A talented and enthusiastic Senior Information Security Assurance Consultant (ISACA member) with a background in GRC, Governance, Risk, Compliance & Resilience
Data Protection (GDPR)
Programme management
ISO 27001 Lead Implementation
CISM; & CRISC. I relish the challenge of being able to champion or support the building of a Cyber Security programme within an organisation based on a structured Enterprise Security Architecture (ESA) model such as SABSA or TOGAF and standards such as ISO 27001, as well as Risk Management Frameworks (RMF) such as ISO 27005, ISO 31000, ISO 27017, Cloud Security – CCSK, SSDLC – Secure Software Development Life-Cycle and NIST800-30/57. Apart from generally focusing on the main tenets of C.I.A, as well as people, processes and technology, the approach adopted to build or bolster CS programmes normally focuses on four key components, namely: Operational
Management
Administrative; and, Educational. Instrumental in influencing senior stakeholders to accept change in order to address risk governance matters.
A talented and enthusiastic Senior Information Security Assurance Consultant (ISACA member) with a background in GRC, Governance, Risk, Compliance & Resilience
Data Protection (GDPR)
Programme management
ISO 27001 Lead Implementation
CISM; & CRISC. I relish the challenge of being able to champion or support the building of a Cyber Security programme within an organisation based on a structured Enterprise Security Architecture (ESA) model such as SABSA or TOGAF and standards such as ISO 27001, as well as Risk Management Frameworks (RMF) such as ISO 27005, ISO 31000, ISO 27017, Cloud Security – CCSK, SSDLC – Secure Software Development Life-Cycle and NIST800-30/57. Apart from generally focusing on the main tenets of C.I.A, as well as people, processes and technology, the approach adopted to build or bolster CS programmes normally focuses on four key components, namely: Operational
Management
Administrative; and, Educational. Instrumental in influencing senior stakeholders to accept change in order to address risk governance matters.