Riyadh, Saudi Arabia

ramielshafei

I make sure technology work is defensible, worth the money, and actually gets built.

Nineteen years across telecom operations, digital consulting, and portfolio, product and project control. Audit, certification and security on one side, the business case and the market on the other, and I build the systems myself.

  • Get in touch
  • Arabic · English
  • MSc Cybersecurity
  • MSc Project Management
  • PMP · CISM · CEH

2007Nineteen years2026

Telecom operations Consulting Products & projects control

Where the experience comes from

  • National telecom operator2007–2018
  • Digital business consulting2018–2019
  • Enterprise solutions provider2019–now
  • 3limakFounder
Rami Elshafei

About

the short version

Most failures in a technology portfolio are not purely technical or purely managerial. They sit in the seam between the two — a risk assessed but never designed against, a control agreed but never evidenced, a delivery plan that ignores what compliance will cost. I work that seam.

Two master's degrees frame how I approach it: one in cybersecurity, one in project management. Managing a portfolio taught me the other half — that a control which cannot be paid for is not a control, so the business case, the financials and the route to market belong in the same conversation as the risk.

I lead the certification and audit programmes that put evidence behind the claim, and I govern products across their whole life — idea, business case, security requirements, launch, and eventually retirement. And I do not stop at the recommendation: I build the dashboards, the automation and the AI platforms that carry it out.

What I do

six families of work

They overlap by design. One governance decision usually becomes a business case, a process change, a security requirement and a dashboard at the same time.

01

governance & assurance

Making sure what gets built can be defended — to an auditor, a regulator, or a customer’s security team.

  • Control frameworks & policy
  • Governance of the product lifecycle
  • Risk & compliance programmes
  • Business continuity & recovery
  • Regulatory requirements
02

audit & certification

Leading the programmes that put evidence behind the claim, and answering the findings when they come.

  • Internal & external audit
  • Project & product management audit
  • ISO 27001 certification programmes
  • PCI DSS · CMMI · business continuity
  • Finding response & closure
03

portfolio & commercial

Deciding what deserves the capital, taking it to market, then holding what is funded to scope and budget.

  • Portfolio management
  • Business case assessment
  • Financial analysis, ROI & margin
  • Market & go-to-market
  • Acquisition & vendor due diligence
04

security assurance

Security designed into a product before launch, and proved after it — not reviewed once and filed.

  • Cybersecurity requirements
  • Security assessment & review
  • VA & PT remediation
  • Secure environment design
  • Access & identity governance
05

engineering & automation

Building the systems rather than specifying them and waiting — infrastructure through to interface.

  • AI platform engineering
  • Workflow automation
  • Approval & evaluation engines
  • Linux & server administration
  • Process design
06

data & decision support

Turning scattered operational data into something an executive can act on, with the right people seeing the right rows.

  • Dashboards & business intelligence
  • Role-based & row-level access
  • Advanced & predictive analytics
  • Large-scale pipelines
  • Customer experience analytics

Product lifecycle

idea to retirement

A product is a governed object for its whole life, not just at launch. Each gate below has an owner, an evidence requirement and a decision.

01

idea

Problem, market and fit. Screened before anyone spends on it.

02

business case

Revenue model, cost to serve, ROI and the number it will be judged on.

03

design

Architecture, cybersecurity requirements and the compliance obligations it inherits.

04

onboard

Risk assessment, security testing, VA and PT remediation, and approval to launch.

05

operate

Change control, audit evidence, performance against the business case.

06

retire

Migration, data disposal, contract exit — closed properly rather than left running.

How I work

six stages, every time

The same sequence whether it is a compliance programme, an investment assessment or an AI platform. Most things fail at stage one or stage five.

01

frame

The problem, the users, the data it touches, and what "done" has to look like.

02

brief

A specification precise enough to hold under pressure, with phased delivery and acceptance criteria.

03

build

Infrastructure, data model and interface — iterated against the brief, not against impressions.

04

govern

Security review, data-protection position and a defined approval path before it touches real work.

05

operate

Monitoring, access control, uptime and cost. An unmonitored system is an unowned one.

06

improve

Measure where it saves time and where it fails, then fold the change back into the documented process.

What changes

before and after

Governance is easy to describe and hard to evidence. These are the shifts the work is meant to produce.

BeforeAudit findings absorbed to keep the peace, accountability landing wherever it fell.

then

AfterEvery finding answered on the evidence — agreed where it holds, disputed with business justification where responsibility sits elsewhere, closed with a package rather than a promise.

BeforeEach reporting cycle rebuilt by hand from scattered exports, late and slightly different every time.

then

AfterA pipeline that runs the same way every period — reconciled, formatted, reproducible, identical whoever presses the button.

BeforeAI stuck in permanent pilot, because nobody could answer the security and data-protection questions.

then

AfterA documented position on posture, data handling and approval, taken through stakeholders — so the capability reaches real work instead of expiring in evaluation.

BeforeApprovals living in email threads, reconstructed after the fact when someone asked who signed off.

then

AfterApproval designed as software — staged routing, explicit responsibility boundaries, and a trail that answers "who approved this, and when" as a query.

BeforeProducts funded on enthusiasm, with no shared view of what each one returns or costs to serve.

then

AfterEvery candidate scored the same way — business case, margin, cost to serve, market fit and risk — so the ranking survives the meeting where someone's favourite comes out low.

BeforeA good product launched into no particular market, positioned by whoever wrote the deck.

then

AfterA go-to-market position tied to the business case — who it is for, what it displaces, what it costs to serve them, and the number it will be judged on.

Scale, timelines and figures belong in a conversation rather than on a public page. Happy to go into detail.

Background

where this came from

2019 — nowRiyadh

chief specialist — products & projects control

Technology division, enterprise solutions provider

Portfolio management alongside governance, risk and compliance — business cases and financial assessment, go-to-market and product positioning, internal and external audit, executive reporting, and the AI and automation that carries it.

2018 — 2019Riyadh

senior consultant — digital business

Consulting practice

Digital transformation for clients: business cases, commercial modelling and revenue models, delivery and project management, with governance system implementation running alongside.

2007 — 2018Kingdom-wide

specialist — systems analyst

National telecom operator

Eleven years in operations and technical support at national scale — broadband, fibre, IP and IPTV — plus budgets, training and the first monitoring dashboards. The network fluency everything since rests on.

Education

  • Master's — CybersecurityMidocean University
  • Master's — Project Management
  • BSc — Information TechnologyArab Open University, Riyadh

Certifications

  • PMP — Project Management Professional
  • CISM — Certified Information Security Manager
  • CEH — Certified Ethical Hacker
  • PMO-CP · CompTIA Security+ · ITIL · Six Sigma

Standards led

  • ISO 27001Information security management
  • PCI DSSPayment card data security
  • CMMICapability maturity
  • Business continuityPlans developed and exercised
  • Internal & external auditProgramme leadership and finding closure

Also building

  • 3limak.com Arabic learning marketplace — courses, digital files and printed titles
  • maziktkSecond platform, in development

Get in touch

say hello

If something here is relevant to a problem you are working on, I am happy to talk it through. Questions and second opinions are welcome.

Rami Elshafei
  • Based inRiyadh, Saudi Arabia
  • Working languagesArabic and English
  • Reply timeUsually within two working days

send a message

Please do not include confidential data in this form.