Portfolio

Project work

Anonymized excerpts from real security engagements. Client identities kept strictly confidential.

Portfolio

Selected projects

Anonymized excerpts from real engagements. Client identities are kept strictly confidential — what is shown is the work, the challenge, and the outcome.

GRC · vCISOBPO · InternationalOngoing
P-01

Dual Framework Certification — ISO 27001 & SOC 2 Type II

Engaged as virtual CISO for a fully remote international company requiring simultaneous ISO 27001:2022 and SOC 2 Type II certification. Built the entire security program from scratch with no internal security resources and a fixed audit deadline.

Challenge
No existing security program. Enterprise clients conditioning contracts on certification. Hard deadline. No internal security team.
Approach
Full vCISO engagement. Deployed Scrut.io GRC, built complete ISMS (34 documents), established tooling stack, conducted user access reviews, weekly executive advisory.
Outcome
96% compliance across both frameworks. Audit readiness on track. Security culture established across the remote workforce.
2% → 96%34 documentsDual frameworkFull ISMS from scratch
Healthcare · GRCHIPAA · ISO 27001Africa
P-02

Healthcare Security Framework — High-Stakes Clinical Environment

Designed a complete security framework for a major specialized hospital — the largest of its kind on the continent — protecting sensitive patient data while achieving HIPAA and ISO 27001 compliance within a resource-constrained clinical setting.

Challenge
No security framework. HIPAA compliance required. Clinical operations could not be disrupted. Significant resource constraints.
Approach
Initial assessment, then tailored HIPAA + ISO 27001 framework balancing international standards with clinical operational reality.
Outcome
Structured security foundation protecting patient data. Dual framework aligned. Zero disruption to clinical operations.
HIPAA + ISO 270018+ documentsBuilt from scratch
Government · Architecture ReviewISO 27001UK
P-03

Security Architecture Review — National Digital Transformation

Independent security reviewer across a national government institution's full digital transformation portfolio — cloud migrations, AI adoption, SaaS onboarding, and network modernization — each requiring structured security assessment and sign-off.

Challenge
Multiple concurrent technology programs with high public trust obligations. Security review needed at each stage without slowing delivery.
Approach
Each document — HLD, MLD, vendor assessments, architecture diagrams — reviewed against ISO 27001 controls with structured findings delivered.
Outcome
22+ documents reviewed and signed off. All programs advanced with security assurance at every stage.
22+ documents6+ tech programsISO 27001National institution
Cloud SecurityNon-Profit · InternationalAzure
P-04

Cloud Security & SIEM Deployment — International Organization

Deployed Microsoft Sentinel for a global heritage organization, implemented Azure File Sync and Backup, integrated Microsoft Copilot for secure document access, and delivered comprehensive cloud security advisory.

Challenge
Dispersed global team with no centralized security monitoring. Files scattered. Limited security visibility.
Approach
Microsoft Sentinel deployment, Azure File Sync, Copilot integration, backup strategy, cloud security advisory.
Outcome
Centralized monitoring live. Files securely accessible globally. Copilot enabled plain-language document access.
Sentinel deployedAzure File SyncCopilot integration
SOC · Incident ResponseTechnology · International
P-05

Incident Response Playbook Suite — Global Platform

Developed a complete SOC incident response playbook suite for a global mobility platform — 40+ threat scenarios including phishing, DDoS, malware, API exploits, PAM events, and email-based attacks. Included a live DDoS tabletop simulation.

Challenge
No structured IR capability. SOC team responding ad-hoc with no documented playbooks or consistent process.
Approach
40+ playbooks across all major threat types, MDM policy, SOP documentation, and live DDoS tabletop exercise.
Outcome
Production-ready IR capability. SOC equipped for consistent, fast response across every documented threat category.
40+ playbooksTabletop simulationMDM policy
Digital ForensicsMulti-sector · 19+ Cases
P-06

Digital Forensics Investigations — Cross-Sector Portfolio

19+ forensic investigations across hacked systems, corporate email compromises, mobile devices, Windows event log analysis, memory forensics (Volatility), blockchain transaction tracing, and USB investigations.

Challenge
Breaches, data loss, compromised accounts, and suspicious activity requiring independent expert investigation.
Approach
Evidence acquisition and preservation using FTK Imager, Autopsy, EnCase, Volatility. Root-cause analysis, timeline reconstruction, documentation.
Outcome
Actionable findings in every case. Root causes identified. Post-incident recommendations delivered to prevent recurrence.
19+ casesFTK · Autopsy · EnCaseMemory forensicsBlockchain tracing

Ready to discuss your project?

Available for immediate engagement globally.