I operate at the intersection of governance, risk, and compliance—translating regulatory complexity into structured, business-aligned security programs that drive trust, resilience, and growth.
With deep expertise across ISO standards including ISO 27001:2022, ISO 9001:2015, and ISO 20000, alongside frameworks such as SOC 2 and NIST, I specialize in building and scaling GRC functions that are both audit-ready and operationally efficient. My work spans the full lifecycle—from readiness assessments and internal audits to certification enablement, policy architecture, and continuous improvement.
Over the years, I have partnered with organizations across banking, product, legal, and service sectors, often leading GRC initiatives end-to-end. This includes single-handedly enabling companies to achieve critical certifications driven by customer and regulatory expectations, while simultaneously strengthening their overall security posture.
My core strengths include:
Designing and executing enterprise-wide GRC strategies
Risk management and third-party/vendor risk management (TPRM)
Data governance and control frameworks
Driving timely and high-quality client/security questionnaire responses
Policy development, standardization, and control maturity enhancement
Beyond compliance, I focus on building forward-looking programs—aligning GRC with business objectives, optimizing budgets, and driving efficiency through automation. I actively leverage AI-driven solutions and tooling to streamline processes, enhance visibility, and reduce manual overhead across the GRC landscape.
I believe effective GRC is not just about meeting standards—it’s about enabling organizations to scale securely, inspire stakeholder confidence, and convert compliance into a strategic advantage.
GRC Strategy & Improvement
GRC Tooling and Automation
Client Audits
Security control monitoring
External Certifications
Client Questionnaire
Risk management
TPRM and Vendor risk management
Legal and compliance
Internal Audit Programme
Football and DJ
ISO 27001 Lead Auditor and ITGC