About Me
I am a cybersecurity and vulnerability management professional with experience across information security operations, vulnerability assessment, remediation coordination, GRC, and technology risk management.
In my current role as IT Security Manager, I support vulnerability management workflows, attack surface review, security monitoring, risk-based prioritisation, and remediation tracking across enterprise environments. My work includes identifying, validating, prioritising, and tracking vulnerabilities across systems, endpoints, networks, web applications, cloud-supported environments, and external-facing assets.
I actively track vulnerability remediation through ticketing workflows, monitor SLA adherence, escalate overdue high-risk findings, and report remediation progress to technical and management stakeholders. I also use AI-assisted tools such as HackerAI and Penligent AI to support vulnerability management workflows, enrich analysis, and improve remediation prioritisation while maintaining human oversight.
My security operations experience includes working with SIEM, EDR, endpoint protection, vulnerability scanners, and risk dashboards. I use tools and capabilities such as Bitdefender EDR, PHASR, Threat Explorer, compliance dashboards, executive summaries, health dashboards, CVE breakdowns, and vulnerability risk views to support exposure visibility and decision-making.
My approach to cybersecurity is risk-driven and exposure-focused. I prioritise vulnerabilities based on exploitability, business impact, asset criticality, exposure, control effectiveness, and remediation urgency rather than relying only on severity ratings.
I have practical experience applying ISO 27001, NIST CSF, COBIT, and ITIL principles to support governance, audit readiness, risk reporting, and operational resilience. I hold the ISC2 Certified in Cybersecurity credential and have completed cybersecurity, ICT governance, information security, and network standards training. I am currently pursuing ISC2 CGRC and SSCP to deepen my expertise in governance, risk, compliance, and security operations.
My professional interests include vulnerability and exposure management, cybersecurity operations, GRC, threat-informed risk prioritisation, incident response, cloud security, and secure digital transformation.