I am cybersecurity specialist with 10+ years in GRC, SOC operations, and risk management, delivering technical security frameworks for enterprises handling sensitive data.
What I Deliver
- ISO 27001: ISMS framework design, risk assessment automation, SoA mapping, and control validation.
- NIST CSF / 800-53 / 800-171: Control mapping, security baselines, and continuous monitoring workflows.
- HIPAA: PHI data flow analysis, encryption & access control review, technical safeguard implementation.
- GDPR: Data lifecycle audit, DPIA, DPO guidance, and integration of privacy-by-design controls.
- All type of Security standard complete documentation , policies , procedures and audits
Technical Focus
- Asset classification, threat modeling & risk scoring
- Penetration testing and vulnerability scanning
- Security control configuration (SIEM, IAM, DLP, Endpoint)
- Policy & procedure automation via compliance tools
- Incident response playbooks and evidence mapping for audits
Why Me
- ISO 27001 Lead Implementer (PECB)
- Experience with IBM QRADAR, Splunk SOC, cloud security, and forensic analysis
- Proven delivery for multinational fintech, healthcare, and SaaS environments
- Audit experienced