I will conduct nist csf maturity assessment and enterprise risk analysis

United Arab Emirates

I speak English, Sinhala

Assistant Manager Security Cyber Resilience

Certified ISO/IEC 27001:2022 and 27701 Lead Auditor with 9+ years in GRC consulting across banking, telecom, government, and healthcare in the UAE and Sri Lanka. I've delivered 16+ security and compli...
About this Gig

I bring 9+ years assessing and managing enterprise risk, including an 18-month enterprise risk framework build for a leading regional bank (regulator-mandated), using scenario-based threat modeling, a scalable risk register, and real-time reporting dashboards. I've also run IT general controls audits that identified 84+ control gaps other reviews had missed.


What you get:

  • NIST CSF 2.0 maturity assessment across all six functions (Govern, Identify, Protect, Detect, Respond, Recover)
  • Risk register with likelihood/impact scoring and treatment plans
  • Enterprise risk appetite and KRI framework (for organizations building or refreshing ERM)


Findings are built around how your organization actually operates, not a generic six-function checklist you could fill out yourself.

My Portfolio