Information Security Consultant at Sentry Cyber (2025-06 – 2026-07)
- Supported ISO 27001 compliance engagements across multiple concurrent clients, including gap assessment, control mapping, and evidence collection, contributing to audit-ready packages that cleared external review without rework.
- Conducted Essential Eight ML1–ML2 maturity assessments against ACSC criteria across multiple client engagements, identifying an average of 10+ control gaps per engagement and delivering risk-prioritised remediation roadmaps tied directly to client business risk.
- Incorporated APRA CPS 234 considerations into ISO 27001 gap reporting for insurance-sector clients, supporting client review of prudential risk obligations.
- Assessed and evidenced logical and privileged access controls (ITGC: access management domain) across Microsoft Entra ID (Conditional Access, RBAC, audit logs) and Google Workspace Admin (DLP, audit logs, OAuth), producing ISO 27001 Annex A-mapped, audit-defensible control evidence in place of ad hoc screenshots.
- Validated MFA, privileged access, and user access controls using IRONSCALES email threat telemetry and Keeper Security access logs, shifting client compliance evidence from policy existence to demonstrated control effectiveness.
- Supported tabletop exercises on client Incident Response playbooks, identifying decision-making bottlenecks and contributing to revised escalation procedures.
GRC Analyst at Monash University (2025-01 – 2025-06)
- Built and maintained a 30-control risk register dual-mapped to NIST CSF and ISO 27001 Annex A, serving as the primary input for quarterly governance reporting to senior university stakeholders.
- Reduced outstanding high-severity risk findings by 30% over 6 months by coordinating structured treatment plans across risk owners, tracking remediation progress, and documenting risk acceptance rationale for each closed item.
- Conducted ISO 27001 A.15-aligned vendor risk assessments for 5+ cloud and software suppliers, with outputs integrated directly into the university's supplier due diligence process.
- Developed a data classification policy and information asset inventory aligned to ISO 27001 A.5.9 and A.5.12, establishing governance baselines for asset ownership and data handling across critical university systems.
GRC & Data Compliance Analyst at Aussizz Group (2024-07 – 2024-11)
- Contributed to an internal data governance review mapping personal information handling practices against APP 3 (collection), APP 6 (use/disclosure), and APP 11 (security), producing a findings summary adopted into the organisation's privacy compliance documentation.
- Identified and resolved 5–8 data integrity incidents per day (500+ over the engagement) using root-cause triage, reducing repeat error patterns by 20% in the final quarter.
- Enforced RBAC and document handling protocols over passport scans, visa records, and tax file numbers, with zero data handling incidents or privacy breaches recorded during tenure.
IT Risk Analyst at Zoho Technologies (2022-06 – 2023-12)
- Executed a continuous audit programme across APAC business and technology operations, collaborating with regional engineering and product stakeholders to assess 160+ controls against ISO 27001, ISO 27017, ISO 27018 and GDPR requirements.
- Conducted 6+ formal domain audits annually and monthly pulse-check samplings targeting privileged access logs, offboarding revocations, and high-risk control areas.
- Enforced least-privilege access controls across internal systems by auditing employee access logs, identifying and remediating 30+ excessive privilege accounts, ensuring customer data access was restricted to a temporary, need-to-know basis with zero access-related incidents recorded during tenure.
- Facilitated 12+ structured RCSA workshops with engineering and product teams, identifying 40+ operational and technical risks including undocumented API dependencies and insufficient logging on legacy modules, delivering mitigation strategies adopted prior to feature go-live.