Anonymous
Details
Skills
Technology and Cyber Security GRC including Information Risk Management Security Frameworks (Assessment, Design, and Implementation) - ISO 27001, NIST, ISF, OWASP, CIS, Swift CSP, NCSC CAF, Cyber Essentials +, CSA CCM etc. ISMS Development and Maintenance using various frameworks and developing security policies. Enterprise and Technical Security Architecture (TOGAF, SABSA, CREST) Security Transformation and Target Operating Model Zero Trust Assessment, Design, and Implementation. Cyber Security Audits, Pen Tests and Assurance Data Protection and Privacy (around DPA and GDPR). Cloud Security (MS Azure, AWS, Google Cloud, O365). Security Development Lifecycle Management including security testing and SDLC security reviews. Identity and Access Management Review and Design Security Infrastructure, Operations and Services (SOC Architecture and Design MS Sentinel, Splunk, Qradar, Logrythm) Threat and Vulnerability Management (Tenable, Defender etc. IT Auditing (IT General Controls, Application Controls, Domain-specific deep-dives etc.) SOx and SOC 2 reviews and implementation Third Party Risk Management (over 50 engagements performed) Security Culture and Awareness Security Compliance Management
About
I am a highly experienced Cyber Security and Technology Consultant with over 15 years of global experience, including senior roles at PwC, KPMG, and leading industry organisations. I hold a CISSP, ISO 27001 Lead Auditor certification, and a Master s degree in Cyber Security, with deep expertise in GRC, Security Architecture, ISMS implementation, and risk management. I have led over 150 engagements across public and private sectors, delivering services aligned with ISO 27001, NIST, and Cyber Essentials standards. My skills include enterprise security architecture, threat and vulnerability management, cloud security, and third-party risk management. I am known for my analytical mindset, leadership, and strong communication skills, consistently driving security transformation and risk reduction.