Canada
I’m a Cybersecurity & GRC professional passionate about helping organizations transform security and compliance into strategic business enablers-not just audit requirements. With experience across banking, consulting, and digital asset environments, I’ve led and supported initiatives in enterprise risk management, control implementation, and audit readiness, ensuring organizations stay secure, compliant, and resilient in rapidly evolving threat landscapes. My core expertise lies in risk assessments, governance frameworks, and control validation, with hands-on experience across NIST CSF 2.0, NIST SP 800-53, ISO 27001, PCI DSS, and SOC 2. I’ve worked closely with stakeholders to build risk registers, KPI/KRI-driven reporting, and maturity assessments that enable leadership to make informed, risk-based decisions. As organizations increasingly adopt emerging technologies, I am actively focused on AI governance and AI risk management—applying structured AI frameworks, ethical AI principles, and model risk considerations to ensure secure, responsible, and compliant AI adoption. I’m particularly interested in how AI governance integrates with existing GRC programs to manage evolving regulatory and operational risks. I also bring strong exposure to cloud security, supporting risk assessments and control alignment across cloud environments with a focus on identity & access management, data protection, and shared responsibility models. What differentiates me is my ability to connect the dots between cybersecurity, compliance, and emerging technologies like AI, translating complex risks into clear, actionable insights for both technical teams and business leaders. 🚀 I’m currently seeking opportunities in Canada where I can contribute to building scalable GRC programs, strengthening cyber resilience, and advancing AI governance capabilities. #Cybersecurity #GRC #RiskManagement #CyberRisk #AI #AIGovernance #ResponsibleAI #CloudSecurity #InfoSec #Compliance #Audit #NIST #ISO27001 #SOC2 #PCIDSS #ThirdPartyRisk #IAM #DataSecurity
- Led comprehensive risk assessments across web applications, network environments, and enterprise systems, identifying vulnerabilities and recommending mitigation strategies. - Developed and implemented governance reporting structures, including KPI and KRI frameworks, improving risk visibility and executive decision-making. - Maintained and managed enterprise risk registers, ensuring accurate tracking, prioritization, and remediation of identified risks. - Supported large-scale client engagements in implementing security controls aligned with NIST SP 800-53, enhancing overall compliance posture. - Conducted cybersecurity maturity assessments based on NIST CSF 2.0, identifying control gaps and delivering actionable roadmaps. - Leveraged AI-enabled tools (e.g., Napkin.ai) to streamline reporting, build executive presentations, and create risk architecture diagrams, improving operational efficiency. - Collaborated with cross-functional stakeholders to align security, risk, and business objectives across multiple domains.
- Supported PCI DSS v4.0 readiness by validating controls in Cardholder Data Environments and collaborating with QSAs. - Conducted control testing and documented compliance gaps with risk-based remediation suggestions. - Assisted with audit evidence collection and control mapping, improving readiness and efficiency. - Developed and implemented security policies for Access Control, Encryption, Incident Response, and Change Management. - Performed risk assessments across systems and third-party environments to improve overall control maturity.
- Performed risk-based assessments of customer activity, transactions, and operational processes in a regulated cryptocurrency environment - Identified and escalated fraud and compliance risks, contributing to prevention of $250K+ in potential losses - Documented risk scenarios, control observations, and remediation actions to support audit defensibility - Collaborated with Legal, Compliance, Security, and Operations teams to remediate audit findings and strengthen governance controls - Supported compliance monitoring and reporting aligned with AML/KYC and regulatory requirements
- Assisted in embedding governance, risk, and compliance controls into SDLC and Agile delivery processes. - Identified delivery, operational, and compliance risks, collaborating with technical and governance teams on mitigation strategies. - Supported audit readiness by ensuring adherence to change management, documentation, and control requirements. - Improved risk visibility through standardized issue tracking and management reporting.
- Supported IT governance and compliance activities, including access control reviews and audit evidence preparation. - Conducted control testing and contributed to zero non-compliance findings across audit cycles. - Assisted with incident documentation, root cause analysis, and corrective actions. - Collaborated with infrastructure and security teams to validate control effectiveness and policy compliance