Riyadh, Saudi Arabia  ·  MSc · CISSP · CISM · ISO 27001 LI · ITIL

Mohamed S. Murad

Senior IT Leader Infrastructure · Cloud · Security · Service Excellence

Twenty+ years building and running the enterprise technology that a SAMA-regulated lender and MENA's largest fitness operator depend on — translating business strategy into infrastructure, cloud and governance that hold up under audit, and proving it in availability, recovery time and cost.

Portrait of Mohamed S. Murad, IT Infrastructure and Security Manager, in a navy suit.

01 — About

An IT executive built on operations, not slideware.

I lead enterprise IT infrastructure for Leejam Sports Company (Fitness Time), the largest operator of sports and fitness centres in MENA — 230+ branches across Saudi Arabia and the UAE, more than 500,000 active members, and the technology estate that keeps all of it running. Over twenty years I have built and operated that layer across four sectors — financial services, sports and leisure, real estate and industrial manufacturing — each with its own regulator, scale and failure modes.

The work has a consistent shape: take a business objective, translate it into infrastructure and governance that survives an audit, then prove the outcome in numbers — availability, recovery time, risk reduction, cost avoided. That has meant standing up cybersecurity and cloud functions from nothing, governing an eight-figure budget, and reporting to the executive table in the language of the business rather than the language of the stack.

I am now focused on Head of IT Infrastructure, IT Director, VP and C-suite technology roles in organisations where the digital agenda is central to Saudi Vision 2030 — and where scale, regulation and pace all have to be handled at once.

02 — Experience

Two decades of infrastructure that had to work.

Roles led with outcome, not remit. Figures below are drawn from departmental performance and annual reporting.

  1. May 2023 — Present

    Riyadh, Saudi Arabia

    IT Infrastructure & Security Manager

    Leejam Sports Company (Fitness Time)

    Largest operator of sports and fitness centres in MENA. 230+ branches across KSA and UAE · 500k+ active members · 5k+ employees.

    • Migrated on-premises data-centre workloads to a resilient multi-cloud platform serving all member web and mobile channels — application response time down ~73% (1.3s → 350ms), availability up from 99.5% to 99.9%, and annual infrastructure run-cost cut from ~SAR 1.2M to ~SAR 675K.
    • Built the Network Operations Centre and enterprise observability capability from scratch to 100% monitoring coverage and 99.99% availability on critical revenue systems, halving Mean Time to Repair.
    • Rebuilt disaster recovery on cloud active-active replication: RTO reduced by over 90% to a validated ≤6-hour target, RPO to near-zero data loss, and DR test cycles from five days to four hours.
    • Govern an eight-figure annual infrastructure budget and lead 15+ engineers across infrastructure, cloud, network, security and end-user support — having established the dedicated Cybersecurity and Cloud functions from the ground up.
  2. Jan 2013 — Apr 2023

    Jeddah, Saudi Arabia

    Infrastructure & Security Manager

    Dar Al Tamleek

    Leading Saudi mortgage and home-finance institution, regulated by the Saudi Central Bank (SAMA).

    • Led a Kingdom-wide network and security transformation — next-generation firewalls, SDWAN, ZTNA, NAC, PAM, EDR, NDR, DLP with data classification, SIEM, secure mail gateway and sandboxing — advancing maturity across all six SAMA Cybersecurity Framework domains and delivering successful regulatory audits.
    • Architected and operated multi-site high-availability infrastructure (primary data centre plus DR site) on Dell VXRail, VMware vSphere clustering, SAN storage and RecoverPoint replication; authored the IT Disaster Recovery Plan and executed live DR activations during genuine business interruptions, restoring full service inside committed recovery windows every time.
    • Served as technical lead on both the Cybersecurity Committee and the Business Continuity Management Committee, owning DR strategy, site readiness and the continuity plan for all technology assets — alongside vendor negotiation across multi-year agreements and an enterprise-wide security awareness programme.
  3. Mar 2008 — Dec 2012

    Jeddah, Saudi Arabia

    Systems Administrator

    Dar Al Tamleek

    • Architected and built the company's entire infrastructure from day one — servers, storage, Active Directory, LAN/WAN, the primary data centre and the DR site — establishing the foundation the business scaled on for the next fifteen years.
    • Deployed clustered Microsoft Exchange (DAG) and SQL Server for high availability on mission-critical systems, with firewalls, IPS, VPN, proxy and endpoint protection across the estate.
    • Delivered 30+ systems tied to business growth including IP-PBX, VoIP, videoconferencing and backup/recovery, achieving up to 85% cost savings through procurement strategy.
  4. Jun 2005 — Mar 2008

    Jeddah, Saudi Arabia

    Systems Administrator

    Al-Sorayai Trading & Industrial Group

    • Modernised the legacy network and established WAN connectivity linking the data centre to multiple factories and divisions across the Kingdom.
    • Administered Active Directory, DNS, DHCP, mail server and corporate intranet supporting fast-growing manufacturing operations, and drove upgrades for performance, reliability and scalability.
  5. May 2003 — May 2005

    Jeddah, Saudi Arabia

    Technical Support Engineer

    AQAR Holding Co. / SIMTIX Co.

    • Built the company's IT infrastructure from scratch — domain, Active Directory, servers and network — and owned ongoing support across hardware, software and connectivity.

Selected programmes

A representative slice of the delivery portfolio. Where a source gave a range, the conservative end is used.

  • 2024 — 2025 · Programme lead

    Data Centre to Multi-Cloud Migration

    On-premises workloads moved to a resilient AWS/Azure platform with cloud-native security, automated backup and recovery, and headroom for national campaign traffic.

