
Dynamic cybersecurity professional specializing in security governance and infrastructure security assurance, with a proven track record in supporting government projects. Expertise includes IT security risk assessments, warrant-of-fitness reviews, system hardening assurance, and comprehensive vulnerability management oversight. Adept at overseeing security event management and ensuring compliance with cybersecurity standards to enhance organizational cyber resilience. Committed to fostering robust security frameworks that protect critical assets and mitigate risks in an ever-evolving threat landscape.
• Support the implementation and continuous improvement of enterprise cybersecurity governance frameworks, ensuring alignment with organizational risk management, compliance, and security objectives.
• Conduct comprehensive IT security risk assessments to identify vulnerabilities, evaluate cyber threats, and recommend effective risk treatment and mitigation strategies.
• Perform security configuration reviews and system hardening assessments across Windows/Linux servers, databases, network devices, and cloud environments, ensuring compliance with industry security baselines and organizational standards.
• Review identity and access management (IAM) controls, including user provisioning, privileged access, authentication mechanisms, and least-privilege enforcement.
• Manage vulnerability assessment activities by coordinating security scans, validating findings, prioritizing risks based on severity, tracking remediation, and verifying the effectiveness of corrective actions.
• Maintain governance over enterprise infrastructure assets by ensuring accurate asset inventory, security classification, and compliance with mandatory security controls.
• Analyze security assessment results and provide actionable recommendations to strengthen the organization's overall cybersecurity posture and reduce operational risk.
• Partner with infrastructure, cloud, application, and network teams to implement remediation plans and drive timely closure of identified security vulnerabilities and compliance gaps.
• Monitor compliance with internal security policies, industry frameworks, and regulatory requirements, while supporting internal and external security audits.
• Develop, review, and maintain cybersecurity policies, standards, procedures, security baselines, and governance documentation.
• Provide security advisory and governance support for technology projects, ensuring security requirements are integrated throughout the system development and infrastructure change lifecycle.
• Prepare governance reports, risk dashboards, and compliance metrics for management, enabling informed decision-making and effective cybersecurity oversight.