ISO/IEC 27001 Lead Implementer
Information Security Management Systems
ITIL Foundation
IT Service Management
MCSA · MCP · CIW Associate
Microsoft & Certified Internet Webmaster
Executive & specialist training
Generative AI for Executives and Business Leaders
IBM · Coursera
Digital Transformation
University of Virginia · Coursera
Cloud Computing Professional Consulting
Arcitura Education
Cybersecurity: Technology, Applications and Policy
MIT
PMP® Preparation · Diploma in Project Management
Project delivery and governance
KPI Masterclass · The Bullet Proof Manager
The KPI Institute · CRESTCOM
05 — Curriculum vitae
The full record.
The complete curriculum vitae — full role history, competency detail, certification and training — is available to preview here or download as a PDF.
Download CV (PDF) Open in a new tab →06 — Contact
Let's talk.
Open to Head of IT Infrastructure, IT Director, VP and C-suite technology conversations across the Kingdom and the wider GCC.
- Email mohamedmurad@outlook.com
- LinkedIn linkedin.com/in/mohamedmurad
- Telephone +966 58 204 4222
- Based in Riyadh, Saudi Arabia