    • ~73% faster response
    • 99.9% availability
    • ~SAR 525K saved p.a.
  • 2024 — 2025

    Disaster Recovery Rebuild

    Cloud-based active-active replication with full risk assessment, redundancy design and a recurring simulation programme — continuity that can be demonstrated, not just documented.

    • >90% RTO reduction
    • ~0 data loss (RPO)
    • 5d → 4h DR test cycle
  • 2023 — 2025

    NOC, Observability & Incident Management

    Built from scratch and consolidated onto a single pane of glass — full-stack APM, distributed tracing with automatic dependency mapping, AI-powered anomaly detection, real user monitoring and integrated on-call.

    • 100% coverage
    • 99.99% critical availability
    • −50% MTTR
  • 2024 — 2025 · Enterprise-wide

    Enterprise Security Controls Hardening

    Firewall policy tightened across head office and every club, AI-driven detection enabled at the WAF and CDN layer, Active Directory RBAC refactored into a role-based model, SSO and MFA rolled out, and the development environment isolated from public exposure.

    • +60% proactive threat identification
    • +150% suspicious email detection
    • Department-level risk-based policy
  • 2025 · With engineering

    DevSecOps & VAPT in the SDLC

    Automated security and compliance gating inside CI/CD — builds blocked on vulnerability detection, findings raised straight into Jira, VAPT embedded across 6+ applications.

    • Weeks → hours remediation
    • +40% pipeline speed
    • Zero critical vulns in prod
  • 2025 · Enterprise-wide

    Cyber Awareness & Human Risk

    Scenario-based modules, simulated phishing and leadership tabletop drills, measured on executive dashboards — content built in-house, avoiding ~SAR 80K in external cost.

    • −43% phishing click rate
    • 2% → 66% reporting rate
  • 2024 — 2026 · 230+ sites

    Centralised Endpoint Management

    One platform for deployment, patching, remote support and configuration governance, with enforced baselines and full inventory visibility across every corporate device.

    • −50% on-site visits
    • −81% highly vulnerable systems
    • −40% resolution time
  • 2016 — 2023 · Dar Al Tamleek

    SAMA Cybersecurity Framework Programme

    Technical lead on the Cybersecurity Committee of a SAMA-regulated lender — baseline assessment, a multi-year maturity roadmap, ISO 27001-aligned policy and procedure, risk treatment, incident response and audit evidence.

    • All 6 framework domains advanced
    • Successful SAMA regulatory audits
    • ISO 27001-aligned policy set

03 — Core competencies

Where I create leverage.

  • IT Strategy & Digital Transformation

    Multi-year technology roadmaps tied to business outcomes, budget cases and board-level approval — aligned to the Saudi Vision 2030 digital agenda.

  • Cloud Architecture & Migration

    Hybrid and multi-cloud target-state design, phased workload migration, cloud-native security and post-migration cost optimisation.

  • Enterprise Infrastructure Operations

    Data centre, platform services, virtualisation, storage and network operating at national scale across hundreds of sites.

  • IT Service Management (ITIL)

    Service standards, incident and change discipline, ITSM platform rollout and measurable MTTR improvement across the organisation.

  • Cybersecurity & Governance

    Defence-in-depth architecture, SIEM and SOC operations, identity and access, and framework-led programmes — SAMA CSF, ISO 27001, NCA, PDPL.

  • Business Continuity & Disaster Recovery

    DR architecture, RTO/RPO definition, BCP ownership and validated failover exercises — including live activations during real interruptions.

  • Monitoring, Observability & AIOps

    Full-stack observability, NOC establishment, AI-driven anomaly detection and executive dashboards linking IT health to business KPIs.

  • Budget Ownership & Cost Optimisation

    Eight-figure budget governance, TCO modelling and sustained multi-year savings without trading away availability or security posture.

  • Vendor Management & Negotiation

    Contract strategy and commercial negotiation across major technology partners, with accountability for delivery and ROI.

  • Team Leadership & Capability Building

    Building specialised functions from the ground up, developing engineers into owners, and structuring teams around business units.

  • Regulatory Compliance & Risk

    Risk assessment and treatment, policy and control frameworks, audit readiness and evidence — proven in a SAMA-regulated environment.

  • Automation, AI & DevOps Enablement

    Infrastructure as code, CI/CD security gating, workflow automation and AI agent orchestration as a route to autonomous IT operations.

04 — Credentials

Education & certification.

Education

  • MSc, Internet Systems Development

    University of Portsmouth, United Kingdom

  • BSc (Honours), Computer Science

    Sudan University of Science and Technology

Professional certification

  • CISSP

    Certified Information Systems Security Professional

  • CISM

    Certified Information Security Manager, ISACA

  • ISO/IEC 27001 Lead Implementer

    Information Security Management Systems

  • ITIL Foundation

    IT Service Management

  • MCSA · MCP · CIW Associate

    Microsoft & Certified Internet Webmaster

Executive & specialist training

  • Generative AI for Executives and Business Leaders

    IBM · Coursera

  • Digital Transformation

    University of Virginia · Coursera

  • Cloud Computing Professional Consulting

    Arcitura Education

  • Cybersecurity: Technology, Applications and Policy

    MIT

  • PMP® Preparation · Diploma in Project Management

    Project delivery and governance

  • KPI Masterclass · The Bullet Proof Manager

    The KPI Institute · CRESTCOM

05 — Curriculum vitae

The full record.

The complete curriculum vitae — full role history, competency detail, certification and training — is available to preview here or download as a PDF.

Download CV (PDF) Open in a new tab →

Your browser cannot display the PDF inline.

Download CV (PDF)
Curriculum vitae — Mohamed S. Murad

06 — Contact

Let's talk.

Open to Head of IT Infrastructure, IT Director, VP and C-suite technology conversations across the Kingdom and the wider GCC.

Or send a message directly.

Prefer email? mohamedmurad@outlook.com