whoami

Cybersecurity professional focused on information security, governance, compliance, and data protection, with a Master’s degree in cybersecurity and certifications including CISSP, OSCP, and CDPSE. The work I enjoy most is the whole loop: finding the weaknesses, then working with the team to fix them. It’s a purple-team mindset, attacking and defending the same system, and it depends on staying as close to the teams outside security as to the ones inside it.

cat skills.md

Skills & Expertise

Strategic Governance & Risk Leadership

  • Executive Stakeholder Engagement: the link between technical teams and senior leadership, translating security risks into business terms for boards, investors, and partners.
  • Cybersecurity Strategy & Vision: building and maintaining the overall security roadmap, so technology projects line up with the business’s goals and its legal obligations.
  • Regulatory Compliance Oversight: keeping the organization aligned with international and local standards, including ISO 27001, NIST, PCI-DSS, and PDPL.
  • Enterprise Risk Management: identifying and documenting security risks through Business Impact Analysis (BIA) and Privacy Impact Assessments (PIA), so decisions rest on real data.
  • Data Privacy Governance: leading data protection, setting up the frameworks and monitoring the day-to-day practices that keep sensitive information safe across different regional jurisdictions.

Operational & Technical Leadership

  • Mentorship & Technical Instruction: teaching and mentoring people getting into cybersecurity, designing the course material and running hands-on sessions in network security and data communications.
  • Security Program Management: running security programs, from company-wide vulnerability management to enforcing security hardening guidelines.
  • Incident Response & Resilience: overseeing continuous monitoring and leading incident response to contain threats and keep the business running.
  • Infrastructure Transformation: leading large technical projects, including datacenter migrations and the design of resilient network architectures.
  • Advanced Threat Intelligence: using research on zero-day attacks and threat hunting to build defenses against new and changing threats.

ls ~/ # where to next

Start here: new to the blog? Try the Shakabrah machine walkthrough , the SSTI lab series , or my recon tool Cataract .